Skip to content

fusion_soar_workflow

Manages a Falcon Fusion SOAR workflow. The workflow is defined by a YAML document in the format the Falcon console exports, so the easiest way to author one is to build it in the console, export it, and pass the file to definition. Only the keys set in definition are managed: keys the API adds, and changes made outside Terraform to keys the configuration does not set, are not reported as drift. The API sets the trigger’s name and each action’s default_name itself, so values given for them are ignored. The API drops keys it does not recognize, so a misspelled key fails the apply with the path of the key that was dropped. A definition exported from another CID can reference activities and plugin configurations that do not exist in this CID; the workflow is then saved with validation errors and cannot be enabled.

The following API scopes are required:

  • Workflow: READ
  • Workflow: WRITE
terraform {
required_providers {
crowdstrike = {
source = "crowdstrike/crowdstrike"
}
}
}
provider "crowdstrike" {}
# The definition uses the YAML format the Falcon console exports. To manage an
# existing workflow, export it from the console and load the exported file.
resource "crowdstrike_fusion_soar_workflow" "from_file" {
enabled = true
definition = file("${path.module}/workflow.yaml")
}
# The definition can also be written inline.
resource "crowdstrike_fusion_soar_workflow" "inline" {
enabled = true
definition = <<-EOT
name: tf-example-inline-workflow
description: Pauses for one minute when run on demand.
trigger:
next:
- Sleep
name: On demand
type: On demand
actions:
Sleep:
id: 4f1af1ae4c13dc1e3bcd725f8dc0f63b
properties:
sleep_time: 1m
version_constraint: ~1
EOT
}
output "fusion_soar_workflow_from_file" {
value = crowdstrike_fusion_soar_workflow.from_file
}
output "fusion_soar_workflow_inline" {
value = crowdstrike_fusion_soar_workflow.inline
}
  • definition (String) The workflow definition as a YAML document, in the format produced by exporting a workflow from the Falcon console. It must set a top-level name, which must be unique in the CID. Renaming the workflow updates it in place. Actions should set version_constraint; the API treats an omitted constraint as ~0.
  • enabled (Boolean) Whether the workflow is enabled and runs when its trigger fires. A workflow with validation errors cannot be enabled. Defaults to false.
  • id (String) Identifier for the workflow.

Import is supported using the following syntax:

Terminal window
# A Fusion SOAR workflow can be imported by specifying the workflow ID.
# Import reads the definition from the API's YAML export, which is formatted
# differently from most configurations, so the first apply after import
# updates the workflow once to store the configured definition.
terraform import crowdstrike_fusion_soar_workflow.example 7fb858a949034a0cbca175f660f1e769