Skip to main content

How to Integrate Crowdstrike

In this guide, we'll run through how to integrate Crowdstrike with the Defense.com SIEM platform.

Kara Crimson avatar
Written by Kara Crimson
Updated over a week ago

This integration is available on our Advanced and Enterprise packages.

Creating a new API Client

  1. Sign in to the CrowdStrike Falcon Console.

  2. Go to Support and Resources > API Clients and Keys.

  3. In the OAuth2 API Clients section, click Add New API Client.

  4. Enter a suitable name, such as Defense.com Logs, in the Client Name field. As well as a description.

  5. In the Scopes table, select the Read checkbox for each of the following:

    • Alerts

    • Detections

    • Hosts

    • Actors (Falcon Intelligence)

    • Reports

    • Host Groups

    • Event Streams

  6. Click Create.

  7. In the API Client Created window, copy and securely save the following details:

    • Client ID

    • Secret

    • Base URL

  8. Click Done to finish.

Completing the integration

Once you have created a new API Client, please reach out to our Technical Support team and share the details mentioned above using one time secret to help keep them secure. Our team will then complete the integration and confirm that Crowdstrike is logging to the SIEM platform.

And that's it! You've successfully integrated Crowdstrike πŸŽ‰

Did this answer your question?