cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Who Me Too'd this topic

Fetching CrowdStrike Next-Gen SIEM Alerts into SOAR

L0 Member

Hi everyone,

How can I fetch Next-Gen SIEM alerts from CrowdStrike into XSOAR? I have already set up my Falcon integration, and I can fetch categories like endpoint detection.

As seen in the image, there is a query section available to fetch different detections. Additionally, in the fetch types section, there are detection options such as endpoint detection, incident, IDP, OFP, and Mobile etc.

However, I want to fetch all detections coming directly to Next-Gen SIEM. Is this possible? For example, Next-Gen SIEM includes various detections created through email, cloud, and custom rules etc. How can I fetch all of them?

Thanks!

Who Me Too'd this topic