CrowdStrike Falcon Event Stream connector

Important

This feature is in Beta. To use it, a workspace admin must turn on Lakeflow Connect for CrowdStrike Falcon Event Stream from the Previews page. See Manage Azure Databricks previews.

The managed CrowdStrike Falcon Event Stream connector in Lakeflow Connect ingests Falcon Event Stream events from CrowdStrike Falcon into Azure Databricks.

Feature availability

Feature Availability
UI-based pipeline authoring Red X icon Not supported
API-based pipeline authoring Green check icon Supported
Declarative Automation Bundles Green check icon Supported
Incremental ingestion Green check icon Supported
Unity Catalog governance Green check icon Supported
Orchestration using Databricks Workflows Green check icon Supported
API-based column selection and deselection Green check icon Supported
API-based row filtering Red X icon Not supported
SCD Type 2 Red X icon Not supported
Automated schema evolution: New and deleted columns Green check icon Supported
Automated schema evolution: Data type changes Red X icon Not supported
Automated schema evolution: Column renames Green check icon Supported
Treated as a new column (new name) and deleted column (old name).

Authentication methods

Authentication method Availability
OAuth U2M Red X icon Not supported
OAuth M2M Green check icon Supported
OAuth 2.0 client credentials from a CrowdStrike Falcon API client.
Basic authentication (username/password) Red X icon Not supported
Basic authentication (API key) Red X icon Not supported

What to know before you start

Start ingesting from CrowdStrike Falcon

  1. Configure CrowdStrike Falcon for ingestion (Admins). Set up CrowdStrike Falcon to authenticate with Azure Databricks.
  2. Create a Unity Catalog connection (Admins). Create a connection in Catalog Explorer so non-admins can create pipelines.
  3. Create an ingestion pipeline (Admins or non-admins). Select any supported interface and create a pipeline from an existing connection.