About the integration:
Detect, prevent, and respond to cyber threats effectively by using the Crowdstrike-Freshservice integration. Ensure that your team responds to the most important alerts immediately by creating them into incidents using alert rules.
Configuration in Freshservice:
Step 1:
Head to the Admin panel, scroll to IT Operations Management and select Monitoring Tools.
Step 2:
You are now on the Monitoring Tools list page. Select Add monitoring tool to add a new integration.
Step 3:
You will see a list of pre-configured integrations, the gateway to custom integration using webhooks, and the option to use email as a channel for alerts. Select Crowdstrike.
Step 4:
A URL and auth-Key will be generated. You will require this to set up the integration in Crowdstrike.
Configuration in Crowdstrike:
- Log into your Crowdstike account.
- Go to CrowdStrike store> All Apps.
- Select the Crowsdstrike Webhook plugin.
- Click on Configure
- Click on Add Configuration.
- Configure the following details:
- Provide a name to the configuration.
- Paste the "Auth query param" generated in Step 4 of the Freshservice configuration in the Webhook URL field. The HMAC Secret Key field is not required for this integration to work. Please fill this field using any dummy value of 32 characters.
- Check Notify on the configuration failure option.
- Click on Save configuration.
- Go to Host setup & management> Fusion workflows.
- Click on Create workflow. You can create a workflow from scratch or create a workflow using a playbook.
- Add the conditions based on which you want to trigger an alert.
- Add an action node. In the action node configure the following:
- Select action type as "Notifications"
- Set action as "Call to webhook"
- Choose the webhook name you saved as part of Step 6 of Crowdstrike configuration.
- In the data to include section, include the following parameters:
Workflow name Sensor domains Host groups Status Sensor hostname Local IP Severity User ID File Path IOC Value Sensor ID User Name Description External IP Action Taken Bios Version Detection ID Product Type Workflow execution timestamp System product Trigger Name Trigger Category
- Select action type as "Notifications"
- Save the workflow.
Now you should be able to receive an alert in Freshservice every time the alert condition is satisfied in CrowdStrike