Learn more about the CrowdStrike Falcon Data Replicator standard data source and content pack integrations in Cortex XSIAM.
You can configure collecting raw EDR event data from CrowdStrike Falcon Data Replicator (FDR) using a standard data source or with a content pack integration:
CrowdStrike Falcon Data Replicator vendor | Description |
|---|---|
Standard collector overview | Forward raw EDR event data from CrowdStrike Falcon Data Replicator (FDR), streamed to Amazon S3, and Cortex XSIAM using the CrowdStrike Falcon Data Replicator data source. In addition to all standard SIEM capabilities, this integration unlocks some advanced Cortex XSIAM features, enabling comprehensive analysis of data from all sources, enhanced detection and response, and deeper visibility into CrowdStrike FDR data. |
Link to standard collector instructions | Ingest raw EDR events from CrowdStrike Falcon Data Replicator |
Links to content pack integration details | The CrowdStrike Falcon content pack contains automations to load the CrowdStrike process file content and transform the data . It also includes the following integration:
|