Sync CrowdStrike Spotlight vulnerabilities to Jira and auto-patch

Starting promptUse this prompt as a starting point to build your workflow.

Build a scheduled workflow that fetches all open CrowdStrike Spotlight vulnerabilities and groups them by CVE. For each CVE, check Jira for an existing issue: create one if new, or reopen and update it if previously closed but new machines are now affected. Attach the impacted host list. Optionally call Automox to initiate patches for the affected devices. Paginate the Spotlight API, deduplicate by CVE+host, retry failures, and avoid duplicate Jira issues. Output a summary of issues created, reopened, and patches triggered.

New to Tines?Sign up free for Tines 3B Explore Edition

What this prompt builds

Turn open CrowdStrike Spotlight findings into deduplicated Jira issues and kick off patching via Automox.

The problem

Vulnerability data in CrowdStrike Spotlight doesn't translate into tracked, owned remediation work, so CVEs sit unpatched and the same finding gets re-triaged repeatedly. Teams lose the thread on which machines a CVE affects over time.

Solution and impact

This workflow pulls open Spotlight vulnerabilities, groups them by CVE, and creates new Jira issues or reopens closed ones when fresh hosts are impacted, optionally triggering Automox patches. Remediation becomes tracked, deduplicated, and partly automated, shrinking exposure windows.

Sync CrowdStrike Spotlight vulnerabilities to Jira and auto-patch | Tines 3B examples | Tines