CrowdStrike Falcon EDR Configuration Guide
Introduction
The CrowdStrike Falcon EDR connector requires a Client ID, Client Secret, and Base URL to access the Falcon API. These values are generated when you create an API client in the Falcon console.
Prerequisites
- Access to the CrowdStrike Falcon console
- Administrator privileges in the Falcon console
Creating the API Client
-
Log in to CrowdStrike Falcon.
-
Open the menu in the upper left corner and go to Support and resources > API clients and keys.
-
Click Create API Client.
-
Enter a client name and description.
-
Grant the following API scopes with Read access. Write access is not required.
- Hosts: Read
- Sensor update policies: Read
- Prevention policies: Read
-
Click Create.
The Client ID, Client Secret, and Base URL are displayed only once. Copy and store them before closing the dialog.
Scopes can be edited after the client is created.