Skip to content

CrowdStrike Integration

You can use CrowdStrike as a source or a destination. Continue below to integrate as a source for CrowdStrike Falcon Data Replicator (FDR), or click here to send logs to CrowdStrike Next-Gen SIEM.

CrowdStrike FDR as a Source

Create CrowdStrike FDR Feed

  1. Log in to CrowdStrike Falcon Console
  2. Go to Support and resources > Falcon data replicator

CS FDR Support and Resources menu

  1. Click Create Feed

CS FDR Create feed

  1. Fill out the feed details:

    Feed name: Realm.Security

  2. Turn the feed on
  3. Leave Default settings selected

CS FDR create feed default

  1. Click Next
  2. Click Create feed

CS FDR create feed

  1. Copy the ClientID and save it in a safe place
  2. Copy the Secret and save it in a safe place — you will not be able to see it again

CS FDR Copy secret

  1. Copy the Notifications URL

CS FDR Copy notifications URL

Configure CrowdStrike FDR in Realm

  1. In Realm, go to Sources
  2. Click Add Source and select CrowdStrike FDR
  3. Fill in the connection details:

    Name: CrowdStrike FDR
    Queue URL: The Notifications URL copied in step 11
    Client ID: The Client ID copied in step 9
    Client Secret: The Secret copied in step 10

  4. Click Save

Realm will begin polling the CrowdStrike FDR queue and ingesting Falcon telemetry events into your data pipeline.

CrowdStrike NGSIEM as a Destination

Send Logs from Realm to CrowdStrike NGSIEM

Find the Event Connector

  1. Log in to the CrowdStrike Falcon Platform console
  2. Go to Next-Gen SIEM > Data onboarding

CrowdStrike Next Gen SIEM menu

  1. Search by Product:

    Falcon Logscale

Falcon Logscale collector

  1. Select Logscale Event connector
  2. Click Configure

Fill Out the Add New Connector Form

  1. Fill out the connector details:

    Connection Name: Realm.Security (this value gets stored in a field along with the data)
    Description: Receive logs from Realm. SecurityParser: JSON (Generic Source)

  2. Select the T&C checkbox
  3. Click Create Connection

NOTE: when forwarding logs from Realm, you have a choice of sending logs either in RAW format (as generated by the source product) or JSON format (as parsed by Realm.) Typically when a parser for a log type is available in NGSIEM, it is recommended to forward RAW logs. When a parser for a log type is not available in NGSIEM or it is available but not working as expected, forward JSON logs from Realm. The setting whether to forward RAW or JSON can be configured on the output feed form in Realm console.

alt text

Get the API Key and API URL

  1. A connector setup in progress confirmation dialog will appear — click Close
  2. While the connector is being set up, copy the API URL from the connector details page

Copy API Key

  1. Setting up the connector may take a while. Refresh the connector details page. Once the connector is set up, click Generate API key
  2. Copy the API Key and save it in a safe place — you will need to enter it in the Realm console

API Key

  1. Copy the API URL — you will need to enter it in the Realm console

API URL