CrowdStrike
Generate API credentials in CrowdStrike
Note: To define a CrowdStrike API client, you must be designated as Falcon Administrator role to view, create, or modify API clients or keys. Secrets are only shown when a new API Client is created or when it is reset.
When logged into the Falcon UI, navigate to Support > API Clients and Keys.
When you click “Add new API Client” you will be prompted to give a descriptive name and select the appropriate API scopes:
user management:readAfter you click save, you will be presented with the Client ID and Client Secret.
API hostname will be
api.crowdstrike.comby default but also support different sub-domain likehttps://api.us-2.crowdstrike.com
Note: The secret will only be shown once and should be stored in a secure place. If the Client Secret is lost, a reset must be performed and any applications relying on the Client Secret will need to be updated with the new credentials.
Setup CrowdStrike Application API Integration on Zilla
Visit the Zilla application and login using your admin credentials and then click on
Add Applicationin the top right.
A window with a search bar appears, type in
CrowdStrikein the search bar and hit enter.CrowdStrikeapp entry will appear at the top of the list, clickAdd to Applicationsbutton to the right.
Fill in the form with appropriate details and then click
Add to Applications.
The
CrowdStrikeapp will be added to the Applications tab. Click onCrowdStrikein Application column.
A detailed view of
CrowdStrikeapplication appears. ClickSync nowin top right corner.
Enable API Integration. Enter the
API hostname,API client IDandAPI client secretobtained above into the respective text boxes and clickSync Now/Next.
Click
Nextand the sync will begin, then clickDone.
Successful sync will pop up with Sync Summary.