Cyber Security Professional | SOC | IBM QRadar | Carbon Black Response | Falcon CrowdStrike | Threat Hunting
How do people see Firewall logs in Crowdstrike . Is it Possible to view Firewall logs or requires a separated application to pull those into CS console.
I could see every endpoint event like Registry modifications , User Logons, File modifications , Dns Requests but i am looking for a way to get the Firewall logs.
Cybersecurity and Privacy Zealot; Forensics and Incident Response Professional
0
0
You can see firewall changes and rule modifications under the event_SimpleNames "FirewallChangeOption" and "FirewallSetRule". CrowdStrike's Firewall license is for firewall management. If you are looking for failed events due to the endpoint's firewall, you will need to scoop those from the endpoint's log data.
Already have CrowdStrike Falcon Endpoint Protection Platform?
About CrowdStrike Falcon Endpoint Protection Platform
CrowdStrike’s leading cloud-based Falcon platform protects your systems through a single lightweight sensor — there is no on-premises equipment to be maintained, managed or updated, and no need for fr
With over 2.5 million reviews, we can provide the specific details that help you make an informed software buying decision for your business. Finding the right product is important, let us help.