-
Notifications
You must be signed in to change notification settings - Fork 1.5k
DDS: CrowdStrike FDR Integration v1.0.0 #21242
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: master
Are you sure you want to change the base?
DDS: CrowdStrike FDR Integration v1.0.0 #21242
Conversation
This PR does not modify any files shipped with the agent. To help streamline the release process, please consider adding the |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Left you some minor feedback for your review!
crowdstrike_fdr/README.md
Outdated
### Set up data replication from CrowdStrike FDR to a customer-owned S3 bucket | ||
|
||
#### Configure CrowdStrike FDR Feed | ||
1. Login to **CrowdStrike Falcon** platform. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
1. Login to **CrowdStrike Falcon** platform. | |
1. Log in to the **CrowdStrike Falcon** platform. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Done
crowdstrike_fdr/README.md
Outdated
|
||
## Overview | ||
|
||
[CrowdStrike Falcon Data Replicator (FDR)][1] is a high-fidelity data export solution that enables organizations to securely stream raw endpoint telemetry in near real time. FDR delivers detailed event data through a data feed in JSON format using S3 (Amazon Web Services Simple Storage Service) and SQS (Amazon Simple Queue Service). |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
[CrowdStrike Falcon Data Replicator (FDR)][1] is a high-fidelity data export solution that enables organizations to securely stream raw endpoint telemetry in near real time. FDR delivers detailed event data through a data feed in JSON format using S3 (Amazon Web Services Simple Storage Service) and SQS (Amazon Simple Queue Service). | |
[CrowdStrike Falcon Data Replicator (FDR)][1] is a high-fidelity data export solution that enables organizations to securely stream raw endpoint telemetry in near real time. FDR delivers detailed event data through a data feed in JSON format using Amazon Web Services Simple Storage Service (Amazon S3) and Amazon Simple Queue Service (Amazon SQS). |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Done
crowdstrike_fdr/README.md
Outdated
|
||
[CrowdStrike Falcon Data Replicator (FDR)][1] is a high-fidelity data export solution that enables organizations to securely stream raw endpoint telemetry in near real time. FDR delivers detailed event data through a data feed in JSON format using S3 (Amazon Web Services Simple Storage Service) and SQS (Amazon Simple Queue Service). | ||
|
||
Integrate CrowdStrike FDR with Datadog to gain insights into Authentication & Identity, Account & Privilege Changes, Execution Monitoring & Threat Detection, File & Malware Activity and Network Behavior events using pre-built dashboard visualizations. Datadog leverages its built-in log pipelines to parse and enrich these logs, facilitating easy search and detailed insights. Additionally, integration includes ready-to-use Cloud SIEM detection rules for enhanced monitoring and security. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Integrate CrowdStrike FDR with Datadog to gain insights into Authentication & Identity, Account & Privilege Changes, Execution Monitoring & Threat Detection, File & Malware Activity and Network Behavior events using pre-built dashboard visualizations. Datadog leverages its built-in log pipelines to parse and enrich these logs, facilitating easy search and detailed insights. Additionally, integration includes ready-to-use Cloud SIEM detection rules for enhanced monitoring and security. | |
Integrate CrowdStrike FDR with Datadog to gain insights into Authentication & Identity, Account & Privilege Changes, Execution Monitoring & Threat Detection, File & Malware Activity and Network Behavior events using pre-built dashboard visualizations. Datadog leverages its built-in log pipelines to parse and enrich these logs, facilitating easy search, and detailed insights. Additionally, integration includes ready-to-use Cloud SIEM detection rules for enhanced monitoring and security. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Done
crowdstrike_fdr/README.md
Outdated
- **Bucket name**: Enter a Bucket name (must be globally unique and begins with the prefix `crowdstrike-fdr` to comply with integration naming requirements). | ||
- **AWS Region**: Choose a region. | ||
- You can only use your S3 bucket if you're using the US-1, US-2, or EU-1 CrowdStrike clouds. | ||
- Ensure that your bucket resides in the same AWS region as your Falcon CID where the FDR feed is provisioned. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
- Ensure that your bucket resides in the same AWS region as your Falcon CID where the FDR feed is provisioned. | |
- Ensure that your bucket resides in the same AWS region as your Falcon CID where the FDR feed is provisioned. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Done
crowdstrike_fdr/README.md
Outdated
6. In the **Description** section of the support case, be sure to include the following details: | ||
- The Falcon Customer ID (CID) where your FDR feed is provisioned | ||
- FDR feed name created in `Configure CrowdStrike FDR Feed` section | ||
- The ARN of the custom S3 bucket copied in **Step-8** from `Setup Custom AWS S3 Bucket`. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
- The ARN of the custom S3 bucket copied in **Step-8** from `Setup Custom AWS S3 Bucket`. | |
- The ARN of the custom S3 bucket copied in **Step-8** from `Setup Custom AWS S3 Bucket` |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Done
crowdstrike_fdr/README.md
Outdated
|
||
## Configure Datadog Forwarder | ||
|
||
- Please refer to the [Datadog Forwarder][2]. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
- Please refer to the [Datadog Forwarder][2]. | |
- See the [Datadog Forwarder][2] page for configuration steps. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Done
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
sorry, noticed a few more minor things to comply with our style guide! should be good to go after they get updated.
crowdstrike_fdr/README.md
Outdated
|
||
[CrowdStrike Falcon Data Replicator (FDR)][1] is a high-fidelity data export solution that enables organizations to securely stream raw endpoint telemetry in near real time. FDR delivers detailed event data through a data feed in JSON format using Amazon Web Services Simple Storage Service (Amazon S3) and Amazon Simple Queue Service (Amazon SQS). | ||
|
||
Integrate CrowdStrike FDR with Datadog to gain insights into Authentication & Identity, Account & Privilege Changes, Execution Monitoring & Threat Detection, File & Malware Activity and Network Behavior events using pre-built dashboard visualizations. Datadog leverages its built-in log pipelines to parse and enrich these logs, facilitating easy search, and detailed insights. Additionally, integration includes ready-to-use Cloud SIEM detection rules for enhanced monitoring and security. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Integrate CrowdStrike FDR with Datadog to gain insights into Authentication & Identity, Account & Privilege Changes, Execution Monitoring & Threat Detection, File & Malware Activity and Network Behavior events using pre-built dashboard visualizations. Datadog leverages its built-in log pipelines to parse and enrich these logs, facilitating easy search, and detailed insights. Additionally, integration includes ready-to-use Cloud SIEM detection rules for enhanced monitoring and security. | |
Integrate CrowdStrike FDR with Datadog to gain insights into Authentication & Identity, Account & Privilege Changes, Execution Monitoring & Threat Detection, File & Malware Activity and Network Behavior events using pre-built dashboard visualizations. Datadog leverages its built-in log pipelines to parse and enrich these logs, facilitating easy search, and detailed insights. Additionally, the integration includes ready-to-use Cloud SIEM detection rules for enhanced monitoring and security. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Done
crowdstrike_fdr/README.md
Outdated
3. In the **FDR feeds** tab, click **Create feed**. | ||
4. Provide a feed name. | ||
5. Set the feed **status** to on. | ||
6. Select **Customize your FDR feed** in **How do you want to create this feed?** option. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
6. Select **Customize your FDR feed** in **How do you want to create this feed?** option. | |
6. Select **Customize your FDR feed** in the **How do you want to create this feed?** option. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Done
crowdstrike_fdr/README.md
Outdated
5. Set the feed **status** to on. | ||
6. Select **Customize your FDR feed** in **How do you want to create this feed?** option. | ||
7. Click **Next**. | ||
8. Include only required **Event name** from the **Primary events** tab. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
8. Include only required **Event name** from the **Primary events** tab. | |
8. Include only the required **Event name** from the **Primary events** tab. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Done
crowdstrike_fdr/README.md
Outdated
|
||
### Set up data replication from CrowdStrike FDR to a customer-owned S3 bucket | ||
|
||
#### Configure CrowdStrike FDR Feed |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
#### Configure CrowdStrike FDR Feed | |
#### Configure the CrowdStrike FDR feed |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Done
crowdstrike_fdr/README.md
Outdated
9. Click **Next**. | ||
10. Click **Create feed**. | ||
|
||
#### Setup Custom AWS S3 Bucket |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
#### Setup Custom AWS S3 Bucket | |
#### Setup a custom AWS S3 bucket |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Done
crowdstrike_fdr/README.md
Outdated
8. Copy the **Bucket ARN** of your S3 bucket. | ||
9. Click **Save changes**. | ||
|
||
#### Raise Support Ticket in CrowdStrike |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
#### Raise Support Ticket in CrowdStrike | |
#### Raise a support ticket in CrowdStrike |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Done
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
looks good, thanks!
What does this PR do?
This is a initial release PR of Crowdstrike FDR integration including all the required assets.
Integration Logo Source: https://static.datadoghq.com/static/images/logos/crowdstrike_large.svg
Additional Notes
Review checklist (to be filled by reviewers)
qa/skip-qa
label if the PR doesn't need to be tested during QA.backport/<branch-name>
label to the PR and it will automatically open a backport PR once this one is merged