Integration · SIEM

HailBytes + CrowdStrike Falcon LogScale

Join what the internet can see to what your endpoints already told you.

What you get

  • Native LogScale dispatcher. ASM findings and SAT campaign events post to the Falcon LogScale HTTP ingest API as structured JSON — no middleware, no log-shipper sidecar.
  • The correlation that matters. Externally discovered exposure lands in the same repository as your Falcon endpoint telemetry, which makes the useful query possible: this internet-facing host is also the one carrying an endpoint detection.
  • Severity floor + category toggles. Per-project control over which severities and event categories reach the repository, so ingest volume stays proportionate.
  • Deterministic dedup. Rediscovered findings update in place rather than re-emitting on every scan cycle.

Bring your own LogScale repository and ingest token. The connection runs from your single-tenant HailBytes instance directly to your repository, and ingest usage stays on your existing CrowdStrike subscription.

HailBytes ASM is complementary to Falcon Surface rather than a replacement — if you're evaluating both, the comparison page is candid about where each fits.

SIEM setup guide → API reference → All integrations →