AptlyStar

CrowdStrike

Query CrowdStrike Identity Protection sensors and documented aggregates

使用方法

Integrate CrowdStrike Identity Protection into workflows to search sensors, fetch documented sensor details by device ID, and run documented sensor aggregate queries.

ツール

crowdstrike_get_sensor_aggregates

Get documented CrowdStrike Identity Protection sensor aggregates from a JSON aggregate query body

入力

パラメータ型必須説明
clientIdstringはいCrowdStrike Falcon API client ID
clientSecretstringはいCrowdStrike Falcon API client secret
cloudstringはいCrowdStrike Falcon cloud region
aggregateQueryjsonはいJSON aggregate query body documented by CrowdStrike for sensor aggregates

出力

パラメータ型説明
aggregatesarrayAggregate result groups returned by CrowdStrike
↳ bucketsarrayBuckets within the aggregate result
↳ countnumberBucket document count
↳ fromnumberBucket lower bound
↳ keyAsStringstringString representation of the bucket key
↳ labeljsonBucket label object
↳ stringFromstringString lower bound
↳ stringTostringString upper bound
↳ subAggregatesjsonNested aggregate results for this bucket
↳ tonumberBucket upper bound
↳ valuenumberBucket metric value
↳ valueAsStringstringString representation of the bucket value
↳ docCountErrorUpperBoundnumberUpper bound for bucket count error
↳ namestringAggregate result name
↳ sumOtherDocCountnumberDocument count not included in the returned buckets
countnumberNumber of aggregate result groups returned

crowdstrike_get_sensor_details

Get documented CrowdStrike Identity Protection sensor details for one or more device IDs

入力

パラメータ型必須説明
clientIdstringはいCrowdStrike Falcon API client ID
clientSecretstringはいCrowdStrike Falcon API client secret
cloudstringはいCrowdStrike Falcon cloud region
idsjsonはいJSON array of CrowdStrike sensor device IDs

出力

パラメータ型説明
sensorsarrayCrowdStrike identity sensor detail records
↳ agentVersionstringSensor agent version
↳ cidstringCrowdStrike customer identifier
↳ deviceIdstringSensor device identifier
↳ heartbeatTimenumberLast heartbeat timestamp
↳ hostnamestringSensor hostname
↳ idpPolicyIdstringAssigned Identity Protection policy ID
↳ idpPolicyNamestringAssigned Identity Protection policy name
↳ ipAddressstringSensor local IP address
↳ kerberosConfigstringKerberos configuration status
↳ ldapConfigstringLDAP configuration status
↳ ldapsConfigstringLDAPS configuration status
↳ machineDomainstringMachine domain
↳ ntlmConfigstringNTLM configuration status
↳ osVersionstringOperating system version
↳ rdpToDcConfigstringRDP to domain controller configuration status
↳ smbToDcConfigstringSMB to domain controller configuration status
↳ statusstringSensor protection status
↳ statusCausesarrayDocumented causes behind the current status
↳ tiEnabledstringThreat intelligence enablement status
countnumberNumber of sensors returned
paginationjsonPagination metadata when returned by the underlying API
↳ limitnumberPage size used for the query
↳ offsetnumberOffset returned by CrowdStrike
↳ totalnumberTotal records available

crowdstrike_query_sensors

Search CrowdStrike identity protection sensors by hostname, IP, or related fields

入力

パラメータ型必須説明
clientIdstringはいCrowdStrike Falcon API client ID
clientSecretstringはいCrowdStrike Falcon API client secret
cloudstringはいCrowdStrike Falcon cloud region
filterstringいいえFalcon Query Language filter for identity sensor search
limitnumberいいえMaximum number of sensor records to return
offsetnumberいいえPagination offset for the identity sensor query
sortstringいいえSort expression for identity sensor results

出力

パラメータ型説明
sensorsarrayMatching CrowdStrike identity sensor records
↳ agentVersionstringSensor agent version
↳ cidstringCrowdStrike customer identifier
↳ deviceIdstringSensor device identifier
↳ heartbeatTimenumberLast heartbeat timestamp
↳ hostnamestringSensor hostname
↳ idpPolicyIdstringAssigned Identity Protection policy ID
↳ idpPolicyNamestringAssigned Identity Protection policy name
↳ ipAddressstringSensor local IP address
↳ kerberosConfigstringKerberos configuration status
↳ ldapConfigstringLDAP configuration status
↳ ldapsConfigstringLDAPS configuration status
↳ machineDomainstringMachine domain
↳ ntlmConfigstringNTLM configuration status
↳ osVersionstringOperating system version
↳ rdpToDcConfigstringRDP to domain controller configuration status
↳ smbToDcConfigstringSMB to domain controller configuration status
↳ statusstringSensor protection status
↳ statusCausesarrayDocumented causes behind the current status
↳ tiEnabledstringThreat intelligence enablement status
countnumberNumber of sensors returned
paginationjsonPagination metadata (limit, offset, total)
↳ limitnumberPage size used for the query
↳ offsetnumberOffset returned by CrowdStrike
↳ totalnumberTotal records available

On this page