↳ GitHub sourceConnector
CrowdStrike API Data Connector (via Codeless Connector Framework)
Description
The [CrowdStrike Data Connector](https://www.crowdstrike.com/) allows ingesting logs from the CrowdStrike API into Microsoft Sentinel. This connector provides the capability to ingest CrowdStrike [Alerts](https://falcon.crowdstrike.com/documentation/84/detection-and-prevention-policies-apis#get-alerts), [Detections](https://falcon.crowdstrike.com/documentation/84/detection-and-prevention-policies-apis#get-detections), [Hosts](https://falcon.crowdstrike.com/documentation/84/host-and-host-group-management-apis#get-hosts), [Cases](https://falcon.crowdstrike.com/documentation/84/cases-apis#get-cases), and [Vulnerabilities](https://falcon.crowdstrike.com/documentation/84/spotlight-apis#get-vulnerabilities) into Microsoft Sentinel. This connector is built on the Microsoft Sentinel Codeless Connector Platform and uses the CrowdStrike API to fetch logs. It supports DCR-based ingestion time transformations so that queries can run more efficiently. Refer to [CrowdStrike API documentation](https://falcon.crowdstrike.com/documentation/page/a2a7fc0e/crowdstrike-oauth2-based-apis) for more information.
- Declared status
- 1
- Declared author / publisher
- Microsoft
Declared sources
Metadata from the source file. No dependencies inferred from KQL.
Data types
Declared permissions
Read and Write permissions are required.
Workspace
Workspace
Crowdstrike OAuth2 API Client and Scopes
#### Required API Scopes In your CrowdStrike Falcon console, go to **Support and resources > API clients and keys**, select your API client, and enable the following scopes with **Read** access: **Alerts**, **Cases**, **Detections**, **Hosts**, **Spotlight Vulnerabilities**. [See the documentation to learn more about API](https://falcon.us-2.crowdstrike.com/documentation/page/a2a7fc0e/crowdstrike-oauth2-based-apis).
Connector instructions
Content published in the repository. Refer to the original file for all parameters.
Connect CrowdStrike to Microsoft Sentinel
**Solution version 3.4.0 and later uses the CrowdStrike V2 tables. Please use updated parser for any existing queries. Refer to the release notes of the solution [here](https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/CrowdStrike%20Falcon%20Endpoint%20Protection/ReleaseNotes.md)**
Manage CrowdStrike Connections
Add, view, and manage CrowdStrike API connections
Add Connection
Configure CrowdStrike API Connection
**Note:** Each data type requires its corresponding API scope to be enabled. Missing scopes will only affect the related data type, other data types will continue to ingest normally.
Connection Alias
Enter a unique alias to identify this CrowdStrike connection. **Important**: Use different aliases for each domain. To update an existing connection, use the same alias or delete and create with the same alias. To replace a connection, delete the old one and create a new one with a new alias.
Query interval (in minutes)
5
10
15
20
30
60
Base API URL
Enter the base URL of your CrowdStrike instance without trailing slash (e.g., https://api.us-2.crowdstrike.com)
Data Types
Alerts - Prevention alerts
Cases - Incident response cases
Detections - Endpoint detections
Hosts - Managed device inventory
Vulnerabilities - Spotlight vulnerability findings
OAuth2 Credentials
Configure OAuth2 credentials for API access
Client ID
Client Secret
Querying Detections (after successful connection)
Related content
Links established from declared identifiers and solution manifests.
Source provenance
GitHubDisplayed values come from files in Azure/Azure-Sentinel. They describe the published template, not your workspace configuration.
- Commit
9800e51↗- Source identifier
CrowdStrikeAPIConnector
GSTEP / CATALOG TRACKING
Added to catalog : 16 Sept 2026 · 05:49 UTC
Last change observed : 16 Sept 2026 · 05:49 UTC