Skip to main content

CrowdStrike

Pre-requisites
  • CrowdStrike domain
  • CrowdStrike Client ID
  • CrowdStrike API key
NOTE: A user with the Falcon Administrator role is necessary.

Steps to derive prerequisites:
  1. Log in to the Falcon console.
  2. Click Support > API Clients and Keys.
  3. Click + Add new API Client.
  4. Specify a client name and description.
  5. In the API SCOPES section, check Read next to Event Streams and Detections.
  6. Click Add.
  7. Copy the Base URL, Client ID, and Secret values.

Configurations

The following are the configurations to forward CrowdStrike Connector logs to DNIF.‌

image 1-Dec-20-2023-05-11-10-6240-AM

Field Name Description
Connector NameEnter a name for the connector
CrowdStrike domainSelect the CrowdStrike Cloud domain where your integration is hosted
CrowdStrike Client IDEnter the CrowdStrike Client ID
CrowdStrike API keyEnter the CrowdStrike API key
  • Click Save after entering all the required details and click Test Connection, to test the configuration.
  • Connection successful message will be displayed on screen along with the time stamp.

If the connection is not successful an error message will be displayed. Refer Troubleshooting Connector Validations for more details on the error message.

Once the connector is configured, validate if the connector is listed under Collection Status screen with status as Active. This signifies the connector is configured successfully and data is ready to ingest