Crowdstrike
StandardCrowdstrike enables you to collect and normalize Crowdstrike logs and lets you analyze the information through the LP_Crowdstrike dashboard. The dashboard visualizes event type distributions, top host generating detection, real-time response summary, successful and failed user login events, detection techniques and tactics, quarantined files and hosts generating higher severity event detections in your network. You can customize it to perform in-depth analysis by changing the data used in a search.
Release Details
Enhancement
Past Releases
CrowdStrike v5.0.2 ▾
Enhancements
Renamed the following fields in CrowdStrikeCEFCompiledNormalizer:
| Former Field Name | Updated Field Name | Event |
|---|---|---|
| pdf_handleoperationdowngraded | handled_operation_downgraded | - |
| pdf_fsoperationblocked | fsoperation_blocked | |
| pdf_detect | detect | |
| pdf_criticalprocessdisabled | critical_process_disabled | |
| pdf_bootupsafeguardenabled | bootup_saftgarden_enabled | |
| pdf_blockingunsupportedordisabled | blocking_unsupported_or_disabled | |
| parentimagefilename | parent_process | |
| parentcommandline | parent_command | |
| nat_destination_address | source_address | |
| incidentstarttime | start_ts | |
| incidentendtime | end_ts | |
| grandparentimagefilename | grand_parent_process | |
| grandparentcommandline | grand_parent_command | |
| external_id | host_id | |
| event_id | event_type | |
| detectionid | detection_id | |
| destination_host | host | |
| pdf_indicator | indicator | |
| pdf_killprocess | kill_process | |
| pdf_killparent | kill_parent | |
| pdf_killactionfailed | kill_action_failed | |
| pdf_inddetmask | inddet_mask | |
| csmtrpatterndisposition | csmtr_pattern_disposition | |
| pdf_killsubprocess | kill_subprocess | |
| pdf_operationblocked | operation_blocked | |
| pdf_policydisabled | policy_disabled | |
| pdf_processblocked | process_blocked | |
| pdf_quarantinefile | quarentine_file | |
| pdf_quarantinemachine | quarantine_machine | |
| pdf_registryoperationblocked | registry_operation_blocked | |
| pdf_rooting | rooting | |
| pdf_sensoronly | sensor_only | |
| quarantinefilepath | quarantine_path | |
| quarantinefilesha256 | hash | |
| severityname | log_level | |
| sha256filehash | hash_sha256 | |
| source_hardware_address | hardware_address | |
| target_user | user | |
| windows_destination_domain | domain | |
| action | attack_tag | DetectionSummary |
| category | attack_category | |
| updatestatus | status | UserActivityAudit |
| appendComment | comment | |
| assigntoname | assigned_to | |
| assigntouserid | assigned_user | |
| remoteresponsesessionstarttimestamp | start_ts | RemoteResponseSessionStart |
| sessionid | session_id | |
| agentIdString | host_id | |
| remoteresponsesessionstarttimestamp | end_ts | |
| targetname | target | UserLogin |
| ioctype | ioc_type | |
| iocvalue | ioc_value | |
| associatedfile | associated_file |
CrowdStrike v5.0.0 ▾
Key Information
You must configure the CEF config file in the system where the CrowdStrike Falcon SIEM Connector is running. Go to CEF Sample Configuration for the configuration file.
Support
If you have any questions or require assistance, create a support ticket..
Comments
Article is closed for comments.