Skip to content

Latest commit

 

History

History
40 lines (24 loc) · 1.32 KB

File metadata and controls

40 lines (24 loc) · 1.32 KB

User Guide for deploying Falcon Integration Gateway for Chronicle from GKE Marketplace

Prerequisites:

  • Have CrowdStrike CWP Subscription
  • Have Chronicle Subscription

Step 1: Obtain OAuth2 API credentials for CrowdStrike Falcon

  • Navigate to API Clients and Keys within CrowdStrike Falcon platform.
  • Use Add new API client* button in the top right corner to create a new key pair
  • Make sure only the following permissions are assigned to the key pair:
  • Event streams: READ
  • Hosts: READ

api keys

Step 2: Obtain Chroncile Service Account file & Customer ID.

Your Chronicle support representative can provide this file.

Step 3: Navigate to Falcon Integration Gateway Listing Page

Marketplace Link

overview

Step 4: Configure the application

Configure button leads you to application configuration page.

  • Fill in Falcon OAuth2 API credentials obtained in Step 1 of this guide.
  • Fill in Chronicle Customer ID and Chronicle Region

configure

Step 5: Hit deploy button

starting

application