From fca811a9db4da75948695b41f95781528a994be2 Mon Sep 17 00:00:00 2001 From: Cody Maffucci <46459665+Maffooch@users.noreply.github.com> Date: Mon, 28 Sep 2026 19:43:06 -0500 Subject: [PATCH] docs(crowdstrike): say which CID the Falcon API client must be created in Under Falcon Flight Control, an API client created in the parent CID may not list the hosts that belong to child CIDs, which leaves a connector that authenticates but sees no hosts. Tell users to create the client in the CID that holds the hosts, and say what saving the connector reports, matching the new CrowdStrike visibility hint. Co-Authored-By: Claude Opus 5.5 --- docs/content/connectors/toolreference/crowdstrike_falcon.md | 2 ++ 1 file changed, 2 insertions(+) diff --git a/docs/content/connectors/toolreference/crowdstrike_falcon.md b/docs/content/connectors/toolreference/crowdstrike_falcon.md index 196e2e5a7d3..7841be79292 100644 --- a/docs/content/connectors/toolreference/crowdstrike_falcon.md +++ b/docs/content/connectors/toolreference/crowdstrike_falcon.md @@ -10,6 +10,8 @@ The CrowdStrike Falcon connector imports **Spotlight vulnerabilities** and **EDR A Falcon **API client** (Client ID and secret), created in the Falcon console under **Support \> API Clients and Keys**. Grant it the scopes for the data you want to import: **Hosts: Read** (required, for host discovery), **Vulnerabilities (Spotlight): Read** (for Spotlight findings), and **Alerts: Read** (for EDR detections). The two finding types are independent — if the client lacks a scope, that finding type is skipped rather than failing the sync, so a client without **Alerts: Read** still imports Spotlight vulnerabilities. +Create the API client in the CID that holds the hosts you want to import. If you use Falcon Flight Control, create it in the child CID the hosts belong to rather than in the parent CID. When you save the connector, DefectDojo reports how many hosts the client can see, and a client whose CID has no hosts is saved with a No Data Visible warning. + #### Connector Mappings 1. Enter your Falcon cloud's API base URL in the **Location** field, matching your console region — for example `https://api.crowdstrike.com` (US\-1), `https://api.us-2.crowdstrike.com` (US\-2), `https://api.eu-1.crowdstrike.com` (EU\-1), or `https://api.laggar.gcw.crowdstrike.com` (US\-GOV\-1).