When the CrowdStrike service goes down, UIM should generate an informational alert within 30 seconds, which will be saved in UIM.
If the service remains down for 5 minutes, the informational alert should convert to a major severity ticket in ServiceNow.
If the service recovers within 5 minutes, the alert should remain informational in UIM and should not trigger any ServiceNow alerts.
UIM 23.4 and later
Create a new NAS processing rule with attach Crowdstrike.lua Script.