Prerequisites
The user performing the integration must be able to create an API Token
A Reco user with Admin Role
Configure CrowdStrike
Login to CrowdStrike
Click on Support -> API Client and Keys
Click on "Add new API Client"
Enter in a new client name and description.
Select Read for
Hosts
Device control policies
Detections
Prevention policies
User Management
Entities
CrowdStrike Falcon Alerts
CrowdStrike Falcon Event Streams
Select the Add button.
Copy and set aside the Client ID, Secret and Base URL, and click on Done
Integrate CrowdStrike with Reco
Login to the Reco Platform
Click on "Configurations" and then "Integrations"
Locate the "CrowdStrike" object, and click on "Add Integration"
A new screen will open, click on "Allow"
Fill in the following fields, and click on "Reinstall into Workspace"
API Endpoint - The location of your CrowdStrike tenant region, from the "Base URL" previously copied
Client ID - Previously copied above
Client Secret - Previously copied above
A new windows appears, click on "Start Extraction"
If the integration was successful, the CrowdStrike Integration status will become "Active"
What do we ingest exactly?
Access | Objects |
Read-only | Hosts Device control policies Detections Prevention policies User Management CrowdStrike Falcon Event Streams CrowdStrike Falcon Alerts Entities |