Configure the CrowdStrike EDR integration

This task gives the necessary steps to configure the CrowdStrike EDR integration in your system. It helps you to select the necessary features, enter the required credentials, and apply the configuration to enhance asset enrichment.

In the Administration > Features section, select the Preview experimental and preview features checkbox.
  1. Go to > Integrations > Internal > CrowdStrike EDR.
  2. In the bottom right corner, select Configure.
    The CrowdStrike EDR integration settings page opens.
  3. In the Description field, enter details that will help you to easily identify it in the future.

  4. From the Endpoint dropdown, select the appropriate CrowdStrike endpoint.
  5. In the Client ID field, enter the CrowdStrike client ID.
  6. In the Client secret field, enter the CrowdStrike client secret.
  7. Choose an option:
    • Only enrich
    • Create and enrich
  8. If you chose Create and enrich, enter details in the CrowdStrike query filter.
  9. Optional: Use the Vantage Asset query filter to filter the assets you would like to enrich.
    For example, you can use a query such as: where assets include? Windows.
    To make sure that your query is correct, you can use the Queries section to check and validate the query before you apply it to asset enrichment.
    Note: You can only filter Vantage assets if the Create and enrich option is not selected. If it is selected, you can only use CrowdStrike filters.
  10. To apply the configuration, select Add.