This integration is available on our Advanced and Enterprise packages.
Creating a new API Client
Sign in to the CrowdStrike Falcon Console.
Go to Support and Resources > API Clients and Keys.
In the OAuth2 API Clients section, click Add New API Client.
Enter a suitable name, such as Defense.com Logs, in the Client Name field. As well as a description.
In the Scopes table, select the Read checkbox for each of the following:
Alerts
Detections
Hosts
Actors (Falcon Intelligence)
Reports
Host Groups
Event Streams
Click Create.
In the API Client Created window, copy and securely save the following details:
Client ID
Secret
Base URL
Click Done to finish.
Completing the integration
Once you have created a new API Client, please reach out to our Technical Support team and share the details mentioned above using one time secret to help keep them secure. Our team will then complete the integration and confirm that Crowdstrike is logging to the SIEM platform.
And that's it! You've successfully integrated Crowdstrike π
