Introduction
This guide will explain to you how to integrate NordPass Activity Logs with CrowdStrike Next-Gen SIEM, as well as how to manage and verify the connection.
Before you start
To integrate NordPass Activity Logs into CrowdStrike Next-Gen SIEM, you must:
- Have an active NordPass Enterprise subscription and Owner/Admin role.
- Have a CrowdStrike subscription: Falcon Next-Gen SIEM or Falcon Next-Gen SIEM 10GB.
- Have CrowdStrike clouds available in US-1, US-2, EU-1, US-GOV1, and US-GOV-2.
- Have Admin or Connector Manager access to the Falcon console for the respective CID.
Here's what to do
How to integrate CrowdStrike
- Generate a CrowdStrike token in the NordPass Admin Panel.
- Log in to your CrowdStrike account.
- In the Falcon console, open the left-side panel, click on the "Connectors" button, located at the bottom-left corner, and choose the "Data connectors" option.
- Next, click on the "+ Add connection" button, located on the right.
- Under the "Vendor" filter, search for "Nord Security", select it, and click on the "Apply" button.
- Click on the "Nord Security NordPass Data Connector" option, and select the "Configure" option, located on the right.
- Afterward, enter the connection name and press the "Manage" button.
- Confirm your decision by pressing the "Accept and Continue" button, then select the "Add configuration" button.
- Enter the configuration's name, choose either the "US" or "EU" region based on your organization's data store region, and the URL generated in step 1.
- Copy the API token generated in step 1, enter it, click on the "Save configuration" button, and close the configuration window.
- Then, select the configuration you have just created from the "Data source configuration" dropdown menu.
- In the "Parsing and enrichment" section, the default parser for the connection is already selected, and host enrichment is enabled by default.
- If you need to enable a custom parser, select the "Enable parser selection" checkbox, accept the terms and conditions, and select the needed parser.
- If you don't want to enrich third-party data with hostname entities, click on the "Enable host enrichment" checkbox to deselect the option.
- Review the terms and conditions, select the checkbox to agree, and click on the "Create connection" button.
Note: Once the setup is complete, activity log data will be fetched into CrowdStrike every 5 minutes. With the first connection, NordPass activity logs for the last 7 days will be fetched. After that, only records generated within the script's set interval will be fetched.
How to verify successful data ingestion
- In the Falcon console, open the left-side panel, click on the "Connectors" button, located at the bottom-left corner, and choose the "Data connectors" option.
- In the "Status" column, verify that the data connection status is "Active".
- Next, click on the "Three-dots" button, located to the right of your connection, and select the "Show events" button to see all events related to this data connection in the "Advanced Event Search".
- Afterward, confirm that at least one match is generated between the CrowdStrike and NordPass Activity log.
- If you wish to run a manual search, use this query in the "Advanced Event Search": #Vendor = nordsec | #event.module = "nordpass"
Note: The connector may take up to 10 minutes to become active after initial integration.
How to update the token on the Data connector
- After generating a CrowdStrike token in the NordPass Admin Panel, log in to your CrowdStrike account.
- In the Falcon console, open the left-side panel, click on the "Connectors" button, located at the bottom-left corner, and choose the "Data connectors" option.
- Next, click on the "Three-dots" button, located to the right of your connection, and select the "Edit connection" button.
- Under the "Source Configuration" section, click the "Manage" button, and confirm your decision by pressing the "Accept and Continue" button.
- If you wish to edit the existing token, select the "Edit configuration" button, located on the right side, and you will be able to edit the following information:
- Configuration name
- Region
- API token
- Afterward, click on the "Save configuration" button and close the configuration window.
- Alternatively, if you wish to add a new configuration, click on the "Add configuration" button instead of "Edit configuration".
- Enter the new configuration's name, choose either the "US" or "EU" region based on your organization's data store region, and the newly generated URL. Additionally, copy the newly generated API token, enter it, click on the "Save configuration" button, and close the configuration window.
- Then, select the configuration you have just created from the "Data source configuration" dropdown menu, and click on the "Save changes" button. Select the "Save changes" button once more to confirm your choice.
- If you wish to delete the no longer used configuration, click the "Delete configuration" button next to the "Edit configuration" button. Then, click on the "Confirm deletion" button to verify your choice and close the configuration window.
Additional Tips
- Only one active token is required per CrowdStrike integration.