CrowdStrike Falcon Event Stream connector
This feature is in Beta. To use it, a workspace admin must turn on Lakeflow Connect for CrowdStrike Falcon Event Stream from the Previews page. See Manage Databricks previews.
The managed CrowdStrike Falcon Event Stream connector in Lakeflow Connect ingests Falcon Event Stream events from CrowdStrike Falcon into Databricks.
Feature availability
Feature | Availability |
|---|---|
UI-based pipeline authoring |
|
API-based pipeline authoring |
|
Declarative Automation Bundles |
|
Incremental ingestion |
|
Unity Catalog governance |
|
Orchestration using Databricks Workflows |
|
API-based column selection and deselection |
|
API-based row filtering |
|
SCD Type 2 |
|
Automated schema evolution: New and deleted columns |
|
Automated schema evolution: Data type changes |
|
Automated schema evolution: Column renames |
Treated as a new column (new name) and deleted column (old name). |
Authentication methods
Authentication method | Availability |
|---|---|
OAuth U2M |
|
OAuth M2M |
OAuth 2.0 client credentials from a CrowdStrike Falcon API client. |
Basic authentication (username/password) |
|
Basic authentication (API key) |
|
What to know before you start
Before starting, review the Databricks user persona, supported interfaces, ingestion frequency, and common patterns.
Start ingesting from CrowdStrike Falcon
- Configure CrowdStrike Falcon for ingestion (Admins). Set up CrowdStrike Falcon to authenticate with Databricks.
- Create a Unity Catalog connection (Admins). Create a connection in Catalog Explorer so non-admins can create pipelines.
- Create an ingestion pipeline (Admins or non-admins). Select any supported interface and create a pipeline from an existing connection.