To stream CrowdStrike Falcon network data into Oomnitza, add your CrowdStrike Falcon Client ID and Secret to the credentials vault in Oomnitza.
Contents
- Retrieving connection information from CrowdStrike
- About adding credentials to Oomnitza
- Adding global variables
- Adding credentials
Retrieving connection information
You must retrieve the following information to add your credentials to Oomnitza:
- CrowdStrike base URL
- CrowdStrike client ID and secret
- Log in to the Falcon UI.
- Go to Support > API Clients and Keys.
- Click Add new API Client.
- Enter a name.
- Select the Hosts (Read) and Host Groups (Read) scopes for the asset integration. If you plan to run asset workflows, you must also have Write access.
- Select the User management (Read) scope for the user integration and SaaS workflow. If you plan to run one or more of the following user workflows, you must also have Write access: CrowdStrike Change User Name, CrowdStrike Change User Roles, CrowdStrike Delete User, and CrowdStrike Remove User Role.
- Click Save. Make sure you copy the base URL, client ID, and secret.
See CrowdStrike Authentication Guide
Adding CrowdStrike Falcon credentials to Oomnitza
About adding credentials
In the CrowdStrike Cloud Environment field, you enter a part of the base URL for CrowdStrike. You get the base URL when you generate the client ID and secret.
To enter the CrowdStrike Cloud Environment, you trim the prefix https:// and the suffix .comfrom the base URL.
For example, if the base URL for your Crowdstrike Falcon instance is https://api.crowdstrike.com, you enter api.crowdstrike.
CrowdStrike base URLs might change or new base URLs might be added. The source of truth is the CrowdStrike Falcon Wiki. To check out the base URLs, go to the Glossary of Terms, and open the Base URL page.
Table: CrowdStrike Cloud Environment values
| Region | Base URL | CrowdStrike Cloud Environment field value |
| US Commercial Cloud | https:// api.crowdstrike .com | api.crowdstrike |
| US Commercial Cloud 2 | https:// api.us-2.crowdstrike .com | api.us-2.crowdstrike |
| US GovCloud | https://api.laggar.gcw.crowdstrike.com | api.laggar.gcw.crowdstrike |
| Europe | https:// api.eu-1.crowdstrike .com | api.eu-1.crowdstrike |
Adding global variables
Save time when you create integrations and run workflows by adding connection information as global variables.
- Click Configuration > General > Global Settings.
- Click Add new variable.
- Add the key value, which is the name of the variable.
- Enter the value.
- Save your changes.
The name of the key value is CrowdStrike Falcon.Api Domain.
To find out the value that you enter, see Table: CrowdStrike Cloud Environment values.
Important
US Commercial Cloud URL,https://api.crowdstrike.com, has a limit of 100,000 assets when you run the extended integration for CrowdStrike assets. All other CrowdStrike Cloud environments have a limit of 10,000 assets.
Adding credentials
To authorize connections between Oomnitza and CrowdStrike Falcon, complete these steps.
Figure: Adding credentials for CrowdStrike
Make life easier and add your credentials to Oomnitza before you create the integration.
- In Oomnitza, click Configuration > Security > Credentials.
- Click Add new credential (+).
- Search for the integration, and then click the forward arrow > to select the integration.
- Enter your client credentials and any other additional information.
- Click Authenticate. You are prompted to log in to authorize your request.
- Click CREATE.
Add the information details
- Click the AUTHORIZATION tab.
- Ensure that OAuth 2.0 is selected as the Authorization type.
- Ensure that Crowdstrike Falcon is selected from the SaaS list.
- In the CrowdStrike Cloud Environment field, enter the highlighted part of the base URL for your region. If the base URL for your region is
https:// api.crowdstrike.com, enterapi.crowdstrike. - Enter your CrowdStrike Falcon client ID and secret.
- Click Authenticate.
- Click CREATE.
You use the credentials that you added to create and customize your CrowdStrike Falcon integrations with Oomnitza.
Comments
0 comments
Please sign in to leave a comment.