Ingest data from CrowdStrike Falcon
This feature is in Beta. To use it, a workspace admin must turn on Lakeflow Connect for CrowdStrike Falcon Event Stream from the Previews page. See Manage Databricks previews.
Create a managed CrowdStrike Falcon Event Stream ingestion pipeline in Lakeflow Connect to ingest Falcon Event Stream events into Databricks.
Requirements
-
To create an ingestion pipeline, first meet the following requirements:
-
Your workspace must be enabled for Unity Catalog.
-
Serverless compute must be enabled for your workspace. See Serverless compute requirements.
-
To create a new connection, you must have
CREATE CONNECTIONprivileges on the metastore. See Manage privileges in Unity Catalog.If the connector supports UI-based pipeline authoring, an admin can create the connection and the pipeline at the same time by completing the steps on this page. However, if the users who create pipelines use API-based pipeline authoring or are non-admin users, an admin must first create the connection in Catalog Explorer. See Connect to managed ingestion sources.
-
To use an existing connection, you must have
USE CONNECTIONprivileges orALL PRIVILEGESon the connection object. -
You must have
USE CATALOGprivileges on the target catalog. -
You must have
USE SCHEMAandCREATE TABLEprivileges on an existing schema orCREATE SCHEMAprivileges on the target catalog.
-
-
To ingest from CrowdStrike Falcon, first configure authentication from Databricks and create a connection. See Configure authentication to CrowdStrike Falcon and Create an CrowdStrike Falcon Event Stream connection.
Create an ingestion pipeline
For the list of supported source tables, see Supported source tables.
- Declarative Automation Bundles
- Databricks notebook
Use Declarative Automation Bundles to manage CrowdStrike Falcon Event Stream pipelines as code. Bundles can contain YAML definitions of jobs and tasks, are managed using the Databricks CLI, and can be shared and run in different target workspaces (such as development, staging, and production). For more information, see What are Declarative Automation Bundles?.
-
Create a bundle using the Databricks CLI:
Bashdatabricks bundle init -
Add two new resource files to the bundle:
- A pipeline definition file (for example,
resources/crowdstrike_falcon_event_stream_pipeline.yml). See pipeline.ingestion_definition and Examples. - A job definition file that controls the frequency of data ingestion (for example,
resources/crowdstrike_falcon_event_stream_job.yml).
- A pipeline definition file (for example,
-
Deploy the pipeline using the Databricks CLI:
Bashdatabricks bundle deploy
-
Import the following notebook into your Databricks workspace:
-
Leave cells one and two as they are. Do not modify.
-
Modify cell three with your pipeline configuration details. See pipeline.ingestion_definition and Examples.
-
Optionally configure advanced pipeline settings. See Common patterns for managed ingestion pipelines.
-
Click Run all.
Examples
The CrowdStrike Falcon Event Stream connector makes available 1 source table in the default source schema. Ingest the table or the entire schema.
Ingest specific tables
Use this option to customize destination naming for the table.
- Declarative Automation Bundles
- Databricks notebook
The following pipeline definition file ingests the CrowdStrike Falcon Event Stream table:
resources:
pipelines:
crowdstrike_falcon_event_stream_pipeline:
name: crowdstrike_falcon_event_stream_pipeline
catalog: 'main'
target: 'crowdstrike_falcon_event_stream_data'
ingestion_definition:
connection_name: crowdstrike_falcon_event_stream_connection
objects:
- table:
source_schema: 'default'
source_table: 'events'
destination_catalog: 'main'
destination_schema: 'crowdstrike_falcon_event_stream_data'
destination_table: 'events'
The following pipeline specification ingests the CrowdStrike Falcon Event Stream table:
pipeline_name = "crowdstrike_falcon_event_stream_pipeline"
connection_name = "<crowdstrike-falcon-event-stream-connection>"
pipeline_spec = {
"name": pipeline_name,
"ingestion_definition": {
"connection_name": connection_name,
"objects": [
{
"table": {
"source_schema": "default",
"source_table": "events",
"destination_catalog": "main",
"destination_schema": "crowdstrike_falcon_event_stream_data",
"destination_table": "events"
}
}
]
},
"channel": "PREVIEW"
}
json_payload = json.dumps(pipeline_spec, indent=2)
create_pipeline(json_payload)
Ingest the entire schema
Use this option to ingest all CrowdStrike Falcon Event Stream source tables into a single destination schema with one declaration.
- Declarative Automation Bundles
- Databricks notebook
The following pipeline definition file ingests all supported CrowdStrike Falcon Event Stream tables into a destination schema:
resources:
pipelines:
crowdstrike_falcon_event_stream_pipeline:
name: crowdstrike_falcon_event_stream_pipeline
catalog: 'main'
target: 'crowdstrike_falcon_event_stream_data'
ingestion_definition:
connection_name: crowdstrike_falcon_event_stream_connection
objects:
- schema:
source_schema: 'default'
destination_catalog: 'main'
destination_schema: 'crowdstrike_falcon_event_stream_data'
The following pipeline specification ingests all supported CrowdStrike Falcon Event Stream tables into a destination schema:
pipeline_name = "crowdstrike_falcon_event_stream_pipeline"
connection_name = "<crowdstrike-falcon-event-stream-connection>"
pipeline_spec = {
"name": pipeline_name,
"ingestion_definition": {
"connection_name": connection_name,
"objects": [
{
"schema": {
"source_schema": "default",
"destination_catalog": "main",
"destination_schema": "crowdstrike_falcon_event_stream_data"
}
}
]
},
"channel": "PREVIEW"
}
json_payload = json.dumps(pipeline_spec, indent=2)
create_pipeline(json_payload)
Declarative Automation Bundles job definition file
The following is an example job definition file for use with Declarative Automation Bundles. The job runs daily.
- Declarative Automation Bundles
resources:
jobs:
crowdstrike_falcon_event_stream_job:
name: crowdstrike_falcon_event_stream_job
schedule:
quartz_cron_expression: '0 0 0 * * ?'
timezone_id: 'UTC'
tasks:
- task_key: crowdstrike_falcon_event_stream_ingestion
pipeline_task:
pipeline_id: ${resources.pipelines.crowdstrike_falcon_event_stream_pipeline.id}
Common patterns
For advanced pipeline configurations, see Common patterns for managed ingestion pipelines.
Next steps
Start, schedule, and set alerts on your pipeline. See Common pipeline maintenance tasks.