Integrating with CrowdStrike
-
- UpdatedJan 30, 2025
- 6 minutes to read
- Yokohama
- IT Asset Management
Integrating your Software Asset Management application with the CrowdStrike enables you to view CrowdStrike active host sensors information and check license compliance.
Process | Required user role in the CrowdStrike application | Authentication scopes |
---|---|---|
Download consumption | Falcon administrator | Sensor usage scope with read permissions |
This process is applicable for Yokohama Patch 1, Software Asset Management - SaaS License Management (sn_sam_saas_int) 15.0.8, and Software Asset Management (sn_itam_samp) 2.1.0 version onwards. If you are on any version for Yokohama below Patch 1, refer KB1801232.
Register a CrowdStrike OAuth application
Register the CrowdStrike OAuth application to access the CrowdStrike API and to receive a Client ID and Client secret.
Before you begin
The CrowdStrike Integration Hub spoke must be active. For more information, see CrowdStrike spoke.
CrowdStrike Role required: Falcon administrator
- To use the Sensor Usage APIs, your API client must be assigned the Sensor usage scope with Read permissions.
- Contact your account team to enable the following feature flags:
- Hourly usage data feature flag: This flag must be enabled for your Customer Identification (CID) to view hourly usage data.
- Aggregated usage data feature flag: This flag must be enabled to get aggregated usage data in multi-CID (non-Flight Control) accounts.
Procedure
Create a CrowdStrike connection
Create a connection between your CrowdStrike applications and your ServiceNow instance so that your instance can retrieve user data from your applications.
Before you begin
ServiceNow Role required: admin
Procedure
Create a CrowdStrike integration profile
Create a CrowdStrike integration profile to track software subscriptions and optimize licensing for your CrowdStrike applications.
Before you begin
The Software Asset Management - SaaS License Management plugin (sn_sam_saas_int) must be installed from the ServiceNow Store.
ServiceNow Role required: admin or sam_integrator
About this task
If you are using Software Asset Workspace, the option to create the CrowdStrike integration profile in Core UI is inactive.
- If any existing CrowdStrike profiles are in the Draft state, create new integration profiles and delete the existing ones.
- If any existing CrowdStrike profiles are in the Published state, their state changes to Draft.
If you are on any version for Yokohama below Patch 1, refer KB1801232.
Procedure
Result
This integration pulls or creates usage records in the CrowdStrike Product Usage [samp_crowdstrike_product_usage] table and CAL records in the Client Access [samp_sw_client_access] table.
What to do next
If you want to set up multiple integration profiles with unique connections, create child aliases to manage different configurations and settings for each integration profile. For more information, see Create a child alias to set up multiple integration profiles.
- For more information on creating software entitlements in the Software Asset Management classic application, see Create entitlements in Software Asset Management classic.
- For more information on creating software entitlements in the Software Asset Workspace, see Create entitlements in workspace.
- For more information on creating software entitlements using the Software Asset Management Playbook, see Create entitlements using the guided walk-through.
- For more information on running reconciliation in the Software Asset Management classic application, see Run software reconciliation in Software Asset Management classic.
- For more information on running reconciliation in the Software Asset Workspace, see Run software reconciliation in the workspace.