Skip to content

Hosts

The Hosts service collection provides operations for managing and investigating endpoints across your CrowdStrike Falcon environment. Search for devices using FQL formatted filters. Retrieve detailed host information, check online status, and review login and network address history. Take action on hosts by containing compromised endpoints, suppressing detections, or hiding and restoring devices. Manage Falcon Grouping Tags to organize your fleet.

LanguageLast Update
Pythonv1.6.5
PowerShellv2.2.9
Gov0.22.0
TypeScriptv0.6.0
Rustv0.7.1
Rubyv1.4.0

This service collection has code examples posted to the repository.



OperationDescription
CombinedDevicesByFilter
query_devices_by_filter_combined
Search for hosts in your environment by platform, hostname, IP, and other criteria.
CombinedHiddenDevicesByFilter
query_hidden_devices_combined
Search for hidden hosts in your environment by platform, hostname, IP, and other criteria.
DevicesActionsDeleteV1
devices_actions_delete_v1
Permanently delete hosts from the system.
entities.perform_action
perform_group_action
Performs the specified action on the provided group IDs.
GetDeviceDetails
get_device_details
Get details on one or more hosts by providing host IDs in a POST body.
GetDeviceDetailsV1
get_device_details_v1
Get details on one or more hosts by providing agent IDs (AID).
GetDeviceDetailsV2
get_device_details_v2
Get details on one or more hosts by providing host IDs as a query parameter.
GetOnlineState.V1
get_online_state
Get the online status for one or more hosts by specifying each host’s unique ID.
PerformActionV2
perform_action
Take various actions on the hosts in your environment.
PostDeviceDetailsV2
get_device_details
Get details on one or more hosts by providing host IDs in a POST body.
QueryDeviceLoginHistory
query_device_login_history_v1
Retrieve details about recent login sessions for a set of devices.
QueryDeviceLoginHistoryV2
query_device_login_history_v2
Retrieve details about recent interactive login sessions for a set of devices powered by the Host Timeline.
QueryDevicesByFilter
query_devices_by_filter
Search for hosts in your environment by platform, hostname, IP, and other criteria.
QueryDevicesByFilterScroll
query_devices_by_filter_scroll
Search for hosts in your environment by platform, hostname, IP, and other criteria with continuous pagination capability (based on offset pointer which expires after 2 minutes with no maximum limit)
QueryGetNetworkAddressHistoryV1
query_network_address_history
Retrieve history of IP and MAC addresses of devices.
QueryHiddenDevices
query_hidden_devices
Retrieve hidden hosts that match the provided filter criteria.
UpdateDeviceTags
update_device_tags
Append or remove one or more Falcon Grouping Tags on one or more hosts.

Search for hosts in your environment by platform, hostname, IP, and other criteria.

Method GET
Route /devices/combined/devices/v1
Scope Hosts: READ
PEP 8 query_devices_by_filter_combined
offset query · string
The offset to page from, provided from the previous call as the “next” value, for the next result set. For the first call, do not supply an offset.
limit query · integer
The maximum records to return. [1-10000]
sort query · string
The property to sort by (e.g. status.desc or hostname.asc). If not specified, the default sort will be device_id.asc. This should be supplied for each consecutive call.
Available values (197)
device_policies.aws-verified-access.appliedpod_namespacedevice_policies.application-abuse-prevention.policy_id
device_policies.aidr.appliedos_builddevice_policies.prevention.policy_type
device_policies.sensor_update.policy_iddevice_policies.netskope.policy_iddevice_policies.data-protection.applied
device_policies.data-protection-cloud.policy_iddevice_policies.mobile.policy_idpod_host_ip4
first_login_userlast_login_user_siddevice_policies.ztl.policy_id
device_policies.fim.policy_typedevice_policies.data-protection-cloud.appliedinstance_id
device_policies.firewall.appliedmanaged_apps.netskope.versionsafe_mode
local_ipplatform_idpolicies.policy_type
device_policies.automox.applieddevice_policies.mobile.appliedconnection_mac_address
migration_completed_timecriticalityplatform_name
site_namedevice_policies.it-automation.policy_typemac_address
reduced_functionality_modecpu_vendorpod_ip6
device_policies.sca.applieddevice_policies.host-retention.appliedgroups
pod_idchassis_typedevice_policies.exposure-management.applied
device_policies.logscale-collector.policy_idbios_versionpod_ip4
device_policies.network-scan-content.policy_typedevice_policies.prevention.applieddevice_policies.vulnerability-management.policy_type
device_policies.remote_response.appliedos_product_namedevice_policies.sensor_update.uninstall_protection
device_policies.kubernetes-admission-control.policy_idservice_provider_account_iddevice_policies.network-scan-content.policy_id
device_policies.fem-browser-extension-control.policy_typedevice_policies.host-retention.policy_typedevice_policies.firewall.policy_id
device_policies.remote_response.policy_typeconfig_id_builddevice_policies.data-protection.policy_id
device_policies.firewall.policy_typepointer_sizechassis_type_desc
device_policies.ztl.policy_typedevice_policies.vulnerability-management.policy_idserial_number
device_policies.application-abuse-prevention.appliedlast_login_timestampdevice_policies.airlock.policy_id
device_policies.jumpcloud.applieddevice_policies.sca.policy_idgroup_hash
k8s_cluster_versionlast_rebootlast_login_user
device_policies.prevention.policy_iddevice_policies.sensor_update.appliedmanaged_apps.airlock.version
rtr_statedevice_policies.logscale-collector.policy_typedevice_policies.logscale-collector.applied
policies.applieddevice_policies.airlock.applieddevice_policies.data-protection.policy_type
device_policies.remote_response.policy_idpod_hostnamedevice_policies.aidr.policy_id
agent_load_flagsdevice_policies.ztl.applieddevice_policies.system-tray.policy_type
device_policies.content-update.policy_idmanaged_apps.identity-protection.versioncpu_signature
kernel_versionrelease_groupdevice_policies.kubernetes-admission-control.policy_type
device_policies.system-tray.policy_idconnection_ipdefault_gateway_ip
config_id_platformhostnamedevice_policies.jumpcloud.policy_type
local_ip.rawtagshost_utc_offset
product_type_descpolicy_iddevice_policies.sensor_update.policy_type
device_policies.device_control.appliedemailinternet_exposure
cloud_service_compartment_iddevice_policies.browser-extension.policy_typeou
product_typedevice_policies.device_control.policy_typedevice_policies.aidr.policy_type
first_login_timestampsystem_product_namemodified_timestamp
device_policies.jumpcloud.policy_iddevice_policies.consumer-subscription.policy_typedevice_policies.aws-verified-access.policy_id
zone_groupdevice_policies.application-abuse-prevention.policy_typeexternal_ip
machine_domaindevice_policies.airlock.policy_typedevice_policies.exposure-management.policy_type
os_version_alllicense_activation_state
filesystem_containment_statusminor_versiondevice_policies.identity-endpoint.applied
device_policies.consumer-subscription.policy_iddevice_policies.data-protection-cloud.policy_typedevice_policies.browser-extension.policy_id
config_id_basefirst_seenlast_login_uid
policies.policy_iddevice_policies.identity-protection.policy_typedevice_policies.vulnerability-management.applied
device_policies.cloud-ml.applieddevice_policies.firewall.rule_set_idbios_manufacturer
major_versiondevice_policies.automox.policy_iddevice_policies.netskope.policy_type
device_policies.netskope.applieddevice_policies.identity-protection.applieddevice_policies.it-automation.policy_id
managed_apps.automox.versionagent_versionsystem_manufacturer
device_policies.fim.appliedk8s_cluster_git_versiondevice_policies.browser-extension.applied
device_policies.exposure-management.policy_iddevice_policies.fem-browser-extension-control.policy_iddevice_id
device_policies.cloud-ml.policy_typedevice_policies.sca.policy_typepod_service_account_name
linux_sensor_modedevice_policies.fem-browser-extension-control.applieddevice_policies.identity-endpoint.policy_id
device_policies.kubernetes-admission-control.applieddevice_policies.host-retention.policy_idservice_provider
pod_host_ip6device_policies.automox.policy_typedevice_policies.identity-protection.policy_id
device_policies.cloud-ml.policy_iddevice_policies.it-automation.applieddevice_policies.aws-verified-access.policy_type
pod_labelsk8s_cluster_iddetection_suppression_status
last_seendevice_policies.identity-endpoint.policy_typedevice_policies.system-tray.applied
device_policies.content-update.policy_typemanaged_apps.jumpcloud.versionmanaged_apps.aws-verified-access.version
pod_annotationsdeployment_typecid
statusdevice_policies.consumer-subscription.applieddevice_policies.content-update.applied
device_policies.mobile.policy_typepod_namedevice_policies.network-scan-content.applied
device_policies.device_control.policy_iddevice_policies.fim.policy_id
filter query · string
The filter expression that should be used to limit the results. This should be supplied for each consecutive call.
fields query · string
The fields to return, comma delimited if specifying more than one field. For example: fields=hostname,device_id would return device records only containing the hostname and device_id
parameters query · dictionary
Full query string parameters payload in JSON format. Not required when using other keywords.
from falconpy import Hosts
falcon = Hosts(client_id=CLIENT_ID,
client_secret=CLIENT_SECRET
)
response = falcon.query_devices_by_filter_combined(filter="string",
limit=integer,
offset="string",
sort="string")
print(response)
[
{
"agent_load_flags": "string",
"agent_local_time": "string",
"agent_version": "string",
"base_image_version": "string",
"bios_manufacturer": "string",
"bios_version": "string",
"build_number": "string",
"chassis_type": "string",
"chassis_type_desc": "string",
"cid": "string",
"cloud_service_compartment_id": "string",
"config_id_base": "string",
"config_id_build": "string",
"config_id_platform": "string",
"connection_ip": "string",
"connection_mac_address": "string",
"cpu_signature": "string",
"cpu_vendor": "string",
"criticality": "string",
"default_gateway_ip": "string",
"deployment_type": "string",
"detection_suppression_status": "string",
"device_id": "string",
"device_policies": {},
"email": "string",
"external_ip": "string",
"filesystem_containment_status": "string",
"first_login_timestamp": "string",
"first_seen": "string",
"group_hash": "string",
"groups": [],
"host_hidden_status": "string",
"host_utc_offset": "string",
"hostname": "string",
"instance_id": "string",
"k8s_cluster_git_version": "string",
"k8s_cluster_id": "string",
"k8s_cluster_version": "string",
"kernel_version": "string",
"last_login_timestamp": "string",
"last_login_uid": "string",
"last_login_user": "string",
"last_login_user_sid": "string",
"last_reboot": "string",
"last_seen": "string",
"linux_sensor_mode": "string",
"local_ip": "string",
"mac_address": "string",
"machine_domain": "string",
"major_version": "string",
"managed_apps": {},
"meta": {},
"migration_completed_time": "string",
"minor_version": "string",
"modified_timestamp": "string",
"notes": [],
"os_build": "string",
"os_product_name": "string",
"os_version": "string",
"ou": [],
"platform_id": "string",
"platform_name": "string",
"pod_annotations": [],
"pod_host_ip4": "string",
"pod_host_ip6": "string",
"pod_hostname": "string",
"pod_id": "string",
"pod_ip4": "string",
"pod_ip6": "string",
"pod_labels": [],
"pod_name": "string",
"pod_namespace": "string",
"pod_service_account_name": "string",
"pointer_size": "string",
"policies": [],
"product_type": "string",
"product_type_desc": "string",
"provision_status": "string",
"reduced_functionality_mode": "string",
"release_group": "string",
"rtr_state": "string",
"safe_mode": "string",
"serial_number": "string",
"service_pack_major": "string",
"service_pack_minor": "string",
"service_provider": "string",
"service_provider_account_id": "string",
"site_name": "string",
"status": "string",
"system_manufacturer": "string",
"system_product_name": "string",
"tags": [],
"zone_group": "string"
}
]


Search for hidden hosts in your environment by platform, hostname, IP, and other criteria.

Method GET
Route /devices/combined/devices-hidden/v1
Scope Hosts: READ
PEP 8 query_hidden_devices_combined
offset query · string
The offset to page from, provided from the previous call as the “next” value, for the next result set. For the first call, do not supply an offset.
limit query · integer
The maximum records to return. [1-10000]
sort query · string
The property to sort by (e.g. status.desc or hostname.asc). If not specified, the default sort will be device_id.asc. This should be supplied for each consecutive call.
Available values (197)
device_policies.aws-verified-access.appliedpod_namespacedevice_policies.application-abuse-prevention.policy_id
device_policies.aidr.appliedos_builddevice_policies.prevention.policy_type
device_policies.sensor_update.policy_iddevice_policies.netskope.policy_iddevice_policies.data-protection.applied
device_policies.data-protection-cloud.policy_iddevice_policies.mobile.policy_idpod_host_ip4
first_login_userlast_login_user_siddevice_policies.ztl.policy_id
device_policies.fim.policy_typedevice_policies.data-protection-cloud.appliedinstance_id
device_policies.firewall.appliedmanaged_apps.netskope.versionsafe_mode
local_ipplatform_idpolicies.policy_type
device_policies.automox.applieddevice_policies.mobile.appliedconnection_mac_address
migration_completed_timecriticalityplatform_name
site_namedevice_policies.it-automation.policy_typemac_address
reduced_functionality_modecpu_vendorpod_ip6
device_policies.sca.applieddevice_policies.host-retention.appliedgroups
pod_idchassis_typedevice_policies.exposure-management.applied
device_policies.logscale-collector.policy_idbios_versionpod_ip4
device_policies.network-scan-content.policy_typedevice_policies.prevention.applieddevice_policies.vulnerability-management.policy_type
device_policies.remote_response.appliedos_product_namedevice_policies.sensor_update.uninstall_protection
device_policies.kubernetes-admission-control.policy_idservice_provider_account_iddevice_policies.network-scan-content.policy_id
device_policies.fem-browser-extension-control.policy_typedevice_policies.host-retention.policy_typedevice_policies.firewall.policy_id
device_policies.remote_response.policy_typeconfig_id_builddevice_policies.data-protection.policy_id
device_policies.firewall.policy_typepointer_sizechassis_type_desc
device_policies.ztl.policy_typedevice_policies.vulnerability-management.policy_idserial_number
device_policies.application-abuse-prevention.appliedlast_login_timestampdevice_policies.airlock.policy_id
device_policies.jumpcloud.applieddevice_policies.sca.policy_idgroup_hash
k8s_cluster_versionlast_rebootlast_login_user
device_policies.prevention.policy_iddevice_policies.sensor_update.appliedmanaged_apps.airlock.version
rtr_statedevice_policies.logscale-collector.policy_typedevice_policies.logscale-collector.applied
policies.applieddevice_policies.airlock.applieddevice_policies.data-protection.policy_type
device_policies.remote_response.policy_idpod_hostnamedevice_policies.aidr.policy_id
agent_load_flagsdevice_policies.ztl.applieddevice_policies.system-tray.policy_type
device_policies.content-update.policy_idmanaged_apps.identity-protection.versioncpu_signature
kernel_versionrelease_groupdevice_policies.kubernetes-admission-control.policy_type
device_policies.system-tray.policy_idconnection_ipdefault_gateway_ip
config_id_platformhostnamedevice_policies.jumpcloud.policy_type
local_ip.rawtagshost_utc_offset
product_type_descpolicy_iddevice_policies.sensor_update.policy_type
device_policies.device_control.appliedemailinternet_exposure
cloud_service_compartment_iddevice_policies.browser-extension.policy_typeou
product_typedevice_policies.device_control.policy_typedevice_policies.aidr.policy_type
first_login_timestampsystem_product_namemodified_timestamp
device_policies.jumpcloud.policy_iddevice_policies.consumer-subscription.policy_typedevice_policies.aws-verified-access.policy_id
zone_groupdevice_policies.application-abuse-prevention.policy_typeexternal_ip
machine_domaindevice_policies.airlock.policy_typedevice_policies.exposure-management.policy_type
os_version_alllicense_activation_state
filesystem_containment_statusminor_versiondevice_policies.identity-endpoint.applied
device_policies.consumer-subscription.policy_iddevice_policies.data-protection-cloud.policy_typedevice_policies.browser-extension.policy_id
config_id_basefirst_seenlast_login_uid
policies.policy_iddevice_policies.identity-protection.policy_typedevice_policies.vulnerability-management.applied
device_policies.cloud-ml.applieddevice_policies.firewall.rule_set_idbios_manufacturer
major_versiondevice_policies.automox.policy_iddevice_policies.netskope.policy_type
device_policies.netskope.applieddevice_policies.identity-protection.applieddevice_policies.it-automation.policy_id
managed_apps.automox.versionagent_versionsystem_manufacturer
device_policies.fim.appliedk8s_cluster_git_versiondevice_policies.browser-extension.applied
device_policies.exposure-management.policy_iddevice_policies.fem-browser-extension-control.policy_iddevice_id
device_policies.cloud-ml.policy_typedevice_policies.sca.policy_typepod_service_account_name
linux_sensor_modedevice_policies.fem-browser-extension-control.applieddevice_policies.identity-endpoint.policy_id
device_policies.kubernetes-admission-control.applieddevice_policies.host-retention.policy_idservice_provider
pod_host_ip6device_policies.automox.policy_typedevice_policies.identity-protection.policy_id
device_policies.cloud-ml.policy_iddevice_policies.it-automation.applieddevice_policies.aws-verified-access.policy_type
pod_labelsk8s_cluster_iddetection_suppression_status
last_seendevice_policies.identity-endpoint.policy_typedevice_policies.system-tray.applied
device_policies.content-update.policy_typemanaged_apps.jumpcloud.versionmanaged_apps.aws-verified-access.version
pod_annotationsdeployment_typecid
statusdevice_policies.consumer-subscription.applieddevice_policies.content-update.applied
device_policies.mobile.policy_typepod_namedevice_policies.network-scan-content.applied
device_policies.device_control.policy_iddevice_policies.fim.policy_id
filter query · string
The filter expression that should be used to limit the results. This should be supplied for each consecutive call.
fields query · string
The fields to return, comma delimited if specifying more than one field. For example: fields=hostname,device_id would return device records only containing the hostname and device_id
parameters query · dictionary
Full query string parameters payload in JSON format. Not required when using other keywords.
from falconpy import Hosts
falcon = Hosts(client_id=CLIENT_ID,
client_secret=CLIENT_SECRET
)
response = falcon.query_hidden_devices_combined(filter="string",
fields="string",
limit=integer,
offset="string",
sort="string")
print(response)
[
{
"agent_load_flags": "string",
"agent_local_time": "string",
"agent_version": "string",
"base_image_version": "string",
"bios_manufacturer": "string",
"bios_version": "string",
"build_number": "string",
"chassis_type": "string",
"chassis_type_desc": "string",
"cid": "string",
"cloud_service_compartment_id": "string",
"config_id_base": "string",
"config_id_build": "string",
"config_id_platform": "string",
"connection_ip": "string",
"connection_mac_address": "string",
"cpu_signature": "string",
"cpu_vendor": "string",
"criticality": "string",
"default_gateway_ip": "string",
"deployment_type": "string",
"detection_suppression_status": "string",
"device_id": "string",
"device_policies": {},
"email": "string",
"external_ip": "string",
"filesystem_containment_status": "string",
"first_login_timestamp": "string",
"first_seen": "string",
"group_hash": "string",
"groups": [],
"host_hidden_status": "string",
"host_utc_offset": "string",
"hostname": "string",
"instance_id": "string",
"k8s_cluster_git_version": "string",
"k8s_cluster_id": "string",
"k8s_cluster_version": "string",
"kernel_version": "string",
"last_login_timestamp": "string",
"last_login_uid": "string",
"last_login_user": "string",
"last_login_user_sid": "string",
"last_reboot": "string",
"last_seen": "string",
"linux_sensor_mode": "string",
"local_ip": "string",
"mac_address": "string",
"machine_domain": "string",
"major_version": "string",
"managed_apps": {},
"meta": {},
"migration_completed_time": "string",
"minor_version": "string",
"modified_timestamp": "string",
"notes": [],
"os_build": "string",
"os_product_name": "string",
"os_version": "string",
"ou": [],
"platform_id": "string",
"platform_name": "string",
"pod_annotations": [],
"pod_host_ip4": "string",
"pod_host_ip6": "string",
"pod_hostname": "string",
"pod_id": "string",
"pod_ip4": "string",
"pod_ip6": "string",
"pod_labels": [],
"pod_name": "string",
"pod_namespace": "string",
"pod_service_account_name": "string",
"pointer_size": "string",
"policies": [],
"product_type": "string",
"product_type_desc": "string",
"provision_status": "string",
"reduced_functionality_mode": "string",
"release_group": "string",
"rtr_state": "string",
"safe_mode": "string",
"serial_number": "string",
"service_pack_major": "string",
"service_pack_minor": "string",
"service_provider": "string",
"service_provider_account_id": "string",
"site_name": "string",
"status": "string",
"system_manufacturer": "string",
"system_product_name": "string",
"tags": [],
"zone_group": "string"
}
]


Permanently delete hosts from the system.

Method POST
Route /devices/entities/devices-actions-delete/v1
Scope Delete Managed Assets: WRITE
PEP 8 devices_actions_delete_v1
body body · dictionary
Full body payload as JSON formatted dictionary.
action_parameters body · array
The action_parameters value.
filter body · string
The filter value.
ids body · array
The ids value.
from falconpy import Hosts
falcon = Hosts(client_id=CLIENT_ID,
client_secret=CLIENT_SECRET
)
id_list = 'ID1,ID2,ID3' # Can also pass a list here: ['ID1', 'ID2', 'ID3']
response = falcon.devices_actions_delete_v1(action_parameters=["string"],
filter="string",
ids=id_list)
print(response)
{
"errors": [
{
"code": 0,
"id": "string",
"message": "string"
}
],
"meta": {
"pagination": {
"limit": 0,
"offset": 0,
"total": 0
},
"powered_by": "string",
"query_time": 0.0,
"trace_id": "string",
"writes": {
"resources_affected": 0
}
},
"resources": [
{
"id": "string",
"path": "string"
}
]
}


Performs the specified action on the provided group IDs.

Method POST
Route /devices/entities/group-actions/v1
Scope Host groups: WRITE
PEP 8 perform_group_action
body body · dictionary
Full body payload as JSON formatted dictionary.
action_parameters body · array
Action parameter payload.
ids query · string or list of strings
The group ids to act on
action_name query · string
The action to perform.
Available values (3)
add_group_memberremove_group_memberremove_all
disable_hostname_check query · boolean
Bool to disable hostname check on add-member
parameters query · dictionary
Full query string parameters payload in JSON format. Not required when using other keywords.
from falconpy import Hosts
falcon = Hosts(client_id=CLIENT_ID,
client_secret=CLIENT_SECRET
)
id_list = 'ID1,ID2,ID3' # Can also pass a list here: ['ID1', 'ID2', 'ID3']
action_parameters = [
{
"name": "string",
"value": "string"
}
]
response = falcon.perform_group_action(action_name="string",
action_parameters=action_parameters,
disable_hostname_check=boolean,
ids=id_list)
print(response)
[
{
"assignment_rule": "string",
"cid": "string",
"created_by": "string",
"created_timestamp": "string",
"description": "string",
"group_type": "string",
"id": "string",
"meta": {},
"modified_by": "string",
"modified_timestamp": "string",
"name": "string"
}
]


Get details on one or more hosts by providing host IDs in a POST body.

Method POST
Route /devices/entities/devices/v2
Scope Hosts: READ
PEP 8 get_device_details
ids body · string or list of strings
AID(s) of the hosts to retrieve.
from falconpy import Hosts
falcon = Hosts(client_id=CLIENT_ID,
client_secret=CLIENT_SECRET
)
id_list = 'ID1,ID2,ID3' # Can also pass a list here: ['ID1', 'ID2', 'ID3']
response = falcon.get_device_details(ids=id_list)
print(response)


Get details on one or more hosts by providing agent IDs (AID).

Method GET
Route /devices/entities/devices/v1
PEP 8 get_device_details_v1
ids query · string or list of strings
The host agentIDs used to get details on
parameters query · dictionary
Full query string parameters payload in JSON format. Not required when using other keywords.
from falconpy import Hosts
falcon = Hosts(client_id=CLIENT_ID,
client_secret=CLIENT_SECRET
)
id_list = 'ID1,ID2,ID3' # Can also pass a list here: ['ID1', 'ID2', 'ID3']
response = falcon.get_device_details_v1(ids=id_list)
print(response)


Get details on one or more hosts by providing host IDs as a query parameter.

Method GET
Route /devices/entities/devices/v2
Scope Hosts: READ
PEP 8 get_device_details_v2
ids query · string or list of strings
The host agentIDs used to get details on
parameters query · dictionary
Full query string parameters payload in JSON format. Not required when using other keywords.
from falconpy import Hosts
falcon = Hosts(client_id=CLIENT_ID,
client_secret=CLIENT_SECRET
)
id_list = 'ID1,ID2,ID3' # Can also pass a list here: ['ID1', 'ID2', 'ID3']
response = falcon.get_device_details_v2(ids=id_list)
print(response)
[
{
"agent_load_flags": "string",
"agent_local_time": "string",
"agent_version": "string",
"base_image_version": "string",
"bios_manufacturer": "string",
"bios_version": "string",
"build_number": "string",
"chassis_type": "string",
"chassis_type_desc": "string",
"cid": "string",
"cloud_service_compartment_id": "string",
"config_id_base": "string",
"config_id_build": "string",
"config_id_platform": "string",
"connection_ip": "string",
"connection_mac_address": "string",
"cpu_signature": "string",
"cpu_vendor": "string",
"criticality": "string",
"default_gateway_ip": "string",
"deployment_type": "string",
"detection_suppression_status": "string",
"device_id": "string",
"device_policies": {},
"email": "string",
"external_ip": "string",
"filesystem_containment_status": "string",
"first_login_timestamp": "string",
"first_seen": "string",
"group_hash": "string",
"groups": [],
"host_hidden_status": "string",
"host_utc_offset": "string",
"hostname": "string",
"instance_id": "string",
"k8s_cluster_git_version": "string",
"k8s_cluster_id": "string",
"k8s_cluster_version": "string",
"kernel_version": "string",
"last_login_timestamp": "string",
"last_login_uid": "string",
"last_login_user": "string",
"last_login_user_sid": "string",
"last_reboot": "string",
"last_seen": "string",
"linux_sensor_mode": "string",
"local_ip": "string",
"mac_address": "string",
"machine_domain": "string",
"major_version": "string",
"managed_apps": {},
"meta": {},
"migration_completed_time": "string",
"minor_version": "string",
"modified_timestamp": "string",
"notes": [],
"os_build": "string",
"os_product_name": "string",
"os_version": "string",
"ou": [],
"platform_id": "string",
"platform_name": "string",
"pod_annotations": [],
"pod_host_ip4": "string",
"pod_host_ip6": "string",
"pod_hostname": "string",
"pod_id": "string",
"pod_ip4": "string",
"pod_ip6": "string",
"pod_labels": [],
"pod_name": "string",
"pod_namespace": "string",
"pod_service_account_name": "string",
"pointer_size": "string",
"policies": [],
"product_type": "string",
"product_type_desc": "string",
"provision_status": "string",
"reduced_functionality_mode": "string",
"release_group": "string",
"rtr_state": "string",
"safe_mode": "string",
"serial_number": "string",
"service_pack_major": "string",
"service_pack_minor": "string",
"service_provider": "string",
"service_provider_account_id": "string",
"site_name": "string",
"status": "string",
"system_manufacturer": "string",
"system_product_name": "string",
"tags": [],
"zone_group": "string"
}
]


Get the online status for one or more hosts by specifying each host’s unique ID.

Method GET
Route /devices/entities/online-state/v1
Scope Hosts: READ
PEP 8 get_online_state
ids query · string or list of strings
The unique ID of the host to get the online status of.
parameters query · dictionary
Full query string parameters payload in JSON format. Not required when using other keywords.
from falconpy import Hosts
falcon = Hosts(client_id=CLIENT_ID,
client_secret=CLIENT_SECRET
)
id_list = 'ID1,ID2,ID3' # Can also pass a list here: ['ID1', 'ID2', 'ID3']
response = falcon.get_online_state(ids=id_list)
print(response)
[
{
"cid": "string",
"id": "string",
"last_seen": "string",
"state": "string"
}
]


Take various actions on the hosts in your environment.

Method POST
Route /devices/entities/devices-actions/v2
Scope Hosts: WRITE
PEP 8 perform_action
body body · dictionary
Full body payload as JSON formatted dictionary.
action_parameters body · array
ids body · array
AID(s) to perform actions against.
action_name query · string
Specify one of these actions: - contain - This action contains the host, which stops any network communications to locations other than the CrowdStrike cloud and IPs specified in your containment policy - lift_containment: This action lifts containment on the host, which returns its network communications to normal - hide_host: This action will delete a host. After the host is deleted, no new detections for that host will be reported via UI or APIs - unhide_host: This action will restore a host. Detection reporting will resume after the host is restored
Available values (6)
contain
This action contains the host, which stops any network communications to locations other than the CrowdStrike cloud and IPs specified in your containment policy
detection_suppress
Supress detections for the host.
detection_unsuppress
Allow detections for the host.
lift_containment
This action lifts containment on the host, which returns its network communications to normal
hide_host
This action will delete a host. After the host is deleted, no new detections for that host will be reported via UI or APIs
unhide_host
This action will restore a host. Detection reporting will resume after the host is restored
parameters query · dictionary
Full query string parameters payload in JSON format. Not required when using other keywords.
note body · string
a custom note that is attached to the action.
from falconpy import Hosts
falcon = Hosts(client_id=CLIENT_ID,
client_secret=CLIENT_SECRET
)
id_list = 'ID1,ID2,ID3' # Can also pass a list here: ['ID1', 'ID2', 'ID3']
response = falcon.perform_action(action_name="string",
ids=id_list,
note="string")
print(response)
{
"errors": [
{
"code": 0,
"id": "string",
"message": "string"
}
],
"meta": {
"pagination": {
"limit": 0,
"offset": 0,
"total": 0
},
"powered_by": "string",
"query_time": 0.0,
"trace_id": "string",
"writes": {
"resources_affected": 0
}
},
"resources": [
{
"id": "string",
"path": "string"
}
]
}


Get details on one or more hosts by providing host IDs in a POST body.

Method POST
Route /devices/entities/devices/v2
Scope Hosts: READ
PEP 8 get_device_details
body body · dictionary
Full body payload as JSON formatted dictionary.
ids body · array
AID(s) of the hosts to retrieve.
from falconpy import Hosts
falcon = Hosts(client_id=CLIENT_ID,
client_secret=CLIENT_SECRET
)
id_list = 'ID1,ID2,ID3' # Can also pass a list here: ['ID1', 'ID2', 'ID3']
response = falcon.get_device_details(ids=id_list)
print(response)
[
{
"agent_load_flags": "string",
"agent_local_time": "string",
"agent_version": "string",
"base_image_version": "string",
"bios_manufacturer": "string",
"bios_version": "string",
"build_number": "string",
"chassis_type": "string",
"chassis_type_desc": "string",
"cid": "string",
"cloud_service_compartment_id": "string",
"config_id_base": "string",
"config_id_build": "string",
"config_id_platform": "string",
"connection_ip": "string",
"connection_mac_address": "string",
"cpu_signature": "string",
"cpu_vendor": "string",
"criticality": "string",
"default_gateway_ip": "string",
"deployment_type": "string",
"detection_suppression_status": "string",
"device_id": "string",
"device_policies": {},
"email": "string",
"external_ip": "string",
"filesystem_containment_status": "string",
"first_login_timestamp": "string",
"first_seen": "string",
"group_hash": "string",
"groups": [],
"host_hidden_status": "string",
"host_utc_offset": "string",
"hostname": "string",
"instance_id": "string",
"k8s_cluster_git_version": "string",
"k8s_cluster_id": "string",
"k8s_cluster_version": "string",
"kernel_version": "string",
"last_login_timestamp": "string",
"last_login_uid": "string",
"last_login_user": "string",
"last_login_user_sid": "string",
"last_reboot": "string",
"last_seen": "string",
"linux_sensor_mode": "string",
"local_ip": "string",
"mac_address": "string",
"machine_domain": "string",
"major_version": "string",
"managed_apps": {},
"meta": {},
"migration_completed_time": "string",
"minor_version": "string",
"modified_timestamp": "string",
"notes": [],
"os_build": "string",
"os_product_name": "string",
"os_version": "string",
"ou": [],
"platform_id": "string",
"platform_name": "string",
"pod_annotations": [],
"pod_host_ip4": "string",
"pod_host_ip6": "string",
"pod_hostname": "string",
"pod_id": "string",
"pod_ip4": "string",
"pod_ip6": "string",
"pod_labels": [],
"pod_name": "string",
"pod_namespace": "string",
"pod_service_account_name": "string",
"pointer_size": "string",
"policies": [],
"product_type": "string",
"product_type_desc": "string",
"provision_status": "string",
"reduced_functionality_mode": "string",
"release_group": "string",
"rtr_state": "string",
"safe_mode": "string",
"serial_number": "string",
"service_pack_major": "string",
"service_pack_minor": "string",
"service_provider": "string",
"service_provider_account_id": "string",
"site_name": "string",
"status": "string",
"system_manufacturer": "string",
"system_product_name": "string",
"tags": [],
"zone_group": "string"
}
]


Retrieve details about recent login sessions for a set of devices.

Method POST
Route /devices/combined/devices/login-history/v1
Scope Hosts: READ
PEP 8 query_device_login_history_v1
body body · dictionary
Full body payload as JSON formatted dictionary.
ids body · array
AID(s) of the hosts to retrieve. Supports a maximum of 500 IDs.
from falconpy import Hosts
falcon = Hosts(client_id=CLIENT_ID,
client_secret=CLIENT_SECRET
)
id_list = 'ID1,ID2,ID3' # Can also pass a list here: ['ID1', 'ID2', 'ID3']
response = falcon.query_device_login_history_v1(ids=id_list)
print(response)
[
{
"cid": "string",
"device_id": "string",
"recent_logins": []
}
]


Retrieve details about recent interactive login sessions for a set of devices powered by the Host Timeline.

Method POST
Route /devices/combined/devices/login-history/v2
Scope Hosts: READ
PEP 8 query_device_login_history_v2
body body · dictionary
Full body payload as JSON formatted dictionary.
ids body · array
AID(s) of the hosts to retrieve. Supports a maximum of 10 IDs.
limit query · integer
The maximum number of results to return [1-100].
from query · string
The inclusive beginning of the time window to search.
to query · string
The inclusive end of the time window to search.
parameters query · dictionary
Full query string parameters payload in JSON format. Not required when using other keywords.
from falconpy import Hosts
falcon = Hosts(client_id=CLIENT_ID,
client_secret=CLIENT_SECRET
)
id_list = 'ID1,ID2,ID3' # Can also pass a list here: ['ID1', 'ID2', 'ID3']
response = falcon.query_device_login_history_v2(ids=id_list,
limit=integer,
from="string",
to="string")
print(response)
[
{
"cid": "string",
"device_id": "string",
"recent_logins": []
}
]


Search for hosts in your environment by platform, hostname, IP, and other criteria.

Method GET
Route /devices/queries/devices/v1
Scope Hosts: READ
PEP 8 query_devices_by_filter
offset query · integer
The offset to start retrieving records from
limit query · integer
The maximum records to return. [1-5000]
sort query · string
The property to sort by (e.g. status.desc or hostname.asc)
filter query · string
The filter expression that should be used to limit the results
Available values (36)
device_id
The ID of the device. Ex: 061a51ec742c44624a176f079d742052
agent_load_flags
CrowdStrike agent configuration notes
agent_version
CrowdStrike agent configuration notes
bios_manufacturer
Bios manufacture name. Ex: Phoenix Technologies LTD
bios_version
Bios version. Ex: 6.00
config_id_base
CrowdStrike agent configuration notes
config_id_build
CrowdStrike agent configuration notes
config_id_platform
CrowdStrike agent configuration notes
cpu_signature
The CPU signature of the device. Ex: GenuineIntel
deployment_type
Linux deployment type: Standard DaemonSet
external_ip
External IP of the device, as seen by CrowdStrike. Ex: 192.0.2.100
first_seen
Timestamp of device’s first connection to Falcon, in UTC date format (“YYYY-MM-DDTHH:MM:SSZ”). Ex: 2016-07-19T11:14:15Z
hostname
The name of the machine. Supports prefix and suffix searching with *wildcard, so you can search for terms like abc* and *abc. Ex: WinPC9251
last_login_timestamp
User logon event timestamp, once a week.
last_seen
Timestamp of device’s most recent connection to Falcon, in UTC date format (“YYYY-MM-DDTHH:MM:SSZ”). Ex: 2016-07-19T11:14:15Z
linux_sensor_mode
Linux sensor mode: Kernel Mode User Mode
local_ip
The device’s local IP address. As a device management parameter, this is the IP address of this device at the last time it connected to the CrowdStrike Cloud. Ex: 192.0.2.1
local_ip.raw
A portion of the device’s local IP address, used only for searches that include wildcard characters. Using a wildcard requires specific syntax: when you specify an IP address with this parameter, prefix the IP address with an asterisk (*) and enclose the IP address in single quotes. Search for a device with the IP address 192.0.2.100: local_ip.raw:*‘192.0.2.*’ local_ip.raw:*‘*.0.2.100’
mac_address
The MAC address of the device Ex: 2001:db8:ffff:ffff:ffff:ffff:ffff:ffff
machine_domain
Active Directory domain name.
major_version
Major version of the Operating System
minor_version
Minor version of the Operating System
modified_timestamp
The last time that the machine record was updated. Can include status like containment status changes or configuration group changes.
os_version
Operating system version. Ex: Windows 7
ou
Active Directory organizational unit name.
platform_id
CrowdStrike agent configuration notes
platform_name
Operating system platform. Available options: Windows Mac Linux
product_type_desc
Name of product type. Workstation Server Domain Controller
reduced_functionality_mode
Reduced functionality mode (RFM) status: yes no _Unknown_ (displayed as a blank string) Unknown is used for hosts with an unavailable RFM status: The sensor was deployed less than 24 hours ago and has not yet provided an RFM status. The sensor version does not support RFM.
release_group
Name of the Falcon deployment group, if the this machine is part of a Falcon sensor deployment group.
serial_number
Serial number of the device. Ex: C42AFKEBM563
site_name
Active Directory site name.
status
Containment Status of the machine. “Normal” denotes good operations; other values might mean reduced functionality or support. Possible values: normal containment_pending contained lift_containment_pending
system_manufacturer
Name of system manufacturer Ex: VMware, Inc.
system_product_name
Name of system product Ex: VMware Virtual Platform
tags
Falcon grouping tags
parameters query · dictionary
Full query string parameters payload in JSON format. Not required when using other keywords.
from falconpy import Hosts
falcon = Hosts(client_id=CLIENT_ID,
client_secret=CLIENT_SECRET
)
response = falcon.query_devices_by_filter(filter="string",
limit=integer,
offset=integer,
sort="string")
print(response)
[
"string"
]


Search for hosts in your environment by platform, hostname, IP, and other criteria with continuous pagination capability (based on offset pointer which expires after 2 minutes with no maximum limit)

Method GET
Route /devices/queries/devices-scroll/v1
Scope Hosts: READ
PEP 8 query_devices_by_filter_scroll
offset query · string
The offset to page from, provided from the previous scroll call, for the next result set. For the first call, do not supply an offset.
limit query · integer
The maximum records to return. [1-10000]
sort query · string
The property to sort by (e.g. status.desc or hostname.asc)
filter query · string
The filter expression that should be used to limit the results
Available values (36)
device_id
The ID of the device. Ex: 061a51ec742c44624a176f079d742052
agent_load_flags
CrowdStrike agent configuration notes
agent_version
CrowdStrike agent configuration notes
bios_manufacturer
Bios manufacture name. Ex: Phoenix Technologies LTD
bios_version
Bios version. Ex: 6.00
config_id_base
CrowdStrike agent configuration notes
config_id_build
CrowdStrike agent configuration notes
config_id_platform
CrowdStrike agent configuration notes
cpu_signature
The CPU signature of the device. Ex: GenuineIntel
deployment_type
Linux deployment type: Standard DaemonSet
external_ip
External IP of the device, as seen by CrowdStrike. Ex: 192.0.2.100
first_seen
Timestamp of device’s first connection to Falcon, in UTC date format (“YYYY-MM-DDTHH:MM:SSZ”). Ex: 2016-07-19T11:14:15Z
hostname
The name of the machine. Supports prefix and suffix searching with *wildcard, so you can search for terms like abc* and *abc. Ex: WinPC9251
last_login_timestamp
User logon event timestamp, once a week.
last_seen
Timestamp of device’s most recent connection to Falcon, in UTC date format (“YYYY-MM-DDTHH:MM:SSZ”). Ex: 2016-07-19T11:14:15Z
linux_sensor_mode
Linux sensor mode: Kernel Mode User Mode
local_ip
The device’s local IP address. As a device management parameter, this is the IP address of this device at the last time it connected to the CrowdStrike Cloud. Ex: 192.0.2.1
local_ip.raw
A portion of the device’s local IP address, used only for searches that include wildcard characters. Using a wildcard requires specific syntax: when you specify an IP address with this parameter, prefix the IP address with an asterisk (*) and enclose the IP address in single quotes. Search for a device with the IP address 192.0.2.100: local_ip.raw:*‘192.0.2.*’ local_ip.raw:*‘*.0.2.100’
mac_address
The MAC address of the device Ex: 2001:db8:ffff:ffff:ffff:ffff:ffff:ffff
machine_domain
Active Directory domain name.
major_version
Major version of the Operating System
minor_version
Minor version of the Operating System
modified_timestamp
The last time that the machine record was updated. Can include status like containment status changes or configuration group changes.
os_version
Operating system version. Ex: Windows 7
ou
Active Directory organizational unit name.
platform_id
CrowdStrike agent configuration notes
platform_name
Operating system platform. Available options: Windows Mac Linux
product_type_desc
Name of product type. Workstation Server Domain Controller
reduced_functionality_mode
Reduced functionality mode (RFM) status: yes no _Unknown_ (displayed as a blank string) Unknown is used for hosts with an unavailable RFM status: The sensor was deployed less than 24 hours ago and has not yet provided an RFM status. The sensor version does not support RFM.
release_group
Name of the Falcon deployment group, if the this machine is part of a Falcon sensor deployment group.
serial_number
Serial number of the device. Ex: C42AFKEBM563
site_name
Active Directory site name.
status
Containment Status of the machine. “Normal” denotes good operations; other values might mean reduced functionality or support. Possible values: normal containment_pending contained lift_containment_pending
system_manufacturer
Name of system manufacturer Ex: VMware, Inc.
system_product_name
Name of system product Ex: VMware Virtual Platform
tags
Falcon grouping tags
parameters query · dictionary
Full query string parameters payload in JSON format. Not required when using other keywords.
from falconpy import Hosts
falcon = Hosts(client_id=CLIENT_ID,
client_secret=CLIENT_SECRET
)
response = falcon.query_devices_by_filter_scroll(filter="string",
limit=integer,
offset="string",
sort="string")
print(response)
[
"string"
]


Retrieve history of IP and MAC addresses of devices.

Method POST
Route /devices/combined/devices/network-address-history/v1
Scope Hosts: READ
PEP 8 query_network_address_history
body body · dictionary
Full body payload as JSON formatted dictionary.
ids body · array
AID(s) of the hosts to retrieve.
from falconpy import Hosts
falcon = Hosts(client_id=CLIENT_ID,
client_secret=CLIENT_SECRET
)
id_list = 'ID1,ID2,ID3' # Can also pass a list here: ['ID1', 'ID2', 'ID3']
response = falcon.query_network_address_history(ids=id_list)
print(response)
[
{
"cid": "string",
"device_id": "string",
"history": []
}
]


Retrieve hidden hosts that match the provided filter criteria.

Method GET
Route /devices/queries/devices-hidden/v1
Scope Hosts: READ
PEP 8 query_hidden_devices
offset query · integer
The offset to start retrieving records from
limit query · integer
The maximum records to return. [1-5000]
sort query · string
The property to sort by (e.g. status.desc or hostname.asc)
filter query · string
The filter expression that should be used to limit the results
parameters query · dictionary
Full query string parameters payload in JSON format. Not required when using other keywords.
from falconpy import Hosts
falcon = Hosts(client_id=CLIENT_ID,
client_secret=CLIENT_SECRET
)
response = falcon.query_hidden_devices(filter="string",
limit=integer,
offset=integer,
sort="string")
print(response)
[
"string"
]


Append or remove one or more Falcon Grouping Tags on one or more hosts.

Method PATCH
Route /devices/entities/devices/tags/v1
Scope Hosts: WRITE
PEP 8 update_device_tags
body body · dictionary
Full body payload as JSON formatted dictionary.
action body · string
device_ids body · array
tags body · array
Tag(s) to update.
action_name body · string
action to perform, ‘add’ or ‘remove’.
ids body · string or list of strings
AID(s) of the hosts to update.
from falconpy import Hosts
falcon = Hosts(client_id=CLIENT_ID,
client_secret=CLIENT_SECRET
)
id_list = 'ID1,ID2,ID3' # Can also pass a list here: ['ID1', 'ID2', 'ID3']
response = falcon.update_device_tags(action_name="string",
ids=id_list,
tags=id_list)
print(response)
[
{
"code": 0,
"device_id": "string",
"error": "string",
"updated": false
}
]