Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Install and configure

Install and configure the CrowdStrike Next-Gen SIEM integration for Security Operations application from the ServiceNow Store on your ServiceNow AI Platform instance.

Before you begin

Role required: sn_si.ingestion_profile_admin

Minimum scopes needed to configure CrowdStrike Next-Gen SIEM in ServiceNow® instance include:

ActionScope Needed
Fetch DetectionsAlerts- Read
Update Comments/StateAlerts- Write
Create Search Query JobNGSIEM- Write
Fetch Search Query JobNGSIEM- Read
Fetch Correlation RulesCorrelation Rules- Read

Procedure

  1. Download the CrowdStrike Next-Gen SIEM integration from the ServiceNow Store and install it.

    For more information, see Download an application from the ServiceNow Store for the first time

  2. Navigate to Security Operations > Integrations > Integration Configurations.

  3. Search for the CrowdStrike Next-Gen SIEM integration tile, and select Configure.

  4. On the form, fill in the fields.

FieldDescription
NameName of the CrowdStrike Next-Gen SIEM integration.
Client IDThe client ID that you obtain from the settings section of your account profile in the CrowdStrike portal.
Client SecretThe client secret key that you obtain from the settings section of your account profile in the CrowdStrike portal.
RegionData center to pull data from. Specify the Region: US-1, US-2, EU-1, US-GOV-1, US-GOV-2By default, the field is set to US-1
  1. Select Submit.

    The configured integration tile displays.

What to do next

Create a detection profile