Getting started with the CrowdStrike Falcon Insight integration
You can activate and set up the CrowdStrike Falcon Insight to interface with your ServiceNow AI Platform instance and Security Incident Response product.
Before you begin
Role required: admin
Before you can use CrowdStrike Falcon Insight for the Security Operations integration, you must download it from the ServiceNow Store.
About this task
| Setup task | Description |
|---|---|
| Assign and verify the required ServiceNow AI Platform and Security Incident Response roles. | These roles are required for configuration and verification of the expected results:
|
| Verify that the ServiceNow core applications that are required to support the integration are installed and activated before you configure this integration. | The ServiceNow Integration Hub Enterprise Pack Installer [com.glide.hub.integrations.enterprise] plugin is required. This plugin enables the execution of IntegrationHub actions and flows: The Security Incident Response plugin (com.snc.security_incident) is required. This plugin automatically installs all the dependencies that are required to support the Security Incident Response product. Install and activate this plugin before you install and activate the other Security Operations applications that are required by the integration. Verify that the following Security Operations applications are installed and activated from the ServiceNow Store. If these applications are not already installed, you must install and activate each application one at a time in the following order to ensure a smooth installation:
|
| Set up an approval group. | An optional approval capability is available for isolating host machines, restoring them to the network, and initiating sightings searches. To enable this option, you require prior approval from the sn_si.admin role before host machines are isolated and restored to your network, or when sightings searches are performed. If you require an extra level of control over these actions, enable the Require approval option when configuring the profile. The approval authority is assigned to the user with the sn_si.admin role. You can also reassign this approval authority to an approval group. |
| Assign and verify the CrowdStrike Falcon Platform roles. | The following roles are required on the CrowdStrike Falcon Platform for the integration configuration:
|
| Verify that the custom scripts roles and permissions are enabled in the CrowdStrike Falcon Platform. | This integration uses CrowdStrike's custom scripts for few of the enrichment capabilities.
|
| Generate API clients and keys in the CrowdStrike Falcon Platform. | Create the CrowdStrike API clients or keys in the CrowdStrike Falcon Platform to use in the ServiceNow AI Platform integration configuration. |