- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
CrowdStrike Integration
Hello Everyone,
we have followed the docx below to integrate with the crowdStrike EDR:
Crowdstrike | FortiSIEM 7.2.4 | Fortinet Document Library
we have successfully received the below event types:
Q1:- We didnt see any log related to the detection summary and alert of the EDR?
Q2:- Why is the reporting IP is the fortiSIEM supervisor, which is the discovery server, can we adjust that to be the Hostname of the CrowdStrike?
#fortisiem
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Did you get the printout here from the reports? If I understand correctly, you need to add raw data instead of count in the display tab to see the raw log.
You need to confirm the CrowdStrike ip by checking the devices in the CMDB tab. I suggest you check the reporting ip again with Device>action>historical events.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Ok, thanks!
we integrated with CrowdStrike EDR using API, so the FortiSIEM Supervisor pulls the events.
we can access EDR Events from Admin => Setup => Pull Events.
We searched all the logs but the detection summary logs dont come out.
Is there anything we can do to eneble receiving the detection summary?
