---
sourceDocument: Australia Workflow Data Fabric
sourceDocumentLink: https://www.servicenow.com/docs/r/integrate-applications

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Workflow Data Fabric

ft:clusterId :

    - crint

bundleId :

    - crint

workflow :

    - Creator


---

# CrowdStrike Spoke

# CrowdStrike Spoke {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Manage licenses for CrowdStrike Falcon protection suite by fetching details of devices with active Falcon sensors installed and checking license compliance.

## Request apps on the Store {#crowdstrike-spoke__section_sz5_jv3_z3b}

Visit the [ServiceNow Store](https://store.servicenow.com/sn_appstore_store.do#!/store/home) to view all the available apps, and for information about submitting requests to the store. For cumulative release notes information for all released apps, see the [ServiceNow Store version history release notes](https://www.servicenow.com/docs/r/store-release-notes/sn-store-release-notes.html).{#crowdstrike-spoke__inline-send-to-store}

## Integration Hub subscription {#crowdstrike-spoke__section_obc_jvt_pqb}

This spoke requires an Integration Hub subscription. For more information, see [Legal schedules - IntegrationHub overview](https://www.servicenow.com/content/dam/servicenow-assets/public/en-us/doc-type/legal/snc-addendum-integrationhub.pdf).

## Spoke version {#crowdstrike-spoke__section_pbc_jvt_pqb}

CrowdStrike spoke v1.1.0 is the latest version.{#crowdstrike-spoke__rally-ver}

## Spoke requirements {#crowdstrike-spoke__section_qbc_jvt_pqb}

CrowdStrike account with a Falcon administrator role.

## Spoke dependencies {#crowdstrike-spoke__section_sbc_jvt_pqb}

If you're having trouble installing the app, ensure that these dependent plugins are installed:

* ServiceNow Integration Hub Runtime (com.glide.hub.integration.runtime)
* ServiceNow Integration Hub Action Step - REST (com.glide.hub.action_step.rest)
{#crowdstrike-spoke__ul_tbc_jvt_pqb}  
Note:  
Some of these plugins are licensable features and require appropriate licenses when used outside the spoke implementation.

## Spoke actions {#crowdstrike-spoke__section_ubc_jvt_pqb}

The CrowdStrike spoke provides actions to automate CrowdStrike
tasks when events occur in your ServiceNow instance.  
{#crowdstrike-spoke__table_vbc_jvt_pqb__entry__3}

| Category | Action | Description |
|-|-|-|
| Host Management | Look up Active Hosts | Retrieves all active hosts. Active hosts are the hosts on which the last_seen date is greater than the date provided in the Active Since field. |
| Host Management | Look up Host Details | Retrieves details of the hosts for the Device IDs passed in the Host IDs field. |
| Sensor Management | Look up Hourly Sensor Usage | Retrieves a daily breakdown of your Customer Identification (CID) average hourly sensor usage by sensor category. Note: The usage data is retrieved up to two days prior to the current date. |
| Sensor Management | Look up Weekly Sensor Usage | Retrieves a daily breakdown of your CID average weekly sensor usage by sensor category. Note: The usage data is retrieved up to two days prior to the current date. |
[ ]

{#crowdstrike-spoke__table_vbc_jvt_pqb}  
Note:  
This spoke has a Look up User action and Software Asset Management related actions only.

## Connection and credential alias requirements {#crowdstrike-spoke__section_wbc_jvt_pqb}

Integration Hub uses aliases to manage connection
and credential information. Using an alias eliminates the need to configure multiple
credentials and connection information profiles when using multiple environments. If the
connection or credential information changes, you don't need to update any actions that
use the connection. For more information, see [Connections and Credentials](https://www.servicenow.com/docs/access?context=r-credentials&version=australia&pubname=australia-platform-security&ft:locale=en-US).

