Skip to main content

How to Get Credentials for CrowdStrike Next-Gen SIEM Data Plane

S
Written by Sergey Bayrachny
  1. Create an API client in your CrowdStrike Next-Gen SIEM:

    1. Navigate to API Clients and keys > OAuth2 API clients and click Create API Client.

    2. In the modal that appears:

      1. Give your client a meaningful name and an optional description

      2. Set the following permission scopes (start entering "Rules" in the search bar to see the options):

        • Correlation Rules: Read and Write

      3. Click Create.

    3. The API client has been created. In the API client created modal, copy the client ID, Secret, and Base URL to a safe location to use them for configuring a Data Plane on the SOC Prime Platform at a later stage.

    4. Click Done.

  2. Configure a CrowdStrike Next-Gen SIEM Data Plane on the SOC Prime Platform.

    1. Create a new Data Plane and select CrowdStrike Next-Gen SIEM as the Platform.

    2. Fill in the Client ID, Client Secret, and Base URL (Cloud Region) fields with the credentials of your API client.

    3. Fill in the Customer ID (CID) field with your Customer ID from the CrowdStrike Falcon platform. You can find it in the User Profile > Profile menu in the CrowdStrike Next-Gen SIEM console.

Did this answer your question?