Appearance
CrowdStrike Integration
You can use CrowdStrike as a source or a destination. Continue below to integrate as a source for CrowdStrike Falcon Data Replicator (FDR), or click here to integrate as a destination for CrowdStrike Next-Gen SIEM.
CrowdStrike FDR as a Source
Send Logs from CrowdStrike FDR to Realm
- Log in to CrowdStrike Platform Console.
- Go to Support and resources > Falcon data replicator.

- Click on Create Feed.

- Enter feed name: Realm.Security
- Turn the feed on.
- Leave Default settings selected.

- Click Next.
- Click Create feed.

- Copy ClientID and save it in a safe place.
- Copy Secret and save it in a safe place. You will not be able to see it again.

- Copy Notifications URL.

CrowdStrike NGSIEM as a Destination
Send Logs from Realm to CrowdStrike NGSIEM
Find the event connector
- Login to CrowdStrike Falcon Platform console.
- Go to Next-Gen SIEM > Data onboarding: https://falcon.us-2.crowdstrike.com/data-connectors/

- Search by Product:
Falcon Logscale
- Select Logscale Event connector.
Fill out the Add new connector form
- Data source: Realm.Security (revist for a better default) -> This value gets stored in a field along with the data.
- Data Type: Select JSON.
- Connector name:
Realm.Security(this is just to show on the My connectors page)
4. Description:
Receive logs from Realm.Security- Parser: JSON (Generic Source)
- Select T&C checkbox.
- Click Save.

Get the API key and API URL
- You should see a connector setup in progress confirmation dialog box. Click Close.
- While the connector is being setup, copy the API URL from the connector details page.

- Setting up the FDR connector could take a while. Refresh the connector details page. Once the connector is setup, click Generate API key to generate an API Key.
- Copy API Key and save it in a safe place. You will need to enter it in the Realm console.

- Copy API URL. You will need to enter it in the Realm console.
