CrowdStrike Falcon Event Stream connector reference
This feature is in Beta. To use it, a workspace admin must turn on Lakeflow Connect for CrowdStrike Falcon Event Stream from the Previews page. See Manage Databricks previews.
Reference information for the managed CrowdStrike Falcon Event Stream connector, including the supported source table, the events destination schema, and connector options.
Supported source tables
The CrowdStrike Falcon Event Stream connector supports the following source table, under the default source schema:
Source table | Primary key | Description | Sync mode | Cursor field |
|---|---|---|---|---|
|
| Falcon Event Stream events for your CrowdStrike Falcon tenant. | Incremental |
|
Destination table schemas
events
Primary key: lw_id
Cursor field: time
Field | Data type |
|---|---|
|
|
|
|
|
|
|
|
This table does not support SCD type 2 because it has VARIANT columns.
Required CrowdStrike Falcon account permissions
Permission | Required for |
|---|---|
Falcon administrator | Create the OAuth2 API client |
Event streams: Read ( | Discover and consume Event Stream feeds |