Skip to main content

CrowdStrike Falcon Event Stream connector reference

Beta

This feature is in Beta. To use it, a workspace admin must turn on Lakeflow Connect for CrowdStrike Falcon Event Stream from the Previews page. See Manage Databricks previews.

Reference information for the managed CrowdStrike Falcon Event Stream connector, including the supported source table, the events destination schema, and connector options.

Supported source tables​

The CrowdStrike Falcon Event Stream connector supports the following source table, under the default source schema:

Source table

Primary key

Description

Sync mode

Cursor field

events

lw_id

Falcon Event Stream events for your CrowdStrike Falcon tenant.

Incremental

time

Source table

Primary key

Description

Sync mode

Cursor field

events

lw_id

Falcon Event Stream events for your CrowdStrike Falcon tenant.

Incremental

time

Destination table schemas​

events​

Primary key: lw_id Cursor field: time

Field

Data type

lw_id

STRING

time

TIMESTAMP

event_data

STRING

data

VARIANT

Field

Data type

lw_id

STRING

time

TIMESTAMP

event_data

STRING

data

VARIANT

note

This table does not support SCD type 2 because it has VARIANT columns.

Required CrowdStrike Falcon account permissions​

Permission

Required for

Falcon administrator

Create the OAuth2 API client

Event streams: Read (event_streams read)

Discover and consume Event Stream feeds

Permission

Required for

Falcon administrator

Create the OAuth2 API client

Event streams: Read (event_streams read)

Discover and consume Event Stream feeds