CrowdStrike Falcon Automation Health
Provides the Falcon Fusion workflows and scheduled reports that failed, stalled, missed their schedule, or were disabled.
What this agent does
This read-only agent checks that the automations in CrowdStrike Falcon run as intended. It reads Fusion workflow and scheduled report definitions and their recent executions. It finds executions that failed or stalled, schedules that are overdue, and definitions that are disabled.
The challenge
Teams build Fusion workflows and scheduled reports to contain hosts, notify owners, and brief leaders. When one fails, the console does not alert anyone. The containment step never runs, or the weekly report never arrives. Teams find the failure days later, after the response it was meant to automate is already late.
The solution
The agent separates the health of each definition from the health of its executions. It ranks failed executions and overdue schedules above stalled executions and disabled definitions. It reports a missing execution as a failure only when the schedule shows it is overdue, to enable defenders to fix broken automation before a response depends on it.
Workflow
- 01
Read automations
Read Fusion workflow definitions and executions, and scheduled report definitions and executions.
- 02
Check definitions
Flag disabled definitions and schedules whose next run is more than an hour past.
- 03
Check executions
Flag executions that failed in the last 24 hours and executions still running after 24 hours.
- 04
Report
Publish the queue and counts with automations replaced by stable pseudonyms.
Agent template
# CrowdStrike Falcon Automation Health
## Measurable outcomes
Every failed, stalled, overdue, or disabled Falcon automation is in the ranked health queue. Track the count for each state on every run.
## Procedure
Read the Fusion workflow definitions and executions, and the scheduled report definitions and executions. Flag an execution that failed, errored, timed out, or was cancelled within the last 24 hours as failed. Flag an execution still running or pending after 24 hours as stalled. Flag a schedule as overdue when its next run is more than an hour in the past. Flag each disabled definition. Rank failed and overdue above stalled and disabled. A definition with no executions is healthy unless its schedule is overdue.
## Requirements
It needs read access to Fusion workflows and scheduled reports, and nothing more. A missing permission is not assessed, not healthy. It never launches, retries, resumes, enables, disables, or edits a workflow or report. Reports show the automation type and state, with automations replaced by stable pseudonyms. Related templates
-
Datadog Detection Posture Report
Delivers a weekly report on Datadog Cloud SIEM log ingestion gaps, detection rules that are disabled, erroring, or blind, and anything in the organization that needs an admin, from Security Filter exclusions to silent Agents.
Reporting and Compliance / Security Operations 1 tools -
Datadog Detection Tuning
Finds the Datadog Cloud SIEM detection rules that produce the most noise, reads each one against the signals it raised, and proposes a specific tuning change with the evidence and what it would have missed.
Security Operations 1 tools -
Elastic Security Detection Posture Report
Delivers a weekly report on Elastic Security data stream gaps, detection rules that are failing, warning, or blind, and anything in the deployment that needs an admin, from offline Elastic Agents to lifecycle errors.
Reporting and Compliance / Security Operations 1 tools -
Elastic Security Detection Tuning
Finds the Elastic Security detection rules that produce the most noise, reads each one against the alerts it raised, and proposes a specific tuning change with the evidence and what it would have missed.
Security Operations 1 tools