How to Forward SentinelOne and CrowdStrike EDR Logs to Your SIEM
SentinelOne and CrowdStrike alerts live in their own console. Forward EDR logs into your SIEM to correlate them with firewall, AD, and cloud activity.
How to Forward SentinelOne and CrowdStrike EDR Logs to Your SIEM
Endpoint detection tools like SentinelOne and CrowdStrike Falcon catch a lot on their own — but their alerts live in a separate console. Without forwarding those logs into your SIEM, you can't correlate an endpoint detection with the firewall, AD, or cloud activity happening at the same time. This guide covers both platforms.
Why forward EDR logs at all?
EDR tools are excellent at catching what happens on the endpoint. What they can't do alone is tell you whether that same user account also triggered an anomalous VPN login, a suspicious AD privilege change, or unusual outbound traffic on the firewall in the same time window. That correlation only happens once EDR events sit in the same place as everything else — your SIEM. (If you're new to the distinction, our Log Management vs SIEM vs SOC explainer covers where each piece fits.)
1. SentinelOne
Via the Management Console (Syslog forwarding):
- Go to Settings → Integrations → Syslog
- Add a new Syslog target: your SIEM's IP, port (default 514, or 6514 for TLS)
- Protocol: choose TCP + TLS if your SIEM supports it — SentinelOne supports encrypted forwarding
- Select event types to forward: at minimum, Threats, Agent Detections, and DFI (Deep File Inspection) events
- Save and check your SIEM's ingestion dashboard for incoming events within a few minutes
Via API (for custom pipelines):
SentinelOne also exposes a REST API (/web/api/v2.1/threats) if you need to pull events on a schedule rather than push via syslog — useful if your SIEM ingests via a collector agent instead of accepting inbound syslog directly.
2. CrowdStrike Falcon
Via Falcon Data Replicator (FDR):
CrowdStrike's primary log export mechanism is FDR, which delivers raw telemetry to an S3 bucket that CrowdStrike hosts, with an SQS queue that announces new files:
- In the Falcon console, go to Support → API Clients and Keys
- Enable Falcon Data Replicator for your CID
- CrowdStrike provisions an S3 bucket + SQS notification queue
- Point your SIEM's cloud log collector at that S3 bucket (most SIEMs support S3-based ingestion)
Via Event Streams API (lower volume, near-real-time):
For teams that don't want to manage an S3 pipeline, the Falcon Streaming API pushes detection and audit events over a persistent HTTPS connection — simpler to set up, but carries less raw telemetry than FDR.
Common mistakes
| # | Problem | Fix |
|---|
| 1 | Only forwarding "Threats," missing lower-severity detections | Also forward Agent Detections / DFI events — low-severity endpoint signals often matter when correlated with other logs |
| 2 | No timestamp normalization between EDR and other log sources | Confirm your SIEM normalizes EDR timestamps to UTC on ingest |
| 3 | Treating EDR alerts as a replacement for SIEM correlation | EDR alerts are one input — the value is correlating them with firewall/AD/cloud logs, not viewing them in isolation |
| 4 | FDR S3 bucket with no lifecycle policy | Set a retention/lifecycle policy on the bucket so raw telemetry doesn't grow unbounded before your SIEM ingests it |
⭐ zcrLog ingests both SentinelOne and CrowdStrike Falcon
zcrLog ingests SentinelOne events directly today and collects CrowdStrike Falcon logs too, correlating EDR events alongside your Firewall, AD, Entra ID, and other logs in one timeline. zcrSIEM, a separate product, also has a CrowdStrike Falcon connector. Pricing starts at ฿4,000/month — see our firewall syslog forwarding guide if you're setting up the other log sources too.
🎯 See zcrLog →
📞 Free consultation
Related product
See zcrLog for the product scope and the inputs to confirm with your delivery partner
Sources
- Netskope — SentinelOne Plugin for Threat Exchange — a third-party integration guide that shows
GET /web/api/v2.1/threats called with an Authorization: ApiToken header
- CrowdStrike — Falcon Data Replicator (FDR) — API reference index (FDR and Event Streams collections)
- CrowdStrike — Falcon Data Replicator: SQS Technical Add-on guide (PDF) — FDR data is retrieved from CrowdStrike-hosted S3 buckets through a CrowdStrike-provided SQS queue
- CrowdStrike — Falcon Event Streams Add-on guide (PDF) — the Streaming API is consumed over a secure persistent connection
- Coralogix — SentinelOne (syslog) — the console path for the syslog steps: Settings, Integrations, SYSLOG, with CEF formatting and TLS options
Read next