Install and configure
Install and configure the CrowdStrike Next-Gen SIEM integration for Security Operations application from the ServiceNow Store on your ServiceNow AI Platform instance.
Before you begin
Role required: sn_si.ingestion_profile_admin
Minimum scopes needed to configure CrowdStrike Next-Gen SIEM in ServiceNow® instance include:
| Action | Scope Needed |
|---|---|
| Fetch Detections | Alerts- Read |
| Update Comments/State | Alerts- Write |
| Create Search Query Job | NGSIEM- Write |
| Fetch Search Query Job | NGSIEM- Read |
| Fetch Correlation Rules | Correlation Rules- Read |
Procedure
Download the CrowdStrike Next-Gen SIEM integration from the ServiceNow Store and install it.
For more information, see Download an application from the ServiceNow Store for the first time
Navigate to Security Operations > Integrations > Integration Configurations.
Search for the CrowdStrike Next-Gen SIEM integration tile, and select Configure.
On the form, fill in the fields.
| Field | Description |
|---|---|
| Name | Name of the CrowdStrike Next-Gen SIEM integration. |
| Client ID | The client ID that you obtain from the settings section of your account profile in the CrowdStrike portal. |
| Client Secret | The client secret key that you obtain from the settings section of your account profile in the CrowdStrike portal. |
| Region | Data center to pull data from. Specify the Region: US-1, US-2, EU-1, US-GOV-1, US-GOV-2By default, the field is set to US-1 |
Select Submit.
The configured integration tile displays.