Overview
This article is a user guide for the CrowdStrike Falcon Next-Gen SIEM Intelligence Engine app in ThreatConnect.
The CrowdStrike Falcon Next-Gen SIEM Intelligence Engine pulls Next-Gen SIEM alerts into ThreatConnect as Event groups, finds the IOCs matched by each alert, and associates them with the Event so playbooks can act straight away.
The app runs as a Feed API Service. It polls the CrowdStrike Alerts API on a recurring schedule, then runs a Next-Gen SIEM search for each alert to retrieve the rule-match events that hold its IOCs. Alerts and indicators are written to ThreatConnect through the Batch API.
The app ingests the following CrowdStrike object types and creates the corresponding ThreatConnect objects:
- Next-Gen SIEM alert (correlation detection) becomes an Event group.
- IOC from an alert's rule-match event becomes an Address, EmailAddress, File, Host or URL indicator, associated with its parent Event.
This app is ingest-only (Next-Gen SIEM to ThreatConnect). Exporting ThreatConnect indicators to Next-Gen SIEM lookup tables is handled by a separate app, CrowdStrike Falcon Next-Gen SIEM Egress.
Dependencies
ThreatConnect Dependencies
- Active ThreatConnect API key.
- ThreatConnect version 7.11.2 or newer.
- System Administrator account to install the app and deploy it with Feed Deployer.
All ThreatConnect dependencies are provided by default to subscribing ThreatConnect Cloud customers. Customers on Dedicated Cloud and On-Premises instances can enable these settings on the Account Settings screen within their ThreatConnect instance.
CrowdStrike Dependencies
- A CrowdStrike Falcon tenant licensed for Falcon Next-Gen SIEM.
- A CrowdStrike API client (Client ID and Client Secret) created in the Falcon console under Support and resources > API clients and keys, with these scopes:
- Alerts: Read
- Next-Gen SIEM (event search): Read
- The cloud region (API base URL) your Falcon tenant lives in: US-1, US-2, EU-1 or US-Gov-1.
Application Setup and Configuration
The CrowdStrike Falcon Next-Gen SIEM Intelligence Engine app uses Feed Deployer to create a Source for Next-Gen SIEM data in an Organization (default name CrowdStrike Next-Gen SIEM Intelligence) and to configure the matching Feed API Service. After you install the app on your ThreatConnect instance, deploy it separately to each Organization that needs its own Source and service.
Install the CrowdStrike Falcon Next-Gen SIEM Intelligence Engine App
- Log into ThreatConnect with a System Administrator account.
- From the Settings menu on the top navigation bar, select TC Exchange Settings.
- Select the Catalog tab.
- Locate the CrowdStrike Falcon Next-Gen SIEM Intelligence Engine app.
- Click Install in the Options column for the app.
- Click INSTALL in the app's Release Notes window.
Feed Deployer opens automatically after the install. Continue with the next section.
Deploy the CrowdStrike Falcon Next-Gen SIEM Intelligence Engine App to an Organization
Skip to step 4 if you just installed the app and the Feed Deployer window is already open.
- Log into ThreatConnect with a System Administrator account.
- From the Settings menu on the top navigation bar, select TC Exchange Settings.
- On the Installed tab, locate the app and select Deploy from the Options (⋮) menu.
- Complete the Feed Deployer fields using Table 1.
- Click DEPLOY on the Confirm tab. Feed Deployer creates the Source in the Organization and the Feed API Service for it.
The app runs a connection check on startup, querying one hour of alerts with your configured query. If the credentials, region or query are wrong, the service logs the failure and does not start ingesting.
Table 1
| Tab | Field | Required | Description |
|---|---|---|---|
| Source | Sources to Create | Required | Name of the Source. Must be unique on the instance unless you are redeploying to an existing Source. Adding the Organization name helps, for example CrowdStrike Next-Gen SIEM Intelligence - Demo Org. |
| Source | Owner | Required | Organization that will own the Source. |
| Source | Activate Deprecation | Optional | Allows confidence deprecation rules to be applied to indicators in the Source. |
| Source | Create Attributes | Optional | Creates the custom attribute types this app uses (Vendor Priority, Correlation Rule ID, Event ID, Tenant ID). Keep this selected, or data mapped to those attributes is not ingested. |
| Parameters | Launch Server | Required | Select tc-job. |
| Parameters | CrowdStrike API Endpoint | Required | Region of your Falcon tenant: US-1 (api.crowdstrike.com), US-Gov-1 (api.laggar.gcw.crowdstrike.com), EU-1 (api.eu-1.crowdstrike.com) or US-2 (api.us-2.crowdstrike.com). |
| Parameters | Crowdstrike API Client ID | Required | Client ID of the CrowdStrike API client. Accepts a user or organization TEXT variable. |
| Parameters | Crowdstrike API Client Secret | Required | Client Secret of the CrowdStrike API client. Encrypted at rest. Accepts a user or organization KEYCHAIN variable. |
| Parameters | Next-Gen SIEM Alert Query | Optional | Falcon Query Language (FQL) filter for the Alerts API. The app adds the time window (updated_timestamp) itself, so leave dates out. Default: `product:'ngsiem'+type:'correlation-detection'+severity_name:['Critical', 'High’]) |
| Confirm | Run Feeds after deployment | Optional | Starts the service as soon as you click DEPLOY. |
| Confirm | Confirm Deployment Over Existing Source | Optional | Shown only if the Source name already exists in the selected Organization. Select it to redeploy to that Source. |
Redeploying a Feed API Service to an existing Source can overwrite data in that Source and create a new service. Delete the old service once the new one is running.
It is advised to tighten volume with FQL; for example, if you are only interested in critical severity detections, use the following FQL: product:'ngsiem'+type:'correlation-detection'+severity_name:['Critical']
Ingestion schedule
| Setting | Value |
|---|---|
| Initial backfill | 60 days, split into 8 hour download jobs |
| Ongoing polling | One job per hour of alert activity |
| Catch-up | If the service is down for more than 8 hours, missed time is backfilled in 8 hour chunks on restart |
| Job retries | Up to 10 retries per job before it is marked failed |
Alerts are selected by updated_timestamp, so an alert that changes in Next-Gen SIEM (status change, reassignment) is picked up again and its Event is updated in place.
CrowdStrike Falcon Next-Gen SIEM Intelligence Engine UI
The service UI is where you monitor and manage ingestion into the Source.
- Log into ThreatConnect with a System Administrator account, or a user with the Organization Administrator role in the Organization that owns the Source.
- From the Automation & Feeds dropdown on the top navigation bar, select Services.
- Locate the row for the CrowdStrike Falcon Next-Gen SIEM Intelligence Engine service.
- Turn on the toggle in the Enable column if the service is not already enabled.
- Click the link in the service's API Path field to open the UI.
Select Feed Service from the Service Type dropdown to show only Feed API Services. If the app is deployed to several Organizations, click a row to open its Details drawer and check the Organization field
The following screens are available: Dashboard, Jobs, Tasks, Download, Batch Errors and Notifications.
Dashboard
Summary of service health and ingestion metrics: job counts by status and totals of Events and indicators downloaded and uploaded.
Jobs
Lists every download job with its pipeline (ingest), job type (Scheduled or Ad-Hoc), time window and status. Columns show Groups Downloaded, Groups Uploaded, Indicators Downloaded and Indicators Uploaded. Filter by Job ID, Job Type, Pipeline and Status. Select a job to see per-stage timings (download, convert, upload), retry count and batch error count.
Add a Job
Use an ad-hoc job to re-pull a specific window, for example after fixing the alert query.
- On the Jobs screen, click Add Job.
- Set Start Time and End Time. Start must be earlier than End.
- Click Submit. The job runs through Download, Convert and Upload like a scheduled job.
Tasks
Shows the background tasks and when they last ran.
| Task | Runs every | Purpose |
|---|---|---|
| Download - Ingest | 10 seconds | Pulls alerts, then runs one indicator search per alert |
| Convert - Ingest | 30 seconds | Maps alerts and IOCs to ThreatConnect batch format |
| Upload - Ingest | 10 seconds | Submits batch files and polls for completion |
| Cleaner | 10 seconds | Cleans the filesystem and the database. |
| Schedule Downloads | 5 seconds | Creates backfill and hourly jobs |
Download
Pull specific alerts on demand and see exactly how they map.
- Set Type to Event.
- Enter one or more CrowdStrike alert composite IDs in Event ID(s), separated by commas.
- Click Download. Results show the raw CrowdStrike JSON next to the converted ThreatConnect batch JSON.
- Click Upload to submit the converted data through the Batch API.
Useful when checking why a field mapped the way it did, or re-ingesting a single alert.
Batch Errors
Lists errors returned by the ThreatConnect Batch API for each job, for example an attribute value that failed validation. Use this screen first when Groups Uploaded is lower than Groups Downloaded.
Notifications
Shows service notifications with category, priority, message and send status. Notifications are batched into a digest every 2 hours by default. Default categories are app startup, job retrying, job failed and job recovered.
Data Mappings
Next-Gen SIEM Alert to ThreatConnect Event
Each alert returned by the CrowdStrike Alerts API becomes one ThreatConnect Event group. The Event's XID is a hash of the alert composite_id, so the same alert always updates the same Event.
| CrowdStrike field | ThreatConnect field | Notes |
|---|---|---|
display_name plus composite_id |
Name | Format <display name> [<id>], truncated to 500 characters |
created_timestamp |
Event Date | |
status |
Status | new = New in_progress = In Progress reopened = Reopened closed = Completed |
description |
Description | |
severity_name |
Severity (attribute) | Critical, High, Medium, Low |
severity (0 to 100) |
Confidence (attribute) | 0 = None 1 to 39 = Low 40 to 74 = Medium 75 to 100 = High empty = Unknown |
priority_value |
Vendor Priority (attribute) | Integer 0 to 100 |
correlation_rule_id |
Correlation Rule ID (attribute) | Unique NG SIEM detection rule that triggered the alert. |
event_ids |
Event ID (attribute) | |
cid |
Tenant ID (attribute) | CrowdStrike Customer ID |
falcon_host_link |
Source (attribute) | Link back to the alert in the NG SIEM console |
severity_name |
Tag | Severity: <value> |
type |
Tag | Type: <value> |
product |
Tag | Product: <value> |
mitre_attack[].technique_id |
Tag | Converted to ThreatConnect MITRE ATT&CK technique tags |
All attributes are written with the source CrowdStrike Next-Gen SIEM.
Rule-Match IOC to ThreatConnect Indicator
For each alert, the app searches the Next-Gen SIEM search-all view for Ngsiem.event.type="ngsiem-rule-match-event" events tied to the alert (Ngsiem.alert.id). Each ioc[n] entry in those events becomes one indicator.
CrowdStrike IOC type |
ThreatConnect indicator |
|---|---|
ip_address |
Address |
domain |
Host |
url |
URL |
email_address |
EmailAddress |
hash_md5 |
File (MD5) |
hash_sha1 |
File (SHA1) |
hash_sha256 |
File (SHA256) |
IOC types with no ThreatConnect equivalent (for example mutex names, user agents and X.509 serials) are skipped.
| CrowdStrike field | ThreatConnect field | Notes |
|---|---|---|
ioc[n].indicator |
Indicator value | |
ioc[n].malicious_confidence |
Threat Confidence and Threat Rating | high = 75 / 4 medium = 50 / 3 low = 25 / 2 unverified = 10 / 1 Left blank if missing. |
ioc[n].labels |
Tags | Comma-separated labels, one tag each |
Ngsiem.alert.id |
Association | Associated with the Event created from that alert |
If the same IOC appears in several alerts within one job, it is written once and associated with every matching Event.
Workflow/Use Cases
Automated alert triage
Events are created with playbook triggers enabled. Build a playbook on the Event Created trigger, scoped to the CrowdStrike Next-Gen SIEM Intelligence Source, to enrich the associated indicators, open a Case or notify the on-call analyst. Filter on the Severity: Critical tag or the Vendor Priority attribute so low-value alerts never reach the queue.
Analyst pivot from TIP back to Next-Gen SIEM
The Source attribute on every Event holds the Next-Gen SIEM console link for the alert. Analysts can jump from the ThreatConnect Event straight to the alert without searching by ID.
Correlation rule tuning
The Correlation Rule ID attribute shows which Next-Gen SIEM rule fired each Event. Use ThreatConnect search or dashboards on that attribute to find the rules producing the most Events, and tune or retire noisy ones in Next-Gen SIEM.
Tracking alert lifecycle
Because alerts are re-pulled when updated in CrowdStrike, the Event Status in ThreatConnect follows the alert's status in Next-Gen SIEM (New, In Progress, Reopened, Completed).
Troubleshooting
The service will not start, or the log shows a failed connection check.
The startup check queries the Alerts API with your query and credentials. Confirm the region matches your tenant, the API client has Alerts: Read, and the Client Secret has not been rotated.
Events arrive but have no associated indicators.**
- Confirm the API client has Next-Gen SIEM search (Read) scope. Alerts can be read without it, but the indicator search fails.
- The indicator search only covers the job's time window. If an alert was updated long after the rule-match event that created it, the IOC may sit outside that window. Run an ad-hoc job with a wider window to recover it.
- Only the seven IOC types listed under Data Mappings are imported.
No Events are created at all.**
Check the Next-Gen SIEM Alert Query. It must be valid FQL for the Alerts API, not a CQL search string. A query such as #type=alert severity=high | head(500) is rejected by the Alerts API.
Fewer Events uploaded than downloaded.**
Open Batch Errors for the job. Attribute validation failures (for example Tenant ID or Correlation Rule ID not matching the expected 32-character hex format) show up here.
Tags or attributes an analyst added to an Event disappear.**
The app replaces tags and attributes on an Event each time the alert is updated in CrowdStrike. Record analyst work in a Case, a Note, or a separate group instead of tagging the ingested Event.
Ingestion is slow during the first deployment.**
The first run backfills 60 days in 8 hour chunks and runs one search per alert. Large tenants should narrow the query (for example Critical only) for the initial deployment.
Frequently Asked Questions (FAQ)
Does this app send ThreatConnect indicators to Next-Gen SIEM?
No. This app only ingests alerts. Use the CrowdStrike Falcon Next-Gen SIEM Egress app to push indicators into Next-Gen SIEM lookup files.
Will re-polling an alert create duplicate Events?
No. The Event XID is a hash of the alert composite_id, so the same alert always updates the same Event.
Can I ingest alerts other than Next-Gen SIEM correlation detections?
The query field accepts any Alerts API FQL filter, so it is technically possible. It is not recommended, because the indicator extraction only works for Next-Gen SIEM rule-match events.
How far back does the first sync go?
60 days.
Can I deploy the app to more than one Organization?
Yes. Deploy it separately to each Organization. Each deployment gets its own Source and service.