Get started with the CrowdStrike Falcon X Sandbox integration
Activate and set up the CrowdStrike Falcon X Sandbox to interface with your ServiceNow instance and Security Incident Response product.
Before you begin
- Before you can use the CrowdStrike Falcon X Sandbox for Security Operations integration, you must download it from the ServiceNow Store.
- Review the following setup checklist and verify that you have completed all the tasks for a smooth CrowdStrike Falcon X Sandbox integration.
| Setup task | Description |
|---|---|
Verify that you have assigned the required ServiceNow AI Platform and Security Incident Response roles. |
The following roles are required for configuration and
verification of the expected results:
|
Verify that the ServiceNow core applications that are required to support the integration are installed and activated before you configure this integration. |
This integration is supported on Paris and Orlando releases. Ensure that these dependent plugins are
installed.
These plugins
enable
the
execution of Integration Hub
actions and flows:
Note: If you
can't
find a plugin, you may have to request it from ServiceNow personnel. To request a
plugin, follow the steps in Request a
plugin. The Security Incident Response plugin (com.snc.security_incident) is required. This plugin automatically installs all the dependencies that are required to support the Security Incident Response product. Install and activate this plugin before you install and activate the other Security Operations applications that are required by the integration. Verify that the following Security Operations applications are installed and activated from the ServiceNow Store. If not installed, install and activate one application at a time in the following order to ensure a smooth installation.
For more information on setting up your ServiceNow AI Platform instance for the integration, see Get entitlement for a Security Operations product or application and Activate a ServiceNow Store application. |
Verify that you are licensed for the Falcon Sandbox Private API key, and obtain the CrowdStrike Falcon X Sandbox full API key. |
This integration supports the Falcon Sandbox Private Cloud
only.
Note: This release does not support Falcon X
integration. CrowdStrike Falcon X Sandbox offers a self-signed restricted API key and an upgraded full API key. Use the full API key for this integration because it enables unrestricted access for automated submissions. For more information, see CrowdStrike Falcon Sandbox Knowledge Base. |
Procedure
What to do next
After you successfully complete the integration, the next step is to set up Sandbox submission configurations.