elastic / elastic/docs-content

[Website]: Falcon Intelligence Integration documentation

Open
#6,341 2 comments 0 reactions 0 assignees View on GitHub
community good-for-ai source:web Team:Ingest
Dominant language
No language data
Stars
47
Forks
261
Avg merge
3d 12h
Merged PRs (30d)
116

Description

### Before you submit

- [x] This issue is about a documentation page, flow, or piece of content.

### Type of issue

Inaccurate

### What documentation page or section is affected

https://www.elastic.co/docs/reference/integrations/ti_crowdstrike

### What happened?

After setting up the integration, it looks like the required scopes/permissions suggested in the documentation are now outdated. After speaking to CrowdStrike support they have provided the following:

Regarding /intel/combined/indicators/v1

The scope `Indicators (Falcon Intelligence):read` must be enabled in order to interact with the API.

Regarding /iocs/combined/indicator/v1

The scope `IOC Management:read` must be enabled to interact with the API

### Additional info

_No response_

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.