Appearance
CrowdStrike Integration
You can use CrowdStrike as a source or a destination. Continue below to integrate as a source for CrowdStrike Falcon Data Replicator (FDR), or click here to integrate as a destination for CrowdStrike Next-Gen SIEM.
CrowdStrike FDR as a Source
Send Logs from CrowdStrike FDR to Realm
- Log in to CrowdStrike Platform Console
- Go to Support and resources > Falcon data replicator

- Click Create Feed

- Fill out the feed details:
Feed name:
Realm.Security - Turn the feed on
- Leave Default settings selected

- Click Next
- Click Create feed

- Copy the ClientID and save it in a safe place
- Copy the Secret and save it in a safe place — you will not be able to see it again

- Copy the Notifications URL

CrowdStrike NGSIEM as a Destination
Send Logs from Realm to CrowdStrike NGSIEM
Find the Event Connector
- Log in to the CrowdStrike Falcon Platform console
- Go to Next-Gen SIEM > Data onboarding

- Search by Product:
Falcon Logscale

- Select Logscale Event connector
Fill Out the Add New Connector Form
- Fill out the connector details:
Data source:
Realm.Security(this value gets stored in a field along with the data)Data Type:JSONConnector name:Realm.Security(shown on the My connectors page)Description:Receive logs from Realm.SecurityParser:JSON (Generic Source) - Select the T&C checkbox
- Click Save

Get the API Key and API URL
- A connector setup in progress confirmation dialog will appear — click Close
- While the connector is being set up, copy the API URL from the connector details page

- Setting up the connector may take a while. Refresh the connector details page. Once the connector is set up, click Generate API key
- Copy the API Key and save it in a safe place — you will need to enter it in the Realm console

- Copy the API URL — you will need to enter it in the Realm console
