Note
Access to this page requires authorization. You can try signing in or changing directories.
Access to this page requires authorization. You can try changing directories.
Important
This feature is in Beta. To use it, a workspace admin must turn on Lakeflow Connect for CrowdStrike Falcon Event Stream from the Previews page. See Manage Azure Databricks previews.
Reference information for the managed CrowdStrike Falcon Event Stream connector, including the supported source table, the events destination schema, and connector options.
Supported source tables
The CrowdStrike Falcon Event Stream connector supports the following source table, under the default source schema:
| Source table | Primary key | Description | Sync mode | Cursor field |
|---|---|---|---|---|
events |
lw_id |
Falcon Event Stream events for your CrowdStrike Falcon tenant. | Incremental | time |
Destination table schemas
events
Primary key: lw_id
Cursor field: time
| Field | Data type |
|---|---|
lw_id |
STRING |
time |
TIMESTAMP |
event_data |
STRING |
data |
VARIANT |
Note
event_datais deprecated. Usedatainstead.datacontains the same event information asevent_data, but uses theVARIANTtype for improved query performance.- This table does not support SCD type 2 because it has VARIANT columns.
Required CrowdStrike Falcon account permissions
| Permission | Required for |
|---|---|
| Falcon administrator | Create the OAuth2 API client |
Event streams: Read (event_streams read) |
Discover and consume Event Stream feeds |