← Files CrowdStrike Falcon FusionARCHIVED FILE
skills/authoring/examples/tutorials/intro-receive-email-trigger.yaml
2.19 KB · Oct 2, 2026 · 00:31 UTC
# Example: Introduction to Receive Email Trigger: Create a Lookup File from an Email
# Category: tutorials
# Source: CrowdStrike Content Library
name: 'Introduction to Receive Email trigger: How to create a lookup file from an email attachment'
description: Learn how to create a lookup file from a file attachment. Requires user has setup the O365 Monitored Mailbox app from the CrowdStrike store.
trigger:
next:
- data_trigger_monitoredemail_attachmentfiles_null_data_trigge
name: Receive email
event: MonitoredEmail
type: Signal
version_constraint: ~1
actions:
CreateLookupFileWithoutLoop:
id: 51c4db34ab30465f796d7550f3e3e97b
name: create lookup file without loop
version_constraint: ~1
properties:
lookup_file_content_file: ${data['Trigger.MonitoredEmail.AttachmentFiles'][0]}
lookup_file_content_type: file
lookup_file_name: ${cs.json.decode(data['Trigger.MonitoredEmail.AttachmentFiles'][0]).Name}
lookup_file_repo: search-all
PrintData:
id: aadbf530e35fc452a032f5f8acaaac2a
name: Print data
version_constraint: ~1
properties:
text_data: "Attachment file types are not .csv${data['Trigger.MonitoredEmail.AttachmentFiles'] != null ?\n data['Trigger.MonitoredEmail.AttachmentFiles']\n .transformList(i, a, cs.json.decode(a).Name)\n .join(', ') :\n ''}"
conditions:
data_trigger_monitoredemail_attachmentfiles_null_data_trigge:
next:
- CreateLookupFileWithoutLoop
else:
- PrintData
cel_expression: "data['Trigger.MonitoredEmail.AttachmentFiles'] != null &&\ndata['Trigger.MonitoredEmail.AttachmentFiles'].exists(s,\n s != null && s != '' &&\n cs.json.valid(s) &&\n cs.json.decode(s)['Name'] != null &&\n cs.json.decode(s)['Name'] != '' &&\n cs.json.decode(s)['Name'].endsWith('.csv')\n)"
display:
- "data['Trigger.MonitoredEmail.AttachmentFiles'] != null &&\ndata['Trigger.MonitoredEmail.AttachmentFiles'].exists(s,\n s != null && s != '' &&\n cs.json.valid(s) &&\n cs.json.decode(s)['Name'] != null &&\n cs.json.decode(s)['Name'] != '' &&\n cs.json.decode(s)['Name'].endsWith('.csv')\n)"
SHA-256: 6cf9b3b917691c1024c79ae126528cb626b1d71e9441f0707a44d2dae546c300