Step-by-step guide to integrate Qevlar AI with CrowdStrike Falcon EDR using OAuth2 API credentials.
Connect CrowdStrike Falcon to Qevlar AI to stream endpoint telemetry and detections directly into your investigations workspace.
info
You will create one CrowdStrike API client and reuse the same credentials for both the Data Source (raw events) and Alert Source (detections) connectors.
Prerequisites
- CrowdStrike Falcon role that can Create API clients and keys
- Qevlar AI tenant Admin permissions
- Outbound HTTPS access from Qevlar AI to
https://api.crowdstrike.com(or the regional URL returned in your credentials)
1. Create an API client in CrowdStrike Falcon
- In the Falcon console open ☰ Support and resources -> API clients and keys.

- Click Create API client.

Complete the form:
Field Value Client name Qevlar AIDescription Qevlar AI integration keyScopes Permissions Alerts READHosts READThreatgraph READ

- Select Create.
Copy the Client ID, Secret and Base URL shown once.
warningStore the secret in a password-manager, it cannot be retrieved later.
- Confirm the new client appears in the list.

2. Add CrowdStrike as a Data Source in Qevlar AI
- In Qevlar AI open Integrations.

- Locate CrowdStrike and click +.
- In the dialog paste the Client ID, Secret, and Base URL you copied earlier.

- Choose the datasets you wish to ingest.
- Click Save, Qevlar AI validates the key and starts the first sync.