For the complete documentation index, see llms.txt. This page is also available as Markdown.

CrowdStrike Falcon CSPM

Configure Radiant Security to sync CrowdStrike CSPM alerts.

In this guide, you will create an API client with read-only credentials for CrowdStrike OAuth2 and use those to configure a data connector with Radiant Security.

At the end of this configuration, you will provide Radiant Security with the following values:

  • Client ID

  • Secret

  • Base URL

Prerequisites

Create the credentials in CrowdStrike Falcon

  1. Sign in to CrowdStrike Falcon with an admin account.

  2. Expand the side menu and click Support and resources.

  3. Under Resources and tools, click API clients and keys.

  1. Click Create API.

  2. Enter a Client Name to help identify the credential.

  1. Under Scope, select CSPM Registration - Read.

  2. Click Create.

  3. Copy and store the Client ID, Secret, and Base URL values.

Create the data connector in Radiant Security

  1. Log into Radiant Security.

  2. From the navigation menu, select Settings > Data Connectors and click + Add Connector.

  3. Search for and select the Crowdstrike OAuth2 option from the list and then click Data Feeds.

  4. Under Select your data feeds, select Falcon CSPM Alerts and click Credentials.

  5. In case you had already created credentials, select them from the drop-down and continue. If you haven’t created credentials yet, create one by giving the credential an identifiable name (e.g. Crowdstrike Falcon CSPM Credentials). Then, paste the values (Base URL, Client ID, and Client Secret Key) that you copied from the Create the credentials in CrowdStrike Falcon section. Leave the Prefix field empty.

  6. Click Add Connector to save the changes.

Verify ingestion

After CrowdStrike Falcon CSPM begins forwarding, confirm alerts are reaching Radiant.

  1. In Radiant, navigate to Log Management.

  2. Filter by rs_connectorType:"crowdstrike_cspm".

  3. Confirm recent alerts appear.

Allow several minutes for alerts to be parsed, indexed, and available for search.

Last updated

Was this helpful?