Skip to main content
Search SIEM query by ID. Note: If you used the Advanced Search Query action, experienced a timeout, and received the search ID, you can use this action to retrieve the results from the search, as long as 90 seconds have not passed since the timeout (after which the search is automatically removed from crowdstrike’s database)
External DocumentationTo learn more, visit the CrowdStrike documentation.

Parameters

Example Output

Workflow Library Example

Search Query by Id with Crowdstrike and Send Results Via Email
Workflow LibraryPreview this Workflow on desktop