We use Crowdstrike and we are interested in getting the EDR Data out of Crowdstrike into QRadar. The existing QRadar apps and DSM only pull out DETECTIONS and nothing else.
the Falcon Data Replicator is essentially all the data in JSON format put into an AWS S3 bucket with an SQS queue. We have QRoC and everyone seems to be gawking at performing this integration.
This seems to be yet another instance were there are clear and easy routes to integrate with Splunk but I'm struggling to get it to work with QRadar.
Anyone have any thoughts or insight?
#QRadar#Support#SupportMigration