Skip to content
nlabadie-crwd edited this page Aug 23, 2024 · 32 revisions

Welcome to the CrowdStrike Query Language community wiki!

CQL Tutorials

  • CQL Primer: a comprehensive guide on using CQL.
  • CQL Building Blocks: this is a list of common questions we've seen in the field. If you've ever wondered how to accomplish X to get to Y, this is likely the place to start.

Specific to Falcon data

Parsing data

  • CrowdStrike Parsing Standard: this document describes the CrowdStrike Parsing Standard, aka CPS. This is the format used for parsers in Next-Gen SIEM.

Everything else

  • Event Forwarding Playground: this is a end-to-end setup of a self-contained single-node cluster, designed to test the Event Forwarding functionality of a self-hosted LogScale deployment.
  • Build a Kubernetes Cluster and LogScale Deployment: this is a lab exercise where you'll build a Kubernetes cluster, deploy LogScale, and optionally enable TLS. Please not that it requires a valid LogScale license.