---
sourceDocument: Xanadu Security Management
sourceDocumentLink: https://www.servicenow.com/docs/r/xanadu/security-management

 Release :

    - xanadu

ft:locale :

    - en-US

ft:publication_title :

    - Xanadu Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Install and configure CrowdStrike Next-Gen SIEM integration

# Install and configure CrowdStrike Next-Gen SIEM integration {#ariaid-title1}

* Release version: Xanadu
* 
* Updated June 5, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Install and configure the CrowdStrike Next-Gen SIEM integration for Security Operations application from the ServiceNow Store on your ServiceNow AI Platform instance.

## Before you begin

Role required: sn_si.ingestion_profile_admin  
Note:  
Users with the sn_si.admin role can perform all operations available to a profile admin because this role inherits the required permissions by default.

## Procedure

1. Download the CrowdStrike Next-Gen SIEM integration from the ServiceNow Store and install it.  
   For more information, see [Download an application from the ServiceNow Store for the first time](https://www.servicenow.com/docs/O2ABmFrJWRJoKsbX5CvJ7Q "Downloading an application from the ServiceNow Store for the first time involves a number of easy steps. Some of the steps are performed on the ServiceNow Store and some in your instance.")
2. Navigate to Security OperationsIntegrationsIntegration Configurations.
3. Search for the CrowdStrike Next-Gen SIEM integration tile, and select Configure.
4. On the form, fill in the fields.  
   {#cs-ng-siem-integration__table_evw_xjl_gxc__entry__2}

   | Field | Description |
   |-|-|
   | Name | Name of the CrowdStrike Next-Gen SIEM integration. |
   | Client ID | The client ID that you obtain from the settings section of your account profile in the CrowdStrike portal. |
   | Client Secret | The client secret key that you obtain from the settings section of your account profile in the CrowdStrike portal. |
   | Region | Data center to pull data from. Specify the Region: US-1, US-2, EU-1, US-GOV-1, US-GOV-2 By default, the field is set to US-1 |
   [Table 1. CrowdStrike Next-Gen SIEM integration form]

   {#cs-ng-siem-integration__table_evw_xjl_gxc}
5. Select Submit.  
   The configured integration tile displays.

## What to do next

[Create a detection profile for CrowdStrike Next-Gen SIEM](https://www.servicenow.com/docs/fELeQjhhQDftRTZ3NBC7rA "Determine the CrowdStrike Next-Gen SIEM detections that are suitable for creating security incidents by creating a detection profile in your ServiceNow AI Platform instance.")

*[\>]: and then


