Crowdstrike is a SaaS (software as a service) system security solution. Deploy this integration to ship Crowdstrike events from your Crowdstrike account to Layerlog using FluentD.

Fluentd will fetch all existing logs, as it is not able to ignore older logs.

Architecture overview

This integration includes:

  • Establishing communication between the Crowdstrike connector and your Crowdstrike account
  • Configuring a FluentD agent on your device
  • Establishing communication between the FluentD agent and your Layerlog account

Crowdstrike integration architecture

Upon deployment, the Crowdstrike connector connects to your Crowdstrike account to collect events. This data is written into a file on your device. The FluentD agent collects the data from this file, connects to your Layerlog account and sends the events to Layerlog.