Skip to main content

Set up integration with CrowdStrike

This guide details the processes for establishing CrowdStrike integration on the Flexxible platform.

API Configuration in CrowdStrike​

  1. Access the CrowdStrike portal.

  2. In the menu, click on Support and Resources -> Api clients and keys.

    guide_crowdstrike1

  3. Select Create API client on the right side of the menu.

    guide_crowdstrike2

  4. Assign a name to the API; the standard is API-Flexxclient.

    guide_crowdstrike3

  5. Without leaving the menu, select the following fields in the READ column:

    • Alerts
    • Detections
    • Hosts
    • Incidents
    • Quarantined Files
  6. Click on Create.

    guide_crowdstrike4

  7. Copy the following three fields (they cannot be retrieved later).

    • Client ID
    • Secret
    • Base URL

    guide_crowdstrike5

Configuration in Portal​

To perform the integration from Portal, the user must have at least the role of Organization Administrator.

  1. Log in to Portal.

  2. In the user menu, select the organization/tenant where you want to enable the integration.

  3. Go to Settings -> Integrations -> CrowdStrike section.

    guide_crowdstrike6

  4. Click on Edit and enter the following information:

  • API Client ID. Unique identifier that represents the client on the CrowdStrike platform.

  • Secret String. Secret key associated with the client ID.

  • Region. Geographic location of the customer's cloud environment. The field offers options like eu, eu-1, us-gov-1, us-1, and us-2. Select the CrowdStrike region.

    guide_crowdstrike7

  1. Click on Save.
info

Integration with CrowdStrike can be done at the tenant level, allowing you to set up a different account for each one. If the integration is done at the organization level, it will extend to all its sub-organizations.

View from Workspaces​

Once the integration is set up, devices with Endpoint Detection and Response (EDR) installed and running will be marked with the Falcon icon.

guide_crowdstrike8

If the EDR generates an alert, the Falcon icon will appear red.

guide_crowdstrike9

Alert Details​

To review the details of the alerts and the resource consumption of the EDR, follow these steps:

  1. Access the Workspaces module -> Workspaces.
  2. Choose a device and click on it.
  3. Scroll down and click on the Security tab.

guide_crowdstrike10