Skip to main content
Telara

Integrations / CrowdStrike Falcon

CrowdStrike Falcon logo

CrowdStrike Falcon

CrowdStrike Falcon endpoint security for hosts, detections, alerts, incidents, sensor health, and threat response.

OAuth 2.0
Indexes
Actions
Events

What Telara does

Capability matrix

Before you connect

Prerequisites

A CrowdStrike Falcon tenant you can administer.
Falcon administrator who can create API clients under Support or API clients and keys.

Vendor setup

Get the credential

1
Open API clients
In the Falcon console, go to Support and resources → API clients and keys (wording is API Clients and Keys under the menu).
2
Create a client
Click Add new API client. Name it for Telara. Grant the permissions this page lists from the catalog. Copy the client id and secret — CrowdStrike shows the secret once.
3
Paste in Telara
Settings → Integrations → CrowdStrike Falcon. Enter client id, secret, and the cloud region your tenant uses (US-1, US-2, EU-1, and so on).

In Telara

Connect in Telara

OAuth 2.0

CrowdStrike Falcon OAuth2 API client using client ID/secret. Base URL may vary by cloud region.

In Telara, open Settings → Integrations, choose this connector, and click Connect. Telara sends you to the vendor to approve access, then returns you here. You do not create an OAuth app or paste a client secret.

Knowledge

What gets indexed

ResourceCoverage
HostPartial — not every record the vendor holds is synced
DetectionPartial — not every record the vendor holds is synced

Sync

Freshness & sync

ResourceLagDeletions
HostUp to 1 dayRemoved records disappear on the next full sync
DetectionUp to 1 hourRemoved records disappear on the next full sync

Data handling

Permissions & data handling

Telara has not published a permission list for this connector yet. Treat the vendor consent screen as the source of truth until this page lists scopes.

Excluded from semantic search: Host, Detection.

After connect

Verify it worked

This connector does not declare a credential probe yet. A saved connection means Telara stored the credential, not that the vendor accepted it.

Honesty

Known limitations

The wrong cloud region authenticates nowhere. Copy the region from the Falcon URL you log into.
A client missing host or detections read produces an empty estate, not always an auth error.