Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

CrowdStrike Falcon Host integration

The CrowdStrike Falcon Host integration allows you to push observables in a security incident into a watchlist, making them able to generate additional alerts. This integration is an implementation of the CrowdStrike Falcon Host - Publish to Watchlist workflow.

Explore Security Incident Response integrationsSet up Get started with the CrowdStrike Falcon Host integration
Use Perform lookups on observablesDevelop - ServiceNow Security Operations integration development guidelines - Tips for writing integrations - Developer training - Developer documentation - Find components installed with an application
Troubleshoot and get help - Integration troubleshooting - Ask or answer questions in the Security Operations community - Search the Known Error Portal for known error articles - Contact Customer Service and Support