---
title: "CrowdStrike"
slug: "crowdstrike"
updated: 2026-04-24T20:22:22Z
published: 2026-04-24T20:33:54Z
canonical: "docs.hunters.ai/crowdstrike"
---

> ## Documentation Index
> Fetch the complete documentation index at: https://docs.hunters.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# CrowdStrike

**Self Service Ingestion**

Connect this data source on your own, using the Hunters platform.

## Overview

![CrowdStrike logo](https://cdn.document360.io/5f63f0e0-3c70-4d00-b623-82493be0bde5/Images/Documentation/df0cb38-CS_Logo_2022_In-Line_All-Red_RGB.png)

CrowdStrike Falcon is a cloud-native endpoint protection platform. Hunters can ingest multiple CrowdStrike data types for detection, IOC search, investigation, and threat hunting workflows.

📘 **Note**

Some CrowdStrike data types require specific modules:

- **Spotlight** requires the CrowdStrike Spotlight module.
- **Raw Events** requires Falcon Data Replicator.

⚠️ **Attention**

If you have several CrowdStrike customer IDs under one parent ID, create a separate Hunters data source for each customer ID. Do not use the parent ID when configuring the connection.

## Supported Data Types

| Supported data types | 3rd party detection | Hunters detection | IOC search | Search | Table name | Log format | Collection method |
| --- | --- | --- | --- | --- | --- | --- | --- |
| CrowdStrike Raw Events |  | ✅ | ✅ | ✅ | crowdstrike_raw_events | NDJSON | AWS S3 ingest |
| CrowdStrike Detections | ✅ |  | ✅ |  | crowdstrike_detects | NDJSON | CrowdStrike Store |
| CrowdStrike Devices |  |  | ✅ | ✅ | crowdstrike_devices | NDJSON | CrowdStrike Store |
| CrowdStrike Incidents |  |  | ✅ |  | crowdstrike_incidents | NDJSON | CrowdStrike Store |
| CrowdStrike Identity Based Alerts | ✅ |  | ✅ |  | crowdstrike_idp | NDJSON | API |
| CrowdStrike Mobile | ✅ |  | ✅ |  | crowdstrike_mobile | NDJSON | API |
| CrowdStrike Spotlight |  |  | ✅ |  | crowdstrike_spotlight | NDJSON | API |
| CrowdStrike Indicators |  |  | ✅ |  | crowdstrike_indicators | NDJSON | API |
| CrowdStrike FileVantage |  |  | ✅ | ✅ | crowdstrike_filevantage_queries_changes | NDJSON | API |
| CrowdStrike Falcon Event Streams | ✅ |  | ✅ | ✅ | crowdstrike_falcon_event_streams | NDJSON | CrowdStrike Store |
| CrowdStrike Alerts | ✅ |  |  |  | crowdstrike_alerts | NDJSON | API |

## Connect the CrowdStrike Marketplace App

- Log into the CrowdStrike Falcon Portal.
- From the left-side menu, click **CrowdStrike > All Apps**.

![image](https://cdn.document360.io/5f63f0e0-3c70-4d00-b623-82493be0bde5/Images/Documentation/df0cb38-CS_Logo_2022_In-Line_All-Red_RGB.png)

![image](https://cdn.document360.io/5f63f0e0-3c70-4d00-b623-82493be0bde5/Images/Documentation/17b6297-cs2.png)

- Search for **Hunters**, then click the app.

![image](https://cdn.document360.io/5f63f0e0-3c70-4d00-b623-82493be0bde5/Images/Documentation/image%20%2823%29.png)

![image](https://cdn.document360.io/5f63f0e0-3c70-4d00-b623-82493be0bde5/Images/Documentation/image%20%2825%29.png)

- To retrieve your Customer ID, open the Falcon menu and navigate to **Host setup and management > Sensor downloads**.
- Copy the Customer ID and keep it available for the Hunters data source setup.
- In the **Open App** screen, enter your Customer ID to start using the integration.

![image](https://cdn.document360.io/5f63f0e0-3c70-4d00-b623-82493be0bde5/Images/Documentation/image%20%2826%29.png)

## Articles In This Category

- [CrowdStrike Raw Events](/docs/crowdstrike-raw-events)
- [CrowdStrike Devices](/docs/crowdstrike-devices)
- [CrowdStrike Identity Based Alerts](/docs/crowdstrike-identity-based-alerts)
- [CrowdStrike Mobile](/docs/crowdstrike-mobile)
- [CrowdStrike Spotlight](/docs/crowdstrike-spotlight)
- [CrowdStrike Indicators](/docs/crowdstrike-indicators)
- [CrowdStrike FileVantage](/docs/crowdstrike-filevantage)
- [CrowdStrike Falcon Event Streams](/docs/crowdstrike-falcon-event-streams)
- [CrowdStrike Alerts](/docs/crowdstrike-alerts)
