• Detections

    The CrowdStrike SIEM Connector Detections dashboard provides comprehensive visibility into security detections and alerts from CrowdStrike Falcon through a series of interconnected visualizations. This dashboard enables monitoring, analysis, and response to potential threats in the environment.

  • Firewall Activity

    The CrowdStrike SIEM Connector Firewall Activity dashboard provides real-time visibility into network traffic patterns, security policy enforcement, and potential threats detected at the firewall level. This dashboard facilitates monitoring and analysis of network traffic behavior and security events across the environment.

  • Summary Dashboard

    The CrowdStrike SIEM Connector Summary dashboard serves as a high-level overview of security events, system health, and key metrics across the environment. This dashboard delivers a consolidated view of security posture and critical operational indicators.

  • User Activity

    The CrowdStrike SIEM Connector User Activity dashboard provides comprehensive visibility into user behavior, authentication events, and account-related activities across the environment. This dashboard facilitates monitoring of user actions, detection of suspicious behavior patterns, and tracking of authentication anomalies.

Detections

The CrowdStrike SIEM Connector Detections dashboard provides comprehensive visibility into security detections and alerts from CrowdStrike Falcon through a series of interconnected visualizations. This dashboard enables monitoring, analysis, and response to potential threats in the environment.

Example of a detections dashboard
WidgetDescriptionType
Detection Types Displays a pie chart of detection types.

Hide Query

Show Query

Explain Query

Pie Chart
Detections Displays a table of event detections and associated data (timestamp, sensor ID, ComputerName, User,Severity, Local IP, etc.)

Hide Query

Show Query

Explain Query

Table
Techniques over Time Displays a chart of detected event techniques over a 1 hour timespan.

Hide Query

Show Query

Explain Query

Time Chart
Detection Events Displays a summary of detection events by computer name and customer IDS string.

Hide Query

Show Query

Explain Query

Gauge
Detections by Technique Displays a chart of detections by technique.

Hide Query

Show Query

Explain Query

Bar Chart
Detection by Tactic Displays a chart of event detections by tactic.

Hide Query

Show Query

Explain Query

Bar Chart
Tactic over Time Displays a chart of event tactics over a 1 hour timespan by computer name and customer IDS string.

Hide Query

Show Query

Explain Query

Time Chart
Tactics Displays a pie chart of top event tactics.

Hide Query

Show Query

Explain Query

Pie Chart
Events by eventtype Displays a chart of events by event type using metadata.

Hide Query

Show Query

Explain Query

Bar Chart
Events over time Displays a list of events over time

Hide Query

Show Query

Explain Query

Time Chart
Firewall Activity

The CrowdStrike SIEM Connector Firewall Activity dashboard provides real-time visibility into network traffic patterns, security policy enforcement, and potential threats detected at the firewall level. This dashboard facilitates monitoring and analysis of network traffic behavior and security events across the environment.

Example of a firewall activity dashboard
WidgetDescriptionType
Firewall Events Displays a table of firewall events and associated data (host name, device ID, event type, event policy name, etc.)

Hide Query

Show Query

Explain Query

Table
Outbound Blocked Requests Displays a flowchart of outbound blocked requests using firewall data from local address to remote address.

Hide Query

Show Query

Explain Query

Sankey
Blocked Requests - Outbound Displays a list of outbound blocked requests.

Hide Query

Show Query

Explain Query

Gauge
Events by eventtype Displays a chart of events by event type using metadata.

Hide Query

Show Query

Explain Query

Bar Chart
Blocked Requests - Inbound Displays a list of blocked inbound access requests using metadata.

Hide Query

Show Query

Explain Query

Gauge
FIrewall Activity - Total events Displays a list of total firewall event activities.

Hide Query

Show Query

Explain Query

Gauge
Events over time Displays a list of events over time

Hide Query

Show Query

Explain Query

Time Chart
Inbound Blocked Requests Displays a flowchart of inbound blocked requests from remote address to local address.

Hide Query

Show Query

Explain Query

Sankey
Summary Dashboard

The CrowdStrike SIEM Connector Summary dashboard serves as a high-level overview of security events, system health, and key metrics across the environment. This dashboard delivers a consolidated view of security posture and critical operational indicators.

Example of a summary dashboard
WidgetDescriptionType
Policy events Displays a list policy events and associated data.

Hide Query

Show Query

Explain Query

Gauge
Detections Displays a table of event detections and associated data (timestamp, sensor ID, ComputerName, User,Severity, Local IP, etc.)

Hide Query

Show Query

Explain Query

Table
Policty events by Users Displays aggregated, policy-related events by user using metadata.

Hide Query

Show Query

Explain Query

Pie Chart
Techniques over Time Displays a chart of detected event techniques over a 1 hour timespan.

Hide Query

Show Query

Explain Query

Time Chart
Detection Events Displays a summary of detection events by computer name and customer IDS string.

Hide Query

Show Query

Explain Query

Gauge
Firewall Events Displays a table of firewall events and associated data (host name, device ID, event type, event policy name, etc.)

Hide Query

Show Query

Explain Query

Table
Outbound Blocked Requests Displays a flowchart of outbound blocked requests using firewall data from local address to remote address.

Hide Query

Show Query

Explain Query

Sankey
Blocked Requests - Outbound Displays a list of outbound blocked requests.

Hide Query

Show Query

Explain Query

Gauge
Detections by Technique Displays a chart of detections by technique.

Hide Query

Show Query

Explain Query

Bar Chart
Detection by Tactic Displays a chart of event detections by tactic.

Hide Query

Show Query

Explain Query

Bar Chart
Tactic over Time Displays a chart of event tactics over a 1 hour timespan by computer name and customer IDS string.

Hide Query

Show Query

Explain Query

Time Chart
User Activity by ServiceName Displays a chart of user activity by username.

Hide Query

Show Query

Explain Query

Bar Chart
Policy events types Displays a pie chart of policy events by type using audit data.

Hide Query

Show Query

Explain Query

Pie Chart
Tactics Displays a pie chart of top event tactics.

Hide Query

Show Query

Explain Query

Pie Chart
Events by eventtype Displays a chart of events by event type using metadata.

Hide Query

Show Query

Explain Query

Bar Chart
User Activity Events Displays user activity events using customer IDS string.

Hide Query

Show Query

Explain Query

Gauge
User Activity Events Displays a table of user activity events and associated data (customer ID, user ID, service, operation).

Hide Query

Show Query

Explain Query

Table
Blocked Requests - Inbound Displays a list of blocked inbound access requests using metadata.

Hide Query

Show Query

Explain Query

Gauge
Identity Protection Events Displays a list of identity protection events.

Hide Query

Show Query

Explain Query

Gauge
Events over time Displays a list of events over time

Hide Query

Show Query

Explain Query

Time Chart
Inbound Blocked Requests Displays a flowchart of inbound blocked requests from remote address to local address.

Hide Query

Show Query

Explain Query

Sankey
User Activity

The CrowdStrike SIEM Connector User Activity dashboard provides comprehensive visibility into user behavior, authentication events, and account-related activities across the environment. This dashboard facilitates monitoring of user actions, detection of suspicious behavior patterns, and tracking of authentication anomalies.

Example of a user activity dashboard
WidgetDescriptionType
Policy events Displays a list policy events and associated data.

Hide Query

Show Query

Explain Query

Gauge
Policty events by Users Displays aggregated, policy-related events by user using metadata.

Hide Query

Show Query

Explain Query

Pie Chart
User Activity by ServiceName Displays a chart of user activity by username.

Hide Query

Show Query

Explain Query

Bar Chart
Policy events types Displays a pie chart of policy events by type using audit data.

Hide Query

Show Query

Explain Query

Pie Chart
Events by eventtype Displays a chart of events by event type using metadata.

Hide Query

Show Query

Explain Query

Bar Chart
Activity by Operations Displays a pie chart of user activity by operation name.

Hide Query

Show Query

Explain Query

Pie Chart
User Activity Events Displays user activity events using customer IDS string.

Hide Query

Show Query

Explain Query

Gauge
User Activity Events Displays a table of user activity events and associated data (customer ID, user ID, service, operation).

Hide Query

Show Query

Explain Query

Table
Events over time Displays a list of events over time

Hide Query

Show Query

Explain Query

Time Chart