← Files CrowdStrike Falcon FusionARCHIVED FILE
skills/authoring/examples/tutorials/intro-cases-add-event.yaml
2.05 KB · Oct 2, 2026 · 00:31 UTC
# Example: Introduction to Cases: How to Add an Event to a Case
# Category: tutorials
# Source: CrowdStrike Content Library
name: 'Introduction to Cases: How to add an event to a case'
description: Learn how to add an event to a case
trigger:
next:
- ExampleEventQuery
name: On demand
type: On demand
actions:
AddEventsToCase:
id: 91e6224248076bdea0e79b51f8b8b13a
name: Add events to case
version_constraint: ~1
properties:
case_id: AAAAAAAAAAFGY2z2DOOaLGMkTGlrJtvbieKrODNtpJgkxoBu_O-enzSixGrCBiTMtYbsdwxTxrQhj95juejTTVdXpGFj5lSZTFWMUxiOdy1KprGaifRlZXPT9Uh0x0Fbj3hJLsPXnMcEoblTxPWpS7SEsfi9GckXqzOfZA
events:
- ${data['ExampleEventQuery.results'][0].eventID}
ExampleEventQuery:
id: cdf5c3e0d69f156eaaf56c1f5d3f1b66
class: Inline.QueryEvent
name: example event query
version_constraint: ~1
next:
- AddEventsToCase
properties:
output_files_only: false
workflow_export_event_query_results_to_csv: false
inline_configuration:
config:
description: ''
end: now
repo_or_view: search-all
search_name: example queries
search_query: '#repo = fusion
| select(["trigger.data.Workflow.Definition.Name", @id])
| rename(field=@id, as=eventID)
'
search_query_args: {}
start: 45m
tags: []
output_schema:
$schema: https://json-schema.org/draft-07/schema
properties:
eventID:
type: string
title: EventID
trigger:
properties:
data:
properties:
Workflow:
properties:
Definition:
properties:
Name:
type: string
title: Trigger Data Workflow Definition Name
type: object
type: object
type: object
type: object
type: object
description: Generated response schema
SHA-256: f56cdd8b9d10de8cd98ab83c0df5e62700280909af4fb46e36aea9cd4369102b