Skip to main content

CrowdStrike Falcon Event Stream connector FAQ

Beta

This feature is in Beta. To use it, a workspace admin must turn on Lakeflow Connect for CrowdStrike Falcon Event Stream from the Previews page. See Manage Databricks previews.

Common questions about the managed CrowdStrike Falcon Event Stream ingestion connector: required CrowdStrike Falcon permissions, supported tables, and authentication methods. For FAQs that apply to all managed connectors, see Managed connector FAQs.

Which tables does the connector support?​

The connector supports the events table only. For the destination schema, see Destination table schemas.

How far back can the connector ingest data?​

When no checkpoint exists, the connector starts the Event Stream feed at offset 0. Later syncs continue from the last stored offset. The connector doesn't backfill a multi-day historical window.

Which authentication methods does the connector support?​

The connector supports OAuth 2.0 client credentials (machine-to-machine) from a CrowdStrike Falcon API client. The client must have Event streams Read permission. OAuth U2M and basic authentication with a username and password aren't supported.

Does the connector support SCD Type 2?​

No. SCD Type 2 isn't supported.