# New Alert — CrowdStrike Falcon

> Emit new event for each CrowdStrike Falcon alert created since the last run. Polls GET /alerts/queries/alerts/v1 (GetQueriesAlertsV2) for alert IDs newer than the stored created_timestamp checkpoint, then hydrates them via POST…

- Key: `crowdstrike_falcon-new-alert`
- Type: Trigger (Polling)
- Version: 0.0.1
- App: CrowdStrike Falcon (`crowdstrike_falcon`) — https://pipedream.com/apps/crowdstrike-falcon.md
- This page (HTML): https://pipedream.com/apps/crowdstrike-falcon/triggers/new-alert
- Source: https://github.com/PipedreamHQ/pipedream/blob/master/components/crowdstrike_falcon/sources/new-alert/new-alert.mjs

## Description

Emit new event for each CrowdStrike Falcon alert created since the last run. Polls GET /alerts/queries/alerts/v1 (GetQueriesAlertsV2) for alert IDs newer than the stored `created_timestamp` checkpoint, then hydrates them via POST /alerts/entities/alerts/v1 (PostEntitiesAlertsV2, body field `composite_ids`). Use the optional FQL filter to narrow to specific alert products (e.g. legacy endpoint detections, now surfaced through the Alerts API). [See the documentation](https://developer.crowdstrike.com/api-reference/collections/alerts/).

## Props

| Prop | Type | Required | Description |
|---|---|---|---|
| `timer` | `$.interface.timer` | Yes | Timer |
| `fqlFilter` | `string` | No | Optional FQL filter appended to the created_timestamp checkpoint filter. Example: product:'epp' to emit only endpoint-detection alerts. Combine terms with +. |

## Returns

Events emitted by CrowdStrike Falcon.

## Run it

**TypeScript**

```ts
import { PipedreamClient } from "@pipedream/sdk"

const pd = new PipedreamClient({
  projectId: process.env.PIPEDREAM_PROJECT_ID!,
  clientId: process.env.PIPEDREAM_CLIENT_ID!,
  clientSecret: process.env.PIPEDREAM_CLIENT_SECRET!,
  projectEnvironment: "production",
})

const deployed = await pd.triggers.deploy({
  id: "crowdstrike_falcon-new-alert",
  externalUserId: "{external_user_id}", // any stable ID for this user in your system
  configuredProps: {
    crowdstrike_falcon: { authProvisionId: "apn_xxxxxxx" },
    timer: { "intervalSeconds": 900 },
    fqlFilter: "FQL Filter",
  },
  webhookUrl: "https://example.com/webhooks/crowdstrike-falcon",
})

console.log(deployed.id)
```

**cURL**

```bash
curl -X POST https://api.pipedream.com/v1/connect/{project_id}/triggers/deploy \
  -H "Content-Type: application/json" \
  -H "X-PD-Environment: production" \
  -H "Authorization: Bearer {access_token}" \
  -d '{
    "external_user_id": "{external_user_id}",
    "id": "crowdstrike_falcon-new-alert",
    "webhook_url": "https://example.com/webhooks/crowdstrike-falcon",
    "configured_props": {
      "crowdstrike_falcon": { "authProvisionId": "apn_xxxxxxx" },
      "timer": { "intervalSeconds": 900 },
      "fqlFilter": "FQL Filter"
    }
  }'
```

**MCP**

MCP servers expose CrowdStrike Falcon actions as on-demand tools.

New Alert is an event source, so your application deploys it with the Connect SDK or API and then either receives each event at a webhook URL or retrieves events on demand with the trigger events API.

## Event delivery

Every event is sent to the HTTP endpoint you choose when you deploy the source. Or: no webhook required — your app or agent can fetch recent events from the [trigger events API](https://pipedream.com/docs/connect/api-reference/list-trigger-events.md) instead.

---

- App: https://pipedream.com/apps/crowdstrike-falcon.md · All apps: https://pipedream.com/apps
