Skip to main content
Get session metadata by session id. One of the following roles is required to read the user’s own sessions details.
  • RTR Read Only Analyst.
  • RTR Active Responder.
  • RTR Administrator.
To read all users sessions, the following role is required:
  • Falcon Administrator.
External DocumentationTo learn more, visit the CrowdStrike documentation.

Parameters

Example Output

Workflow Library Example

Get Rtr Sessions Details with Crowdstrike and Send Results Via Email
Workflow LibraryPreview this Workflow on desktop