Skip to main content

CrowdStrikeStreamingPreProcessing

This Script is part of the CrowdStrike Falcon Streaming Pack.#

Adds an entry to duplicate (older) incidents, notifying that a duplicate incident was ignored. Use this script as the pre-processing script for CrowdStrike Streaming. This will not duplicate incidents (detection events) that have the same host.

Permissions#


This automation runs using the default Limited User role, unless you explicitly change the permissions. For more information, see the section about permissions here: https://docs.paloaltonetworks.com/cortex/cortex-xsoar/6-2/cortex-xsoar-admin/playbooks/automations.html

Script Data#


NameDescription
Script Typepython
TagspreProcessing, crowdStrike, crowdStrikeStreaming

Inputs#


There are no inputs for this script.

Outputs#


There are no outputs for this script.