This article details the configuration process to allow Lumu Logs to be processed by your CrowdStrike Falcon Next-Gen SIEM deployment.
To successfully perform this integration from the Lumu Portal, you will need to do the following in your CrowdStrike Falcon Next-Gen SIEM Web console:
The following sections will guide you through the process.
First, you must create the Lumu parser. It allows the SIEM to parse and map the Lumu events to its data model. Open your CrowdStrike Falcon Next-Gen SIEM Web console and follow these steps:
1. In the console, use the hamburger menu at the top-left and navigate to Connectors > Data connectors > Parsers.
2. Click Create new parser.
3. Set the Parser name to lumu-defender. Leave the Blank template option selected. Then, click Create.
4. Clear the Parser script input area. Download the Lumu parser from this link. Copy, and paste its content into the cleared Parser script area. Then, click Save and exit.
Now, you can proceed to create the Data Connector.
To successfully integrate with Lumu, you must create a HEC Data Connector. Follow these steps from where you left off in the previous section:
1. Go to Next-Gen SIEM > Log management > Data ingestion.
2. Select Add Connection.
3. Find and select the HEC/HTTP Event Connector. You can use the Filter by Connector Name search box and type http for a quick lookup.
4. Then, select Configure in the HEC/HTTP Event Connector modal.
5. Fill in the required data as follows:
6. After creating the connector, a confirmation box will appear. Close it.
7. Click Generate API Key.
8. Make sure to collect the URL and API Key information in this window. Save these values; they will be used during the Integration Setup step.
Having completed these steps, you can proceed with the integration in the Lumu Portal.
This section of the article describes the steps that must be completed on the Lumu portal to properly set up the CrowdStrike Next-Gen SIEM integration. To start, log in to your Lumu account through the Lumu Portal.
1. In the Lumu Portal, head to the panel on the left and go to Integrations > Apps.
2. Go to the Available Apps tab and select the SecOps option.
3. Locate the Next-Gen SIEM integration and click Add.
4. Review the detailed description provided for the app to understand the integration and click Activate to proceed with the activation.
5. Type the name and choose the Lumu events you want to ingest. Note that the New Incident event is always selected and sent. Once you have selected the desired events, click Next.
6. Enter the URL and API Key you saved earlier under URL and Token, respectively. Then, click Activate.
7. Once the integration is activated, you will see details of the created integration.
Deleting the HEC/HTTP Event Connector will result in the integration going offline. We recommend avoiding deletion unless necessary. Alternatively, you can edit the token if needed.You can find the injected events in Next-Gen SIEM > Advanced event search. Lumu detections will be displayed in the CrowdStrike Falcon Next-Gen SIEM Unified Detection portal.