Create an CrowdStrike Falcon Event Stream connection

Important

This feature is in Beta. To use it, a workspace admin must turn on Lakeflow Connect for CrowdStrike Falcon Event Stream from the Previews page. See Manage Azure Databricks previews.

Create an CrowdStrike Falcon Event Stream connection in Catalog Explorer to store authentication credentials for Lakeflow Connect ingestion. Any user with the USE CONNECTION privilege on the connection can then create CrowdStrike Falcon Event Stream ingestion pipelines without needing direct access to the credentials.

For privilege requirements, see Connect to managed ingestion sources.

Prerequisites

Complete the source setup. Use the credentials retrieved there to create the connection.

Create a connection

  1. In the Azure Databricks workspace, click Data icon. Catalog > Create > Create a connection.
  2. On the Connection basics page of the Set up connection wizard, specify a Connection name.
  3. In the Connection type drop-down menu, select CrowdStrike Falcon Event Stream.
  4. (Optional) Add a comment.
  5. Click Next.
  6. On the Authentication page, enter the following credentials from Configure authentication to CrowdStrike Falcon:
    • Client ID: The client ID of your CrowdStrike Falcon OAuth2 API client.
    • Client Secret: The client secret of your CrowdStrike Falcon OAuth2 API client.
    • Base URL: The API URL for your Falcon cloud, with the https:// scheme and no path. For example, https://api.crowdstrike.com or https://api.us-2.crowdstrike.com.
    • Client app name: Required to create the connection. Databricks generates the Event Stream application ID and doesn't use this value to identify the stream.
  7. Click Create connection.

Next steps

Create an ingestion pipeline.