CrowdStrike
Integrate CrowdStrike with Cloudaware to ingest hosts, detections, policies, and vulnerabilities for unified security reporting and correlation with applications and assets.
info
- Audience: Cloudaware administrators, SecOps
- Outcome: The CrowdStrike account is connected, and hosts, detections, policies, and vulnerability data are available in the CMDB for security reporting and correlation
Capabilities
The integration supports:
- Read-only discovery of CrowdStrike hosts, groups, detections, policies, and vulnerabilities in the CMDB
- Relationships between CrowdStrike detections, affected assets, applications, and related infrastructure
- Security reporting for detection trends, endpoint coverage, and vulnerability context in Cloudaware
Prerequisites
Before you begin, make sure you have:
- Access to a Cloudaware account.
- A user with access to the Admin Console and permissions to manage cloud accounts, organizations, and integrations (Cloudaware Administrator).
- CrowdStrike Falcon Client ID and Client Secret.
- Environment or region matching your CrowdStrike Falcon tenant.
- API scopes for sensor download, detections, hosts, host groups, and vulnerabilities.
Add a CrowdStrike Account to Cloudaware
To connect your CrowdStrike account to Cloudaware:
- In Cloudaware, go to Admin.
- Find CrowdStrike, then click + ADD.
- Enter the following values:
- Name: A display name for this connection
- Client ID: The CrowdStrike Falcon API client ID
- Client Secret: The CrowdStrike Falcon API client secret
- Environment: The environment or region that matches your Falcon tenant
- Click SAVE.
- Confirm that the integration status indicator is green.
tip
Allow the initial discovery cycle to complete after enabling the integration.
View CrowdStrike Data in CMDB
To browse discovered CrowdStrike resources:
- In Cloudaware, open CMDB Navigator.
- In the left pane, select CROWDSTRIKE.
- Open an object list, e.g., CrowdStrike Hosts or CrowdStrike Detections, to view records.
Supported Objects
Cloudaware ingests the following CrowdStrike objects:
| CrowdStrike Object | CMDB Object API Name |
|---|---|
| CrowdStrike Account | CA10CR__CaCrowdstrikeAccount__c |
| CrowdStrike Detection | CA10CR__CaCrowdstrikeDetection__c |
| CrowdStrike Detection Behavior | CA10CR__CaCrowdstrikeDetectionBehavior__c |
| CrowdStrike Group | CA10CR__CaCrowdstrikeGroup__c |
| CrowdStrike Host | CA10CR__CaCrowdstrikeHost__c |
| CrowdStrike Host Group Link | CA10CR__CaCrowdstrikeHostGroupLink__c |
| CrowdStrike Sensor Update Policy | CA10CR__CaCrowdstrikeSensorUpdatePolicy__c |
| CrowdStrike Sensor Update Policy Group Link | CA10CR__CaCrowdstrikeSensorUpdatePolicyGroupLink__c |
Troubleshooting
note
Initial data collection may take time to complete.
Authentication Fails or Integration Shows Red Status
- Verify the Client ID and Client Secret values.
- Confirm that the selected Environment matches your CrowdStrike Falcon tenant.
- Check that the API client is active in CrowdStrike.
- Re-enter the credentials by editing the integration in Cloudaware.
Required Objects Are Missing or Access Errors Appear
- Confirm that the CrowdStrike API client has the required scopes for sensor download, detections, hosts, host groups, and vulnerabilities.
- Review the error message to identify which object or endpoint is not accessible.
- Update the CrowdStrike API client scopes if a required permission is missing.
No Data Appears After a Successful Save
- Allow the initial discovery cycle to complete.
- Confirm that the CrowdStrike tenant contains hosts, detections, policies, or vulnerabilities that the API client can read.
- In CMDB Navigator, verify that you are viewing the CROWDSTRIKE section and related resources.
Changes in CrowdStrike Are Not Yet Visible in Cloudaware
- Synchronization is periodic. Wait for the next cycle or contact support to review the schedule.
Still stuck? Contact Cloudaware Support at support@cloudaware.com with the integration name and a brief description of the issue.
Reconfigure or Remove the Integration
warning
To rotate credentials, edit the existing integration instead of deleting and re-creating it.
Update the Integration Details
- Go to Admin.
- Select CrowdStrike.
- Select the specific integration.
- Open the three-dot menu (⋮), then click Edit.
- Update the required fields.
- Click Save.
Remove the Integration from Cloudaware
- Go to Admin.
- Select CrowdStrike.
- Select the specific integration.
- Open the three-dot menu (⋮), then click Delete.
- Confirm the deletion if prompted.
Security Notes
- Use a dedicated CrowdStrike API client with the minimum required read scopes for Cloudaware discovery.
- Avoid granting write, remediation, or administrative scopes unless Cloudaware specifically requires them for your deployment.
- Rotate the Client Secret according to your organization's credential-rotation policy.
- Update the Cloudaware integration immediately if the Client Secret is revoked or regenerated in CrowdStrike.
- Credentials are stored securely and are only visible to Cloudaware collector.