CrowdStrike Falcon

Download 57
Last updated Sep 16, 2026

crowdstrike-falcon-devices

Lists the devices registered in CrowdStrike Falcon with their details.

Syntax

crowdstrike-falcon-devices [profile=STRING] [duration=STRING] [from=DATETIME] [to=DATETIME] [order=STRING] [time-filter=STRING] [os=STRING] [only-online=BOOL]

Options

profile=STRING
Optional. Connect profile code of CrowdStrike Falcon
duration=STRING
Optional. Retrieve only devices within the recent time range, based on the field selected by the time-filter option. You should use s(second), m(minute), h(hour), d(day), mon(month) time unit. For example, 10s means the last 10 seconds. The from option takes precedence when both are given.
from=DATETIME
Optional. Start time of range, applied to the field selected by the time-filter option. yyyyMMddHHmmss format. If you omit time part, it will be padded by zero.
to=DATETIME
Optional. End time of range, applied to the field selected by the time-filter option. yyyyMMddHHmmss format. If you omit time part, it will be padded by zero.
order=STRING
Optional. Retrieve direction of the field selected by the time-filter option. desc or asc. desc by default.
time-filter=STRING
Optional. Reference field of the duration, from, to and order options. 'updated' uses the time the device record was last updated, 'last_seen' uses the time the device was last seen. updated by default.
os=STRING
Optional. Filter by operating system. Available values: 'windows', 'mac', 'linux'. Specify only one value, multiple values are not supported. All devices are retrieved if omitted.
only-online=BOOL
Optional. Specify t to output only online devices. t or f (default: f, both online and offline devices are retrieved)

Output fields

FieldTypeNameDescription
profileStringConnect profileCrowdStrike Falcon connect profile code
device_idStringDevice IDUnique device identifier
cidStringCustomer IDCustomer identifier
agent_load_flagsStringAgent Load FlagsAgent load flags value
agent_local_timeDateAgent Local Time
agent_versionStringAgent VersionFalcon agent version
bios_manufacturerStringBIOS ManufacturerBIOS manufacturer name
bios_versionStringBIOS VersionBIOS version number
os_build_numberStringOS Build NumberOS build number
config_id_baseStringConfig ID BaseConfiguration ID base value
config_id_buildStringConfig ID BuildConfiguration ID build value
config_id_platformStringConfig ID PlatformConfiguration ID platform value
cpu_signatureStringCPU SignatureCPU signature
cpu_vendorStringCPU VendorCPU vendor name
host_ipIPHost IPExternal IP address of the host
macStringMacMAC address
hostnameStringHostnameHost name
first_seenDateFirst Seen
last_seenDateLast Seen
last_login_timestampDateLast Login TimestampLast user login time
last_login_userStringLast Login UserUsername of last login
last_login_user_sidStringLast Login User SIDSecurity identifier of last login user
last_login_uidStringLast Login UIDUser ID of last login
first_login_timestampDateFirst Login TimestampFirst user login time
first_login_userStringFirst Login UserUsername of first login
local_ipIPLocal IPInternal IP address of the host
machine_domainStringMachine DomainDomain name of the machine
os_major_versionStringOS Major VersionOS major version number
os_minor_versionStringOS Minor VersionOS minor version number
os_versionStringOS VersionOperating system version
os_buildStringOS BuildOS build identifier
os_product_nameStringOS Product NameFull OS product name
platform_idStringPlatform IDPlatform identifier
os_familyStringOS Familye.g. Windows, Mac, Linux
product_typeStringProduct TypeProduct type identifier
product_type_descStringProduct Type DescriptionProduct type description
provision_statusStringProvision StatusDevice provisioning status
reduced_functionality_modeStringReduced Functionality ModeReduced functionality mode status
rtr_stateStringRTR StateReal Time Response connection state
serial_numberStringSerial NumberDevice serial number
os_service_pack_minorStringOS Service Pack MinorService pack minor version
pointer_sizeStringPointer SizeSystem pointer size (32/64 bit)
site_nameStringSite NameDevice site name
statusStringStatusDevice status
system_manufacturerStringSystem ManufacturerSystem manufacturer name
system_product_nameStringSystem Product NameSystem product name
updatedDateUpdatedLast updated
last_rebootDateLast RebootLast system reboot time
connection_ipIPConnection IPCurrent connection IP address
default_gateway_ipIPDefault Gateway IPDefault gateway IP address
connection_macStringConnection MACCurrent connection MAC address
chassis_typeStringChassis TypeHardware chassis type identifier
chassis_type_descStringChassis Type DescriptionHardware chassis type description
groupsListGroupsDevice groups
group_hashStringGroup HashHash value of device groups
tagsListTagsDevice tags
metaMapMetaAdditional metadata information
kernel_versionStringKernel VersionOperating system kernel version
policiesListPoliciesapplied policies
device_policiesListDevice Policiesdevice-specific policies