CrowdStrike Falcon Next-Gen SIEM

CrowdStrike Falcon Next-Gen SIEM

This article details the configuration process to allow Lumu Logs to be processed by your CrowdStrike Falcon Next-Gen SIEM deployment.

Requirements

  • An active CrowdStrike Falcon Next-Gen SIEM subscription capable of enabling a HEC Data Connector.
  • An Active Lumu Insights or Lumu Defender subscription.

Preliminary set up - CrowdStrike Falcon Next-Gen SIEM

To successfully perform this integration from the Lumu Portal, you will need to do the following in your CrowdStrike Falcon Next-Gen SIEM Web console:

  • Create the parser
  • Create the connector

The following sections will guide you through the process.

Create the parser

First, you must create the Lumu parser. It allows the SIEM to parse and map the Lumu events to its data model. Open your CrowdStrike Falcon Next-Gen SIEM Web console and follow these steps:

1. In the console, use the hamburger menu at the top-left and navigate to Connectors > Data connectors > Parsers.


2. Click Create new parser.


3. Set the Parser name to lumu-defender. Leave the Blank template option selected. Then, click Create.


4. Clear the Parser script input area. Download the Lumu parser from this link. Copy, and paste its content into the cleared Parser script area. Then, click Save and exit.


Now, you can proceed to create the Data Connector.

Create the Connector

To successfully integrate with Lumu, you must create a HEC Data Connector. Follow these steps from where you left off in the previous section:

1. Go to Next-Gen SIEM > Log management > Data ingestion.


2. Select Add Connection.


3. Find and select the HEC/HTTP Event Connector. You can use the Filter by Connector Name search box and type http for a quick lookup.


4. Then, select Configure in the HEC/HTTP Event Connector modal.


5. Fill in the required data as follows:

  • Under Connection name set your preferred name for the data connection.
  • For Data timezone select UTC +00:00.
  • Under the Parsing and enrichment section, locate and select the specific Lumu parser.
  • Leave the Enable host enrichment option unchecked.
  • Confirm the Crowdstrike terms and conditions.
  • When finished, click Create connection.

6. After creating the connector, a confirmation box will appear. Close it.

7. Click Generate API Key.


8. Make sure to collect the URL and API Key information in this window. Save these values; they will be used during the Integration Setup step.


Having completed these steps, you can proceed with the integration in the Lumu Portal.

Integration Setup - Lumu portal

This section of the article describes the steps that must be completed on the Lumu portal to properly set up the CrowdStrike Next-Gen SIEM integration. To start, log in to your Lumu account through the Lumu Portal.

1. In the Lumu Portal, head to the panel on the left and go to Integrations > Apps.


2. Go to the Available Apps tab and select the SecOps option.


3. Locate the Next-Gen SIEM integration and click Add.


4. Review the detailed description provided for the app to understand the integration and click Activate to proceed with the activation.


5. Type the name and choose the Lumu events you want to ingest. Note that the New Incident event is always selected and sent. Once you have selected the desired events, click Next.


6. Enter the URL and API Key you saved earlier under URL and Token, respectively. Then, click Activate.


7. Once the integration is activated, you will see details of the created integration.


AlertDeleting the HEC/HTTP Event Connector will result in the integration going offline. We recommend avoiding deletion unless necessary. Alternatively, you can edit the token if needed.You can find the injected events in Next-Gen SIEM > Advanced event search. Lumu detections will be displayed in the CrowdStrike Falcon Next-Gen SIEM Unified Detection portal