Skip to content

Scope of the Alerts API: EDR or SIEM? #1268

Answered by crowdstrikedcs
antoinemzs asked this question in Q&A
Discussion options

You must be logged in to vote

Hi @antoinemzs thanks for the question!

As you've mentioned, a call to query_alerts_v2 can return IDs generated from various products. One of these is NGSIEM which employs a filter like this filter=product:'ngsiem'

As far as generating these events, my suggestion would be to use a correlation rule to generate some detections from a search. This process is documented here

Once the rules are set up and you see them in the UI under the NGSIEM detections dashboard, the corresponding events will also be in the API for your usage.

Let us know with any questions!

Replies: 2 comments

Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Answer selected by crowdstrikedcs
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
alerts Alerts issues or questions
2 participants