CrowdStrike OAuth2
Configure Radiant Security to sync CrowdStrike data.
Last updated
Was this helpful?
Configure Radiant Security to sync CrowdStrike data.
In this guide, you'll configure the integration between Radiant Security and CrowdStrike so that your alerts and data can be triaged and leveraged by Radiant's AI.
At the end of this configuration, you will provide Radiant Security with the following values:
Client ID
Secret
Base URL
Sign in to CrowdStrike Falcon with an admin account.
Expand the side menu and click Support and resources.
Under Resources and tools, click API clients and keys.

Click Create API.
Enter a Client Name to help identify the credential (e.g. Radiant_Security_CrowdStrike).

Under Scope, select Alerts: Read, Alerts: Write, NGSIEM: Read, NGSIEM: Write, CSPM Registration - Read (this last one is needed if you want Radiant to handle CSPM alerts.)
Click Create.
Copy and store the Client ID, Secret, and Base URL values. 
Log in to Radiant Security.
From the navigation menu, click Settings > Data Connectors and click + Add Connector.
Search for and select the CrowdStrike OAuth2 option from the list and then click Data Feeds.
Select the data feeds you want to ingest and click Credentials.
In case you had already created credentials, select them from the drop-down and continue. If you haven’t created credentials yet, create one by giving the credential an identifiable name (e.g. CrowdStrike OAuth2 Credentials). Then, paste the values (Base URL, Client ID, and Client Secret Key) that you copied from the Create the credentials in CrowdStrike Falcon section. Leave the Prefix field empty.
Click Add Connector to save the changes.
After CrowdStrike Falcon begins forwarding, confirm alerts and events are reaching Radiant.
In Radiant, navigate to Log Management.
Filter by the rs_connectorType for each data feed you enabled:
CSPM Alerts
rs_connectorType:"crowdstrike_cspm"
Falcon Alerts
rs_connectorType:"crowdstrike_alerts"
Next-Gen SIEM Detections & Incidents
rs_connectorType:"crowdstrike_ngsiem_alerts"
Next-Gen SIEM Events
rs_connectorType:"crowdstrike_ngsiem_events"
Confirm recent alerts and events appear.
Allow several minutes for alerts and events to be parsed, indexed, and available for search.
Last updated
Was this helpful?
Was this helpful?