Configure authentication to CrowdStrike Falcon
This feature is in Beta. To use it, a workspace admin must turn on Lakeflow Connect for CrowdStrike Falcon Event Stream from the Previews page. See Manage Databricks previews.
Configure CrowdStrike Falcon to enable authentication from Databricks for the CrowdStrike Falcon Event Stream connector. Use the credentials from these steps to create a Unity Catalog connection in Databricks.
Prerequisites
- Requires a Falcon administrator to create an OAuth2 API client. See CrowdStrike's Event Streams API documentation.
- The API client must have the Event streams scope with Read permission (
event_streamsread). The connector callsGET /sensors/entities/datafeed/v2and consumes the returned feeds.
Configure CrowdStrike Falcon
CrowdStrike Falcon authenticates Event Stream requests with an OAuth 2.0 client credentials token. Databricks exchanges the client ID and client secret for an access token, then discovers and reads Event Stream feeds. For more information, see CrowdStrike's Event Streams API documentation.
- Sign in to the Falcon console as a Falcon administrator.
- Go to Support and resources, then API clients and keys.
- Click Add new API client.
- Enter a Client name (for example,
Event_Stream_Ingestor) and an optional Description. - Under API scopes, find Event streams and enable Read.
- Click Create.
- Copy the Client ID, Client Secret, and Base URL. CrowdStrike Falcon shows the client secret only once. For the Databricks connection, enter the Base URL with the
https://scheme and no path (for example,https://api.crowdstrike.comorhttps://api.us-2.crowdstrike.com).
Next steps
Create a CrowdStrike Falcon Event Stream connection in Databricks. See Create an CrowdStrike Falcon Event Stream connection.