Skip to main content
{ Security Operations }

CrowdStrike Falcon Automation Health

Provides the Falcon Fusion workflows and scheduled reports that failed, stalled, missed their schedule, or were disabled.

What this agent does

This read-only agent checks that the automations in CrowdStrike Falcon run as intended. It reads Fusion workflow and scheduled report definitions and their recent executions. It finds executions that failed or stalled, schedules that are overdue, and definitions that are disabled.

The challenge

Teams build Fusion workflows and scheduled reports to contain hosts, notify owners, and brief leaders. When one fails, the console does not alert anyone. The containment step never runs, or the weekly report never arrives. Teams find the failure days later, after the response it was meant to automate is already late.

The solution

The agent separates the health of each definition from the health of its executions. It ranks failed executions and overdue schedules above stalled executions and disabled definitions. It reports a missing execution as a failure only when the schedule shows it is overdue, to enable defenders to fix broken automation before a response depends on it.

Workflow

  1. 01

    Read automations

    Read Fusion workflow definitions and executions, and scheduled report definitions and executions.

  2. 02

    Check definitions

    Flag disabled definitions and schedules whose next run is more than an hour past.

  3. 03

    Check executions

    Flag executions that failed in the last 24 hours and executions still running after 24 hours.

  4. 04

    Report

    Publish the queue and counts with automations replaced by stable pseudonyms.

Agent template

# CrowdStrike Falcon Automation Health

## Measurable outcomes

Every failed, stalled, overdue, or disabled Falcon automation is in the ranked health queue. Track the count for each state on every run.

## Procedure

Read the Fusion workflow definitions and executions, and the scheduled report definitions and executions. Flag an execution that failed, errored, timed out, or was cancelled within the last 24 hours as failed. Flag an execution still running or pending after 24 hours as stalled. Flag a schedule as overdue when its next run is more than an hour in the past. Flag each disabled definition. Rank failed and overdue above stalled and disabled. A definition with no executions is healthy unless its schedule is overdue.

## Requirements

It needs read access to Fusion workflows and scheduled reports, and nothing more. A missing permission is not assessed, not healthy. It never launches, retries, resumes, enables, disables, or edits a workflow or report. Reports show the automation type and state, with automations replaced by stable pseudonyms.