| title | CrowdStrike Next-Gen SIEM Destination | |||||||
|---|---|---|---|---|---|---|---|---|
| disable_toc | false | |||||||
| products |
|
{{< product-availability >}}
Use Observability Pipelines' CrowdStrike Next-Gen SIEM destination to send logs to CrowdStrike Next-Gen SIEM.
Set up the CrowdStrike NG-SIEM destination and its environment variables when you set up a pipeline. The information below is configured in the pipelines UI.
To use the CrowdStrike NG-SIEM destination, you need to set up a CrowdStrike data connector using the HEC/HTTP Event Connector. See Step 1: Set up the HEC/HTTP event data connector for instructions. When you set up the data connector, you are given a HEC API key and URL, which you use when you configure the Observability Pipelines Worker later on.
- Enter the identifier for your CrowdStrike NG-SIEM endpoint URL. If you leave it blank, the default is used.
- Enter the identifier for your CrowdStrike NG-SIEM token. If you leave it blank, the default is used.
- Select JSON or Raw encoding in the dropdown menu.
- Toggle the switch to Enable compressions.
- Select an algorithm (gzip or zlib) in the dropdown menu.
{{% observability_pipelines/tls_settings %}}
{{% observability_pipelines/destination_buffer %}}
{{% observability_pipelines/set_secrets_intro %}}
{{< tabs >}} {{% tab "Secrets Management" %}}
- CrowdStrike NG-SIEM endpoint URL identifier:
- In your secrets manager, do not include the suffix
/services/collectorin the URL. The URL must follow this format:https://<your_instance_id>.ingest.us-1.crowdstrike.com. - The default identifier is
DESTINATION_CROWDSTRIKE_NEXT_GEN_SIEM_ENDPOINT_URL.
- In your secrets manager, do not include the suffix
- CrowdStrike NG-SIEM token identifier:
- The default identifier is
DESTINATION_CROWDSTRIKE_NEXT_GEN_SIEM_TOKEN.
- The default identifier is
- CrowdStrike NG-SIEM TLS passphrase identifier (when TLS is enabled):
- The default identifier is
DESTINATION_CROWDSTRIKE_NEXT_GEN_SIEM_KEY_PASS.
- The default identifier is
{{% /tab %}}
{{% tab "Environment Variables" %}}
{{% observability_pipelines/configure_existing_pipelines/destination_env_vars/crowdstrike_ng_siem %}}
{{% /tab %}} {{< /tabs >}}
A batch of events is flushed when one of these parameters is met. See event batching for more information.
| Maximum Events | Maximum Size (MB) | Timeout (seconds) |
|---|---|---|
| None | 1 | 1 |