← Files CrowdStrike Falcon FusionARCHIVED FILE

skills/authoring/examples/tutorials/crowdstrike-http-request-falcon-api.yaml

6.1 KB · Oct 5, 2026 · 18:32 UTC

↓ Download file

# Example: Query the Falcon Alerts API with a CrowdStrike HTTP Request, email the result
# Category: tutorials
# Source: Built in the Falcon console and verified live end-to-end against a CID
#   (published + on-demand execution + email received). This is the canonical
#   shape of a **CrowdStrike HTTP Request** — the action that calls Falcon
#   platform APIs, as distinct from a Cloud HTTP Request (external APIs like
#   VirusTotal). Use this to fetch a *population* of alerts/detections the
#   workflow does not already hold (e.g. "all high-severity alerts from the last
#   24h") — NOT an Event Query, whose NG-SIEM data is connector-dependent.
#
# Ground truth captured from the export (things that are easy to get wrong):
#   - request_url is ABSOLUTE and region-specific:
#       https://api.us-2.crowdstrike.com/...   (US-2)
#       https://api.crowdstrike.com/...        (US-1)
#       https://api.eu-1.crowdstrike.com/...   (EU-1)
#     A relative path (/alerts/queries/...) is rejected with "Invalid URL format".
#   - The URL must NOT contain a query string. Query params (filter, limit) go in
#     the console Query tab, which serializes to the request_query UUID-map below.
#     Putting ?filter=... in the URL is rejected with "URL should not contain
#     query parameters".
#   - Authentication is REQUIRED for a CrowdStrike HTTP Request (no credential-less
#     option, unlike a Cloud HTTP Request). This example references a saved
#     credential config: authentication_option: UseExisting + config_id (32-hex) +
#     config_name. (When you create the config inline instead, the console writes
#     authentication_option: CreateNew + definition_id + oauth_token_url.) The API
#     client behind the config needs the **Alerts** scope (Read) for /alerts endpoints.
#   - config_id below is CID-specific and will NOT work in another CID. Create your
#     own OAuth credential on the action in the console (Authentication -> Create new
#     -> Token URL https://api.<region>.crowdstrike.com/oauth2/token + Client ID +
#     Client secret from an API client with the Alerts scope), or pick Use existing.
#   - class is Inline.HTTPRequest — the same class as a Cloud HTTP Request; the
#     "CrowdStrike" vs "Cloud" distinction is console-side, not in the class.
#
# This is an exported workflow. Editing this file is not recommended.

name: CrowdStrike HTTP Actions Demo
trigger:
    next:
        - CrowdStrikeHTTPRequest
    name: On demand
    type: On demand
actions:
    CrowdStrikeHTTPRequest:
        id: ad9b77de3da84531b79740e5b4076571
        default_name: CrowdStrike HTTP Request
        inline_configuration:
            output_schema:
                $schema: https://json-schema.org/draft-07/schema
                properties:
                    meta:
                        properties:
                            pagination:
                                properties:
                                    limit:
                                        type: integer
                                    offset:
                                        type: integer
                                    total:
                                        type: integer
                                type: object
                            powered_by:
                                type: string
                            query_time:
                                type: number
                            trace_id:
                                type: string
                            writes:
                                properties:
                                    resources_affected:
                                        type: integer
                                type: object
                        type: object
                    resources:
                        items: {}
                        type: array
                type: object
                description: This generated schema may need tweaking. In particular format fields are attempts at matching workflow field types but may not be correct.
        class: Inline.HTTPRequest
        name: CrowdStrike HTTP Request
        next:
            - SendEmail
        properties:
            authentication_option: UseExisting
            config_id: 56dc4d3ec3024dbbb3ff624a8c0bef61
            config_name: Alerts Read
            http_transaction:
                _cs_inline_output_schema: '{"$schema":"https://json-schema.org/draft-07/schema","properties":{"meta":{"properties":{"pagination":{"properties":{"limit":{"type":"integer"},"offset":{"type":"integer"},"total":{"type":"integer"}},"type":"object"},"powered_by":{"type":"string"},"query_time":{"type":"number"},"trace_id":{"type":"string"},"writes":{"properties":{"resources_affected":{"type":"integer"}},"type":"object"}},"type":"object"},"resources":{"items":{},"type":"array"}},"type":"object","description":"This generated schema may need tweaking. In particular format fields are attempts at matching workflow field types but may not be correct."}'
                request_content_type: NONE
                request_headers: {}
                request_http_method: GET
                request_query:
                    9795b73c-1ddd-479e-b915-b5ea10750367:
                        name: limit
                        value: "100"
                    c95c8267-a249-4fe9-8040-2b4e629170ab:
                        name: filter
                        value: severity_name:'High'+created_timestamp:>'now-24h'
                request_url: https://api.us-2.crowdstrike.com/alerts/queries/alerts/v2
                response_as_raw_string: false
                response_status_code: 200
            oauth_token_url: https://api.us-2.crowdstrike.com/oauth2/token
        version_constraint: ~1
    SendEmail:
        id: 07413ef9ba7c47bf5a242799f59902cc
        default_name: Send email
        name: Send email
        properties:
            msg: ${data['CrowdStrikeHTTPRequest.resources']}
            msg_type: text
            subject: Daily High-Severity Alerts
            to:
                - ${data['recipient']}   # supply a real Falcon user / CID-approved address (e.g. an On-demand 'recipient' input, or a literal)
        version_constraint: ~1

SHA-256: 95473716af379cf711b59d707b228438c2540a63728adb0e530f262904de37f5