Skip to main content

CrowdStrike Falcon Event Stream connector limitations

Beta

This feature is in Beta. To use it, a workspace admin must turn on Lakeflow Connect for CrowdStrike Falcon Event Stream from the Previews page. See Manage Databricks previews.

The managed CrowdStrike Falcon Event Stream connector ingests only the events table. SCD Type 2 isn't supported.

General software as a service (SaaS) connector limitations​

The limitations in this section apply to all SaaS connectors in Lakeflow Connect.

  • When you run a scheduled pipeline, alerts don't trigger immediately. Instead, they trigger when the next update runs.
  • When a source table is deleted, the destination table is not automatically deleted. You must delete the destination table manually. This behavior is not consistent with Spark Declarative Pipelines on Lakeflow behavior.
  • During source maintenance periods, Databricks might not be able to access your data.
  • If a source table name conflicts with an existing destination table name, the pipeline update fails.
  • Multi-destination pipeline support is API-only.
  • You can optionally rename a table that you ingest. If you rename a table in your pipeline, it becomes an API-only pipeline, and you can no longer edit the pipeline in the UI.
  • If you select a column after a pipeline has already started, the connector does not automatically backfill data for the new column. To ingest historical data, manually run a full refresh on the table.
  • Databricks can't ingest two or more tables with the same name in the same pipeline, even if they come from different source schemas.
  • The source system assumes that the cursor columns are monotonically increasing.
  • The connector ingests raw data without transformations. Use downstream Spark Declarative Pipelines on Lakeflow pipelines for transformations.

Connector-specific limitations​

The limitations in this section apply to the CrowdStrike Falcon Event Stream connector.

  • The connector ingests a single table, events. It doesn't ingest other CrowdStrike Falcon APIs, such as detections, hosts, or Falcon Data Replicator (FDR).
  • SCD Type 2 isn't supported.
  • The Unity Catalog connection Base URL must be an API hostname with the https:// scheme and no path (for example, https://api.crowdstrike.com). Don't include /sensors or other path segments.
  • When no checkpoint exists, the connector starts the Event Stream feed at offset 0. The connector doesn't backfill a multi-day historical window.