CrowdStrike Falcon Streaming v2
Use the CrowdStrike Falcon Stream v2 integration to stream detections and audit security events.
- Category
- Endpoint
- Pack
- CrowdStrikeFalconStreamingV2
Configuration parameters
- base_url — Cloud Base URL (e.g., https://api.crowdstrike.com) (required)
- client_id — Client ID
- client_secret — Client Secret
- credentials_client — Client ID
- app_id — Application ID
- longRunning — Long running instance
- event_type — Event type to fetch
- offset — Offset to fetch events from
- incidentType — Incident type
- fetch_time — First fetch timestamp (<number> <time unit>, e.g., 12 hours, 7 days)
- sock_read_timeout — Stream client read timeout
- store_samples — Store sample events for mapping
- insecure — Trust any certificate (not secure)
- proxy — Use system proxy settings
Commands (1)
- crowdstrike-falcon-streaming-get-sample-events — Returns a list of sample events fetched from the stream.