IBM QRadar SOAR

IBM QRadar SOAR

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
  • 1.  CrowdStrike Falcon Integration Fails (MSSP Organization)

    Posted Wed July 10, 2024 02:41 PM

    Hello All,

    We are currently running IBM SOAR on-premises v50.2 with an MSSP organization. Several applications such as VirusTotal and restAPI app are already operational on our APP Host within a child organization.

    I am attempting to install the CrowdStrike APP (IBM Security App Exchange - CrowdStrike Falcon Insight and Threat Intel (ibmcloud.com)) on this child organization. However, I have encountered an issue, details of which are attached (error, app.config, sample of client.log).

    The issue appears to be related to the API key for the message destination of CrowdStrike. I have tried granting full permissions, regenerating the key, and updating the app.config file, but the problem persists. also, I created an API key with full permissions within the configuration organization and assigned this key to the message destination for CrowdStrike, but this approach also did not resolve the issue.

    Thank You



    ------------------------------
    Mohamed Lebda
    ------------------------------

    Attachment(s)

    txt
    app.logs.txt   7 KB 1 version
    txt
    app.config.txt   2 KB 1 version
    log
    client.log   2 KB 1 version


  • 2.  RE: CrowdStrike Falcon Integration Fails (MSSP Organization)

    Posted Thu July 11, 2024 02:00 AM

    Not long ago I had issues with this app too, but the errors I had were different so I'm not sure if I'll be able to help. 

    Did the self tests in app.config pass? And just to make sure, did you try to give the API key only the permissions that are specified in the documentation? 



    ------------------------------
    Maria Czapkowska
    ------------------------------



  • 3.  RE: CrowdStrike Falcon Integration Fails (MSSP Organization)

    Posted Thu July 11, 2024 02:17 AM

    Hi Maria,

    Thanks for your reply, Yes I did try with with only the permissions that are specified in the documentation, but it didn't work, so I tried to give it full access. 

    regarding the self test, I didn't check it, but I have another SOAR Platform "cloud" and this app works fine there, I think the issue might be related to the MSSP and configuration and child organization thing, but I'm not sure why.

    Thanks!



    ------------------------------
    Mohamed Lebda
    ------------------------------



  • 4.  RE: CrowdStrike Falcon Integration Fails (MSSP Organization)

    Posted Thu July 11, 2024 03:25 AM

    I really recommend checking the selftest, at least in my case it was very helpful. I disregarded it at first, but once I checked it I realized where the issue was and managed to solve all the issues.



    ------------------------------
    Maria Czapkowska
    ------------------------------



  • 5.  RE: CrowdStrike Falcon Integration Fails (MSSP Organization)

    Posted Thu July 11, 2024 02:55 AM

    Hello,

    Look at this:

    ERROR: could not connect to SOAR at '****'.
    Reason: Could not subscribe to any message destinations

    Please check your message destination - is there a API Key to Crowdstrike Falcon ?

    for example:

    crowd_strike Queue CrowdStrike Falcon



    ------------------------------
    Przemyslaw Klys
    ------------------------------