Get started with the CrowdStrike Falcon Host integration
The Integration Configuration feature allows you to quickly activate and set up third-party security integrations, including the CrowdStrike Falcon Host integration. Before you can use the CrowdStrike Falcon Host integration, you must download it from the ServiceNow Store and then add a user name and password.
Before you begin
- If you are upgrading CrowdStrike Falcon Host integration from a previous version, then you must delete the existing configuration and set up a new configuration. The new integration supports OAUTH2 authentication. This update requires you to enter the API Client ID and the API Client Secret to authenticate and complete the configuration.
- In the CrowdStrike Falcon Host portal API Scopes, enable the Read and Write setting for IOCs (Indicators of Compromise).
Role required: sn_si_admin
Procedure
When the installation is complete, navigate to Security Operations > Integrations > Integration Configurations.
The available security integrations appear as a series of cards.
In the CrowdStrike Falcon Host card, click Configure.
On the form, fill in the fields to complete the configuration:
| Field | Description |
|---|---|
| Name | Name of the integration, for example, `demo-1`. |
| API Client ID | The client ID that you obtain from the settings section of your account profile in CrowdStrike Falcon Host portal. |
| API Client Secret | The client secret key that you obtain from the settings section of your account profile in CrowdStrike Falcon Host portal. |
- Click Submit.
Result
After it is configured, the CrowdStrike Falcon Host integration can be selected for publishing observables to watchlists in Security Incident Response.