Skip to main content
Ani1337
New Member
October 20, 2025
Solved

Crowdstrike connector : Many actions use deprecated API endpoints

  • October 20, 2025
  • 2 replies
  • 1293 views

Hello,
A little surprise today while I was creating my playbook, it seems that the following actions are still using the CrowdStrike API endpoints that were decommissioned on September 30th.

 

detection_search : use /detects/queries/detects/v1

detection_aggregates : use /detects/aggregates/detects/GET/v1

update_detection : use /detects/entities/detects/v2

get_detection_details : use /detects/entities/summaries/GET/v1

 

In accordance with the CrowdStrike documentation, it appears that these API endpoints have been merged into the Alerts section. The documentation say "Detections are no longer stored in their legacy format."

https://falcon.eu-1.crowdstrike.com/documentation/page/d02475a5/converting-from-detects-api-to-alerts-api#

 

Could we please, in the next update, either remove these actions or update them to use the correct endpoints (for example, the ones already used in the update_alert action) ?

    Best answer by snikam

    Hi 
    FortiSOAR R&D team is working on developing new connector version which will have these fixes.
    Thank you!

    2 replies

    snikam
    Staff
    snikamAnswer
    Staff
    October 21, 2025

    Hi 
    FortiSOAR R&D team is working on developing new connector version which will have these fixes.
    Thank you!

    anerot-forti
    Staff
    Staff
    October 21, 2025