CrowdStrike Next-Gen SIEM
Support Statement
This documentation is provided "as is" without support for 3rd party software. The level of support for this integration guide is best effort without any SLA on response time. No 3rd party product support can be provided by Superna directly. 3rd party components require support contracts. See EULA for more details.
Overview
Superna Data Security Edition integrates with CrowdStrike Next-Gen SIEM to stream security findings from the storage layer directly into the Falcon platform for search, correlation, and alerting. When Superna detects malicious activity - it automatically forwards those findings to CrowdStrike Next-Gen SIEM via the Collector API, where they appear as searchable log events and detections alongside other security telemetry.
For ransomware detection, all required indicators are preconfigured by Superna and do not need to be recreated in the SIEM. Each payload contains the necessary details for the SecOps team to assess the event, conduct investigations, or build correlation rules with detections from other security systems.
Demo Video
Features and Solution Overview
This integration provides the following capabilities:
- Structured log ingestion — Superna findings are forwarded to CrowdStrike Next-Gen SIEM via the Collector API, mapped to CrowdStrike Parsing Standard (CPS) format for native compatibility.
- Detections visibility — high-confidence findings surface as detections in the CrowdStrike Falcon console for SOC review and triage.
- Rich incident context — each webhook payload includes the actor username, client IP addresses, affected SMB shares, file paths, severity, and detection state so the SOC can immediately assess scope.
Customer Workflow Benefits
- Correlate Superna's storage-layer detections with endpoint, identity, and network signals already in Next-Gen SIEM.
- Reduce mean time to detect and respond (MTTD/MTTR) by centralizing storage security findings in a single pane of glass.
- Build saved searches, alerts, and correlation rules in Next-Gen SIEM based on Superna event fields.
Limitations
- Requires a CrowdStrike Next-Gen SIEM subscription with Data Onboarding entitlement.
- The integration runs as a service on the Superna (Eyeglass) VM and requires direct outbound HTTPS connectivity from the VM to CrowdStrike. HTTPS proxy routing is not supported.
- Upgrade and rollback functionality is not available.
About CrowdStrike Next Gen SIEM
CrowdStrike Falcon Next-Gen SIEM revolutionizes threat detection, investigation, and response by bringing together unmatched security depth and breadth in one unified platform. It combines log ingestion, search, correlation, and detection capabilities natively within the Falcon platform, eliminating the need for separate SIEM infrastructure. The Superna data source is available directly within the Next-Gen SIEM Data Onboarding tab via the CrowdStrike Marketplace.