Overview
The CrowdStrike integration polls the Falcon Streaming API and detection endpoints to ingest:
- Endpoint detections (malware, IOA, IOC matches)
- Incident lifecycle changes
- Real-Time Response (RTR) session activity
- Audit events for user, role, and policy changes
Prerequisites
- A CrowdStrike Falcon tenant.
- Falcon Administrator privileges to create API clients.
- The Falcon cloud region your tenant lives in (
us-1,us-2,eu-1, orus-gov-1).
Step 1: Create an API client in Falcon
- Sign in to the Falcon console.
- Go to Support and resources → API clients and keys.
- Click Create API client.
- Name it
atatus-siemand grant the following scopes (read-only):- Detections — Read
- Incidents — Read
- Event streams — Read
- Audit — Read
- Click Create, then copy the Client ID and Client Secret shown once.
- Note the Base URL for your cloud region (for example,
https://api.crowdstrike.comfor US-1).
Step 2: Connect CrowdStrike in Atatus
- In Atatus, go to Security → Cloud SIEM → Integrations.
- Locate the CrowdStrike card and click Connect.
- Fill in the form:
| Field | Description | Example |
|---|---|---|
| Client ID | Falcon API client ID. | abc123... |
| Client Secret | Falcon API client secret. | •••••••• |
| Cloud Region | Falcon cloud region. | us-1 |
| Poll Interval (minutes) | How often to fetch new events. | 5 |
| Enabled | Turn collection on. | true |
- Click Connect.
Verification
- The CrowdStrike card shows Configured.
- Detections and audit events appear in Security → Cloud SIEM → Audit Logs → Events with source
crowdstrike.
+1-415-800-4104