Retrieves detailed asset data on hosts running the CrowdStrike Falcon sensor via the Falcon Hosts API, for asset visibility and vulnerability mapping.
Sync Type: Full Synchronisation
Requirements
Before you connect Monad to CrowdStrike, you need a Client ID and Client Secret. Log in to your CrowdStrike portal, and under Support & Resources, click on 'API Client and Keys' to create your credentials.
Enter a Client Name, Description and API Scopes to define the API client. Ensure read roles for Hosts are enabled.
Click Done.
Copy the ClientID and ClientSecret key. You'll need them when you set up the Monad connector.
Details
Monad uses the cron field to run on specific intervals and returns all device details, performing a full sync of data each time.
Configuration
The following configuration defines the input parameters. Each field's specifications, such as type, requirements, and descriptions, are detailed below.
Settings
Setting
Type
Required
Description
Cron
string
Yes
Cron string for scheduling tasks. Ex: '0 0 * * *' for daily execution at midnight.
Cloud Type
string
No
Your cloud type for CrowdStrike. Ex: 'autodiscover', 'us-1', 'us-2', 'eu-1', 'us-gov-1'.
Secrets
Secret
Type
Required
Description
Client ID
string
Yes
Client ID for the CrowdStrike API. This is required to authenticate requests.
Client Secret
string
Yes
Client Secret for the CrowdStrike API. This is required to authenticate requests.
OCSF Conversion
The following JQ transformation converts Crowdstrike Device Details data to OCSF Version 1.1.0 compliant format.