Skip to content

Enhance CrowdStrike Integrations with Comprehensive Testing and Coverage Expansion #14135

@jamiehynds

Description

@jamiehynds

Current Situation:
We support multiple CrowdStrike data ingestion methods, including the Falcon SIEM Connector, Event Streaming API, Falcon Data Replicator, and REST API. Our integration covers various CrowdStrike modules such as endpoint, vulnerabilities, threat intelligence, host data, and more.

Challenge:
Until recently, testing our CrowdStrike integrations was limited by lack of access to the Falcon platform. Thanks to our new technology partnership with CrowdStrike, we now have direct access to a CrowdStrike instance.

Goals:

Populate the CrowdStrike Instance:

Fully populate our CrowdStrike instance to closely replicate a typical customer deployment.

Align the data in this instance with the types of data supported by our existing integrations.

Continuous Testing and Validation:

Use our integrations to ingest data from the populated CrowdStrike instance into an Elastic instance.

Perform ongoing testing across dashboards, pipelines, performance, and scalability.

Identify and resolve any bugs, performance bottlenecks, or data normalization issues to improve reliability and user experience.

Expand Integration Coverage:

Review and compare our current CrowdStrike integrations against all available CrowdStrike modules.

Prioritize building support for modules we do not currently cover, such as Identity Protection, to broaden our offering and meet evolving customer needs.

Sub-issues

Metadata

Metadata

Labels

Integration:crowdstrikeCrowdStrikeIntegration:ti_crowdstrikeCrowdStrike Falcon IntelligenceTeam:Security-Service IntegrationsSecurity Service Integrations team [elastic/security-service-integrations]Team:Sit-CrestCrest developers on the Security Integrations team [elastic/sit-crest-contractors]

Type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions