Hello, I have recently switched to using the cloud connection method for CrowdStrike Falcon from the collector method. I’ve noticed that now when I make updates to or close detections from within the Falcon console (the event source isn’t bi-directional, so this is currently necessary) it is causing investigations to open in InsightIDR for that detection.
Looking at the CrowdStrike Falcon detection rules in InsightIDR, I can see that there is no filter in the queries on the “source_json.status” key of the event. From looking through the available keys, this appears to be the only one that could be used to determine that the event shouldn’t trigger an action in InsightIDR, but maybe I am wrong on this?
I see no way of bulk adding an exception to all rules in the CrowdStrike Falcon rule set, which is currently sitting at 1265 rules, and I don’t want to manually add an exception to each rule for obvious reasons.
Is this a known issue others are facing? Does anyone have suggestions for how to address this without reverting back to using the collector method?