CrowdStrike Falcon Event Stream connector reference

Important

This feature is in Beta. To use it, a workspace admin must turn on Lakeflow Connect for CrowdStrike Falcon Event Stream from the Previews page. See Manage Azure Databricks previews.

Reference information for the managed CrowdStrike Falcon Event Stream connector, including the supported source table, the events destination schema, and connector options.

Supported source tables

The CrowdStrike Falcon Event Stream connector supports the following source table, under the default source schema:

Source table Primary key Description Sync mode Cursor field
events lw_id Falcon Event Stream events for your CrowdStrike Falcon tenant. Incremental time

Destination table schemas

events

Primary key: lw_id Cursor field: time

Field Data type
lw_id STRING
time TIMESTAMP
event_data STRING
data VARIANT

Note

  • event_data is deprecated. Use data instead. data contains the same event information as event_data, but uses the VARIANT type for improved query performance.
  • This table does not support SCD type 2 because it has VARIANT columns.

Required CrowdStrike Falcon account permissions

Permission Required for
Falcon administrator Create the OAuth2 API client
Event streams: Read (event_streams read) Discover and consume Event Stream feeds