Skip to main content
Update an alert or multiple ones. Allows you to update the status, assign it to a user, add comments with additional info, ect. The following permission is required to run this action:
  • Alerts: Read and Write.
This endpoint does not support detection IDs prefixed with ldt.
External DocumentationTo learn more, visit the CrowdStrike documentation.

Parameters

Example Output

Workflow Library Example

Update Alerts with Crowdstrike and Send Results Via Email
Workflow LibraryPreview this Workflow on desktop