Skip to content

Learn how to use the Foundry CLI to create a Foundry app that enriches Falcon incidents with third-party data. This app adds third-party data on the Next-Gen SIEM incident details page of the Falcon console.

License

Notifications You must be signed in to change notification settings

CrowdStrike/foundry-tutorial-enrich-incidents

Repository files navigation

CrowdStrike CrowdStrike

CrowdStrike Subreddit

Enrich Incidents tutorial Foundry app

Important

To view this tutorial and import the app, you need access to the Falcon console.

This code is the result of doing the Falcon Foundry Create an App that Enriches Falcon Incidents tutorial.

Prerequisites

  • Falcon Insight XDR or Falcon Prevent (one app)
  • Falcon Next-Gen SIEM or Falcon Foundry (1+ apps depending on entitlement)

Getting Started

  1. Download this repository as a zip file.
  2. Log in to the Falcon console and go to Foundry > App manager.
  3. Click Import app and select the zip file you downloaded.
  4. Click Import.

Tip

If you get an error that the name already exists, change the name to something unique to your CID when importing the app.

Links

This example uses the following CrowdStrike products:

Help

Please post any questions as issues in this repo, ask for help in our CrowdStrike subreddit, or post your question to our Foundry Developer Community.

Support

The foundry-tutorial-enrich-incidents repo is the resulting code from doing the Foundry Create an App that Enriches Falcon Incidents tutorial. While not a formal CrowdStrike product, foundry-tutorial-enrich-incidents is maintained by CrowdStrike and supported in partnership with the open source developer community.

License

MIT, see LICENSE.

About

Learn how to use the Foundry CLI to create a Foundry app that enriches Falcon incidents with third-party data. This app adds third-party data on the Next-Gen SIEM incident details page of the Falcon console.

Topics

Resources

License

Code of conduct

Security policy

Stars

Watchers

Forks