Skip to content

CrowdStrike Integration

You can use CrowdStrike as a source or a destination. Continue below to integrate as a source for CrowdStrike Falcon Data Replicator (FDR), or click here to integrate as a destination for CrowdStrike Next-Gen SIEM.

CrowdStrike FDR as a Source

Send Logs from CrowdStrike FDR to Realm

  1. Log in to CrowdStrike Platform Console
  2. Go to Support and resources > Falcon data replicator

CS FDR Support and Resources menu

  1. Click Create Feed

CS FDR Create feed

  1. Fill out the feed details:

    Feed name: Realm.Security

  2. Turn the feed on
  3. Leave Default settings selected

CS FDR create feed default

  1. Click Next
  2. Click Create feed

CS FDR create feed

  1. Copy the ClientID and save it in a safe place
  2. Copy the Secret and save it in a safe place — you will not be able to see it again

CS FDR Copy secret

  1. Copy the Notifications URL

CS FDR Copy notifications URL

CrowdStrike NGSIEM as a Destination

Send Logs from Realm to CrowdStrike NGSIEM

Find the Event Connector

  1. Log in to the CrowdStrike Falcon Platform console
  2. Go to Next-Gen SIEM > Data onboarding

CrowdStrike Next Gen SIEM menu

  1. Search by Product:

    Falcon Logscale

Falcon Logscale collector

  1. Select Logscale Event connector

Fill Out the Add New Connector Form

  1. Fill out the connector details:

    Data source: Realm.Security (this value gets stored in a field along with the data)Data Type: JSONConnector name: Realm.Security (shown on the My connectors page)Description: Receive logs from Realm.SecurityParser: JSON (Generic Source)

  2. Select the T&C checkbox
  3. Click Save

alt text

Get the API Key and API URL

  1. A connector setup in progress confirmation dialog will appear — click Close
  2. While the connector is being set up, copy the API URL from the connector details page

Copy API Key

  1. Setting up the connector may take a while. Refresh the connector details page. Once the connector is set up, click Generate API key
  2. Copy the API Key and save it in a safe place — you will need to enter it in the Realm console

API Key

  1. Copy the API URL — you will need to enter it in the Realm console

API URL