Skip to content

Add CrowdStrike integration docs#359

Draft
mavam wants to merge 2 commits into
mainfrom
topic/crowdstrike-ngsiem
Draft

Add CrowdStrike integration docs#359
mavam wants to merge 2 commits into
mainfrom
topic/crowdstrike-ngsiem

Conversation

@mavam
Copy link
Copy Markdown
Member

@mavam mavam commented May 27, 2026

🔍 Problem

  • The docs do not cover CrowdStrike Falcon Next-Gen SIEM ingestion.
  • Users need guidance for both CrowdStrike HEC/HTTP forwarding and Falcon Data Replicator collection.
  • The CrowdStrike HEC terminology can be confused with Splunk HEC, which uses a different Tenzir operator and request contract.

🛠️ Solution

  • Add a CrowdStrike integration page with prerequisites, HEC/HTTP to_http examples, FDR SQS/S3 collection, troubleshooting, and related vendor references.
  • Add a diagram and sidebar entry so the integration is discoverable.
  • Clarify why to_http is used instead of to_splunk for CrowdStrike's HEC/HTTP connector.

💬 Review

  • Check the Falcon HEC endpoint shapes and authentication wording against real tenant behavior.
  • Check the FDR replay guidance around keep_messages=true, deduplication, and dedicated queues.

Document how to send events to Falcon Next-Gen SIEM through the CrowdStrike HEC/HTTP connector and how to collect Falcon Data Replicator events through SQS and S3.

Add the integration sidebar entry and diagram so the page is discoverable.

Assisted-by: GPT-5 (Codex)
@github-actions github-actions Bot added integration Integration documentation site Site infrastructure labels May 27, 2026
@github-actions
Copy link
Copy Markdown
Contributor

github-actions Bot commented May 27, 2026

📦 Preview  ·  View →  ·  🟢 Live

Verified for f2c73b5  ·  Auto-updates on push

Tighten the integration page by removing low-level prerequisite detail, keeping the FDR queue example on the default deletion behavior, and collapsing shared-queue guidance into one aside.

Remove the troubleshooting and vendor-reference sections so external sources inform the page without becoming page content.

Assisted-by: GPT-5 (Codex)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

integration Integration documentation site Site infrastructure

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant