Note
Access to this page requires authorization. You can try signing in or changing directories.
Access to this page requires authorization. You can try changing directories.
Important
This feature is in Beta. To use it, a workspace admin must turn on Lakeflow Connect for CrowdStrike Falcon Event Stream from the Previews page. See Manage Azure Databricks previews.
The managed CrowdStrike Falcon Event Stream connector in Lakeflow Connect ingests Falcon Event Stream events from CrowdStrike Falcon into Azure Databricks.
Feature availability
| Feature | Availability |
|---|---|
| UI-based pipeline authoring | |
| API-based pipeline authoring | |
| Declarative Automation Bundles | |
| Incremental ingestion | |
| Unity Catalog governance | |
| Orchestration using Databricks Workflows | |
| API-based column selection and deselection | |
| API-based row filtering | |
| SCD Type 2 | |
| Automated schema evolution: New and deleted columns | |
| Automated schema evolution: Data type changes | |
| Automated schema evolution: Column renames | Treated as a new column (new name) and deleted column (old name). |
Authentication methods
| Authentication method | Availability |
|---|---|
| OAuth U2M | |
| OAuth M2M | OAuth 2.0 client credentials from a CrowdStrike Falcon API client. |
| Basic authentication (username/password) | |
| Basic authentication (API key) |
What to know before you start
Note
Before starting, review the Azure Databricks user persona, supported interfaces, ingestion frequency, and common patterns.
Start ingesting from CrowdStrike Falcon
- Configure CrowdStrike Falcon for ingestion (Admins). Set up CrowdStrike Falcon to authenticate with Azure Databricks.
- Create a Unity Catalog connection (Admins). Create a connection in Catalog Explorer so non-admins can create pipelines.
- Create an ingestion pipeline (Admins or non-admins). Select any supported interface and create a pipeline from an existing connection.