---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Configure

# Get started with the CrowdStrike Falcon Host integration {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

The Integration Configuration feature allows you to quickly activate and set up third-party security integrations, including the CrowdStrike Falcon Host integration. Before you can use the CrowdStrike Falcon Host integration, you must download it from the ServiceNow Store and then add a user name and password.

## Before you begin

* If you are upgrading CrowdStrike Falcon Host integration from a previous version, then you must delete the existing configuration and set up a new configuration. The new integration supports OAUTH2 authentication. This update requires you to enter the API Client ID and the API Client Secret to authenticate and complete the configuration.
* In the CrowdStrike Falcon Host portal API Scopes, enable the Read and Write setting for IOCs (Indicators of Compromise).
{#activate-configure-crowdstrike-host__ul_ol2_cn3_qnb}Role required: sn_si_admin

## Procedure

1. [Download the integration from the ServiceNow Store](https://servicenow-prod.fluidtopics.net/qGeljAXHdNqRLZ7BfdM03w "Downloading an application from the ServiceNow Store for the first time involves a number of easy steps. Some of the steps are performed on the ServiceNow Store and some in your instance.").
2. When the installation is complete, navigate to Security OperationsIntegrationsIntegration Configurations.  
   The available security integrations appear as a series of cards. {#activate-configure-crowdstrike-host__Nav-To}
{#activate-configure-crowdstrike-host__Nav-To}
3. In the CrowdStrike Falcon Host card, click Configure.
4. On the form, fill in the fields to complete the configuration:  
   {#activate-configure-crowdstrike-host__table_ifn_tlk_mnb__entry__2}

   | Field | Description |
   |-|-|
   | Name | Name of the integration, for example, <kbd class="ph userinput">demo-1</kbd>. |
   | API Client ID | The client ID that you obtain from the settings section of your account profile in CrowdStrike Falcon Host portal. |
   | API Client Secret | The client secret key that you obtain from the settings section of your account profile in CrowdStrike Falcon Host portal. |
   [Table 1. CrowdStrike Falcon Host Configuration]

   {#activate-configure-crowdstrike-host__table_ifn_tlk_mnb}
5. Click Submit.
{#activate-configure-crowdstrike-host__steps_gfz_1yn_vw}

## Result

After it is configured, the CrowdStrike Falcon Host integration can be selected for publishing observables to watchlists in Security Incident Response.

*[\>]: and then


