Skip to main content

Troubleshoot the CrowdStrike Falcon Event Stream connector

Beta

This feature is in Beta. To use it, a workspace admin must turn on Lakeflow Connect for CrowdStrike Falcon Event Stream from the Previews page. See Manage Databricks previews.

Resolve common CrowdStrike Falcon Event Stream connector errors, including authentication failures, Event Stream feed discovery failures, and malformed events.

For general troubleshooting guidance that applies to all managed ingestion pipelines, see Troubleshoot managed ingestion pipelines.

Pipeline fails to authenticate​

Cause: CrowdStrike Falcon returned an HTTP 401 or 403 response, or the OAuth token exchange failed. This usually means the client ID or client secret isn't valid, someone revoked the API client, the Base URL doesn't match your Falcon cloud, or the API client doesn't have Event streams Read permission.

Solution:

  1. Confirm that the Client ID and Client Secret in the Unity Catalog connection match an active API client in the Falcon console.
  2. Confirm that the API client has the Event streams scope with Read permission.
  3. Confirm that Base URL includes the https:// scheme for your Falcon cloud (for example, https://api.crowdstrike.com or https://api.us-2.crowdstrike.com) and doesn't include a path.

For details, see Configure authentication to CrowdStrike Falcon.

Feed discovery fails​

Cause: The connector couldn't list Event Stream feeds (FEED_DISCOVERY_FAILED). Common causes include an API client without Event streams Read permission, an incorrect Base URL, or a CrowdStrike Falcon API error on GET /sensors/entities/datafeed/v2.

Solution:

  1. Confirm Event streams Read on the API client.
  2. Confirm the Base URL uses the https:// scheme and has no path.
  3. Confirm that Event Streams are available for your Falcon tenant. See CrowdStrike's Event Streams API documentation.

Session or access token refresh fails​

Cause: The connector couldn't refresh the CrowdStrike access token or Event Stream session token (TOKEN_REFRESH_FAILED).

Solution:

  1. Confirm that the API client is still active and the client secret hasn't been rotated without updating the Unity Catalog connection.
  2. Run the pipeline again. If the issue persists, recreate the API client and update the connection credentials.

Pipeline fails on a malformed event​

Cause: An Event Stream payload was missing required fields (MALFORMED_EVENT). Each event must include a top-level metadata object and event object, and metadata must include offset and eventCreationTime.

Solution:

Retry the pipeline. If the error persists for the same events, contact Databricks support with the pipeline update ID.