> For the complete documentation index, see [llms.txt](https://docs.oort.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.oort.io/integrations/crowdstrike.md).

# CrowdStrike

Cisco Identity Intelligence can integrate with CrowdStrike Falcon NGSIEM (Falcon LogScale) to retrieve log data created by CrowdStrike agents on endpoints. This article explains how to create the required CrowdStrike API client and connect it to Identity Intelligence.

{% hint style="warning" %}
The CrowdStrike integration is currently in Alpha and can only be enabled by the Identity Intelligence team. Please contact Support to have it enabled for your account.
{% endhint %}

### Overview

To connect CrowdStrike to Identity Intelligence:

1. Confirm that your CrowdStrike environment meets the prerequisites
2. Create a Falcon API client with the required NGSIEM permissions and, if approved, the recommended read permissions for planned capabilities
3. Copy the API client ID and secret
4. Add the CrowdStrike integration in Identity Intelligence
5. Verify the connection and configure network allowlisting if required

### Prerequisites

Before you begin, make sure that:

* An active CrowdStrike **NGSIEM (Falcon LogScale)** license is provisioned
* You have access to the **Falcon Console**
* You are a **Falcon administrator**, or have permission to manage Falcon API clients
* You have the necessary permissions to manage integrations in your Identity Intelligence tenant

### CrowdStrike configuration

Create a dedicated Falcon API client for the Identity Intelligence integration:

1. Sign in to the Falcon Console with a Falcon Administrator role
2. Open **Support and resources** from the left navigation
3. Under **Resources and tools**, select **API clients and keys**

<figure><img src="https://582105988-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FqPSBzsjxd7KYg9DNVZ4l%2Fuploads%2FDB514CrOn2B25oHT0BTy%2Fcrowdstrike-api-clients-navigation.png?alt=media&amp;token=ffbddc26-1b47-45ee-901e-7b73f26fa416" alt=""><figcaption></figcaption></figure>

4. Select **Create API client**

<figure><img src="https://582105988-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FqPSBzsjxd7KYg9DNVZ4l%2Fuploads%2FEEHXjkozAkNXjRpfkk20%2Fcrowdstrike-api-client-create.png?alt=media&amp;token=f2fa9d5d-f160-4291-99d0-7f02d374b514" alt="" width="563"><figcaption></figcaption></figure>

5. Enter a descriptive client name, for example, `cii-crowdstrike-integration`
6. Optionally, add a description to identify the client’s purpose
7. In the scope search field, enter `ngsiem`
8. On the **NGSIEM** row, select both the **Read** and **Write** checkboxes. These selections grant `NGSIEM:READ` and `NGSIEM:WRITE`

<figure><img src="https://582105988-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FqPSBzsjxd7KYg9DNVZ4l%2Fuploads%2FVECiccDinLxx6aRryVyt%2Fcrowdstrike-api-client-ngsiem-scopes.png?alt=media&amp;token=20df8c65-db54-4e09-9994-abea625e7cd1" alt="" width="563"><figcaption></figcaption></figure>

9. Grant the `read` permissions described in Recommended permissions for planned capabilities. Granting them now will reduce the need to update the API client when the planned capabilities become available in the near future
10. Select **Create**
11. Copy the **Client ID** and **Client Secret**, and store them securely. Proceed to the [#identity-intelligence-configuration](#identity-intelligence-configuration "mention") section, to enter these values in Identity Intelligence and complete the integration process

{% hint style="warning" %}
Your client secret is sensitive. Do not include it in your org's internal documentation, source control, or support tickets. Use a dedicated client for Identity Intelligence and follow your organization’s credential-rotation policy.
{% endhint %}

#### Required permissions

| Permission     | Purpose                                                                                                 |
| -------------- | ------------------------------------------------------------------------------------------------------- |
| `NGSIEM:WRITE` | Required by the integration to send queries to the CrowdStrike cloud and retrieve relevant NGSIEM data. |
| `NGSIEM:READ`  | Allows the integration to read or query NGSIEM data and receive the query results.                      |

#### Recommended permissions for planned capabilities

To prepare for expanded CrowdStrike data collection, consider granting the following read permissions when you create the API client.\
\
**Recommended approach:** Grant **Hosts - Read** if you want the integration to be ready for planned endpoint inventory collection. Policy permissions are recommended; grant read scopes for policy types whose IDs you want Identity Intelligence to resolve to friendly names.

{% hint style="info" %}
These permissions are **optional for the current integration** and do not enable additional endpoint or policy collection today. They are intended to support capabilities planned for approximately the next **3-6 months**, though the delivery timeline may change.
{% endhint %}

| Planned capability                   | Falcon scope            | Access   | Potential future use                                 |
| ------------------------------------ | ----------------------- | -------- | ---------------------------------------------------- |
| **Endpoint inventory - recommended** | **Hosts**               | **Read** | Core permission for collecting endpoint inventory.   |
| Policy name resolution               | Prevention policies     | Read     | Resolve prevention policy IDs to friendly names.     |
| Policy name resolution               | Firewall management     | Read     | Resolve firewall policy IDs to friendly names.       |
| Policy name resolution               | Sensor update policies  | Read     | Resolve sensor update policy IDs to friendly names.  |
| Policy name resolution               | Device control policies | Read     | Resolve device control policy IDs to friendly names. |
| Policy name resolution               | Response policies       | Read     | Resolve response policy IDs to friendly names.       |

### Identity Intelligence configuration

1. Log in to Identity Intelligence with an Admin role and navigate to **Integrations**
2. Select the **Add Integration** button
3. Find the **CrowdStrike** tile and select **Add Integration** in the respective tile
4. Enter a name for the integration, such as `CrowdStrike-production`
5. Enter the **API client ID** created in the Falcon Console
6. Enter the corresponding **API client secret** when prompted
7. Enter the **CrowdStrike account ID** for the Falcon environment you want to monitor
8. If needed, enter the **CrowdStrike API base URL** for your Falcon API region. The API clients and keys page displays this value as **Base URL**. This field is optional. For example:

   ```
   https://api.us-2.crowdstrike.com
   ```
9. Select **Save**

### Verify the integration

After saving the integration:

1. Confirm that the integration appears in the Identity Intelligence integrations list
2. Confirm that its connection status is successful or connected
3. Return to the product in the next 24 hours to review that CrowdStrike data begins appearing in the Identity Intelligence views that use this integration

If the connection fails, check the troubleshooting list below before creating a new client&#x20;

### IP allowlisting

If your organization restricts access to CrowdStrike by source IP address, add the Identity Intelligence egress addresses to the relevant allowlist:

```
18.119.58.52
3.135.12.148
18.116.228.18
3.140.6.181
```

Confirm the current addresses shown in your Identity Intelligence integration setup screen before applying an allowlist. Egress addresses can be environment- or region-specific.

### Troubleshooting checklist

If Identity Intelligence is not receiving CrowdStrike data, verify the following:

* The CrowdStrike NGSIEM license is active
* The API client was created in the Falcon environment you intend to monitor
* The API client has both `NGSIEM:WRITE` and `NGSIEM:READ` permissions
* The Client ID and Client Secret were copied correctly
* The CrowdStrike account ID is correct
* The API base URL is correct for the CrowdStrike region, or is left blank when the default is appropriate
* Any required Identity Intelligence IP addresses are allowlisted by your organization
* The API client remains enabled in CrowdStrike

### Rotate CrowdStrike credentials

When the Falcon API client secret must be rotated:

1. Create or regenerate the credentials for the dedicated Falcon API client in the Falcon Console
2. In Identity Intelligence, navigate to **Integrations**, and select **Edit Settings** for the relevant CrowdStrike integration
3. Resetting credentials removes the current stored credentials from the integration, so keep the replacement secret available before starting the reset
4. Select **Reset Credentials**
5. Enter the new Client ID and Client Secret
6. Select **Save**
7. Confirm that the integration reconnects successfully
