📢 Read the latest Release Notes to learn what's new on Hunters! 💡

CrowdStrike Devices

Prev Next

Overview

Table name: crowdstrike_devices

CrowdStrike device logs encompass a wide range of data points collected from each endpoint or device within the network. These logs are crucial for monitoring the health and security status of the network, detecting potential threats, and facilitating forensic analysis in the event of a security incident.

Send data to Hunters

Step 1: Connect Hunters to your CrowdStrike portal

  1. Log into the CrowdStrike Falcon portal.

  2. From the left-side menu, click CrowdStrike Store > All Apps.
    17b6297-cs2

  3. Look for the Hunters.AI tile and click to open it.
    image 23

  4. Click Try it free.

    📘 Note
    1. Your CrowdStrike API token will be shared with Hunters with the following permissions:

      • CrowdStrike Falcon raw data replicator
      • CrowdStrike Detections API
    2. You will receive an automated email from Hunters confirming this action. This is designed for new prospects who have not yet been introduced to Hunters.

  5. To retrieve your Customer ID, open the Falcon menu and navigate to Host setup and management > Sensor downloads.
    image 25

  6. Copy your Customer ID and paste it into a safe place.
    image 26

Step 2: Create a data source on Hunters

  1. Follow this procedure to connect CrowdStrike as a data source.
  2. Insert the Customer ID value from the previous section and click Apply.
📘Note

The Customer ID field is case-sensitive.

02610f3-2023-04-16_12-31-02

Once done, Hunters will connect your CrowdStrike Detections, CrowdStrike Devices, CrowdStrike Incidents, CrowdStrike Falcon Event Streams and CrowdStrike Raw Events to your Hunters platform.