Skip to content

docs: add CrowdStrike Falcon (Cloud / Event Streams) adapter page#256

Draft
maximelb wants to merge 1 commit into
masterfrom
docs/adapter-falconcloud
Draft

docs: add CrowdStrike Falcon (Cloud / Event Streams) adapter page#256
maximelb wants to merge 1 commit into
masterfrom
docs/adapter-falconcloud

Conversation

@maximelb
Copy link
Copy Markdown
Contributor

@maximelb maximelb commented Jun 5, 2026

Documents the falconcloud USP adapter under Sensors → Adapters → Security Tools, following the existing adapter page pattern.

What's covered

  • Adapter Type falconcloud, consuming the CrowdStrike Falcon Streaming API (Event Streams).
  • A callout distinguishing it from the on-host crowdstrike EDR sensor adapter (it was split off precisely to avoid that collision).
  • OAuth2 API-client auth with the Event streams: Read scope.
  • The is_using_offset/offset vs not_before resume modes and the write_timeout_sec default (600).
  • The one-consumer-per-stream constraint (run a single instance per Falcon tenant).
  • IaC example with hive:// secret references; recommends the dedicated falconcloud platform.

Config fields and behavior verified against usp-adapters/falconcloud/client.go.

Draft — markdownlint-cli2 passes clean.

🤖 Generated with Claude Code

Documents the falconcloud USP adapter (Sensors → Adapters → Security
Tools): consumes the CrowdStrike Falcon Streaming API (Event Streams).
Distinguishes it from the on-host crowdstrike EDR adapter, covers the
OAuth2 API-client auth and Event streams: Read scope, the offset vs
not_before resume modes, and the single-consumer-per-stream constraint.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant