CEF Sample Configuration

Version: 1

CrowdStrike SIEM Connector's CEF config file provided by Logpoint

Released in: Dec 2023

Note:

  • Use this reference config to create your own final config.

  • Specify the correct region in API & Request Token URLs. EU-1 region is taken as example here.

  • Syslog forwarding is enabled. Insert the IP address of the Logpoint in SYSLOG_SERVER_IP.

  • Events need to be enriched as the CrowdStrike's baseline config does not generate sufficiently detailed logs

  • Enrichment added to following events:

    • DetectionSummaryEvent

    • DetectionSummaryEvent_DnsRequests

    • DetectionSummaryEvent_NetworkAccesses

    • DetectionSummaryEvent_DocumentsAccessed

    • DetectionSummaryEvent_ScanResults

    • DetectionSummaryEvent_ExecutablesWritten

    • DetectionSummaryEvent_QuarantineFiles

    • UserActivityAuditEvent

    • AuthActivityAuditEvent

    • RemoteResponseSessionStartEvent

    • RemoteResponseSessionEndEvent

We do our best to ensure that the content we provide is complete, accurate and up to date. Logpoint makes no representations or warranties of any kind, express or implied about the documentation. We update it on a best-effort basis.

Last updated

Was this helpful?