Skip to main content

Cloud-delivered Incident ResponderIncident Responder Documentation

Configure the CrowdStrike Falcon Host API Service Service

Configure the CrowdStrike Falcon Host OAuth2-based API as a service to get entity and artifact reputations, search hosts, and run other CrowdStrike Falcon actions.

  • Note the client ID and client secret of the API client you created.

  • Ensure you assign specific scopes to the API client:

    • Detections

    • Hosts

    • Sandbox

    • Host Groups

    • IOC Manager

    • IOCs

    • Prevention Policies

    • Real Time Response (Admin)

    • Real Time Response

    • Sample Uploads

    • Sensor Update Policies

    • User Management

  • Note the API IP address or domain of your CrowdStrike Falcon endpoint.

  • If you use a proxy, ensure that you whitelist the API IP address or domain.

  1. In the sidebar, click SETTINGSA grey gear icon, then select Core.

  2. Under SERVICE INTEGRATIONS, select Services.

  3. Select a service:

    • To configure a specific service, hover over a service, then click CONFIGURE. Use the search by vendor or filter by action to find a service.

    • To manually provide the relevant information for a service, click Configure a new serviceA dark blue plus sign..

    • To view all actions for a service, hover over a service, then click the information icon An icon of a grey i inside a grey circle..

  4. Enter information about the service:

    • Service Name – Enter a unique name for the service. By default, the service name is CrowdstrikeFalconV2.

    • (Optional) Description – Describe the service.

    • (Optional) Owner – Enter the email address of the person or group responsible for the service. 

    • Client ID – Enter the client ID of your CrowdStrike Falcon API client.

    • Client Secret – Enter the client secret of your CrowdStrike Falcon API.

    • API Host – Enter the IP address or domain of your CrowdStrike Falcon endpoint.

  5. To validate the source, select TEST CONNECTIVITY.

  6. Select CREATE SERVICE.