Skip to main content
Version: 25.4

Set up integration with CrowdStrike

This guide details the processes for establishing CrowdStrike integration on the Flexxible platform.

API Configuration in CrowdStrike

  1. Access the CrowdStrike portal.

  2. In the menu, click on Support and Resources -> Api clients and keys.

guide_crowdstrike1

  1. Select Create API client on the right side of the menu.

guide_crowdstrike2

  1. Assign a name to the API; the standard is API-Flexxclient.

guide_crowdstrike3

  1. Without leaving the menu, select the following fields in the READ column:
  • Alerts
  • Detections
  • Hosts
  • Incidents
  • Quarantined Files
  1. Click on Create.

guide_crowdstrike4

  1. Copy the following three fields (they cannot be retrieved later).
  • Client ID
  • Secret
  • Base URL

guide_crowdstrike5

Configuration in Portal

To perform the integration from Portal, the user must have at least the role of Organization Administrator.

  1. Log in to Portal.

  2. In the user menu, select the organization/tenant where you want to enable the integration.

  3. Go to Settings -> Integrations -> CrowdStrike section.

guide_crowdstrike6

  1. Click on Edit and enter the following information:
  • API Client ID. Unique identifier that represents the client on the CrowdStrike platform.

  • Secret String. Secret key associated with the client ID.

  • Region. Geographic location of the customer's cloud environment. The field offers options like eu, eu-1, us-gov-1, us-1, and us-2. Select the CrowdStrike region.

    guide_crowdstrike7

  1. Click on Save.
info

Integration with CrowdStrike can be done at the tenant level, allowing you to set up a different account for each one. If the integration is done at the organization level, it will extend to all its sub-organizations.

View from Workspaces

Once the integration is set up, devices with Endpoint Detection and Response (EDR) installed and running will be marked with the Falcon icon.

guide_crowdstrike8

If the EDR generates an alert, the Falcon icon will appear red.

guide_crowdstrike9

Alert Details

To review the details of the alerts and the resource consumption of the EDR, follow these steps:

  1. Access the Workspaces module -> Workspaces section.
  2. Choose a device and click on it.
  3. Scroll down and click on the Security tab.

guide_crowdstrike10