To fully remove a CrowdStrike Falcon integration from Red Canary, you must perform steps in both Red Canary and CrowdStrike.
CrowdStrike Falcon Identity Protection
Delete the integration from Red Canary.
Delete the corresponding API client in CrowdStrike.
CrowdStrike Falcon EDR
Delete the integration from Red Canary.
Delete the corresponding API client in CrowdStrike.
Delete the FDR feed in CrowdStrike.
Wait for Red Canary to remove the backend data service.
Important
Please contact your Customer Success Manager (CSM) to inform them that you would like to remove an integration.
Prerequisites
Before you remove the Crowdstrike Falcon Identity Protection or CrowdStrike Falcon EDR integrations, please make sure the following requirements are met:
You have contacted your CSM and informed them that you want to remove your CrowdStrike Falcon integration
You have the Administrator role in Red Canary
You have the Falcon Administrator role in the CrowdStrike Falcon console
1 Red Canary | Remove the Integration
If you have a CrowdStrike Falcon EDR integration that is associated with an active CrowdStrike Falcon Identity Protection integration, you must remove both integrations using the following steps.
From your Red Canary homepage, go to the Integrations page.

Search for and select the CrowdStrike integration you want to remove.
On the Red Canary configuration page, click the
action. 
Click Save to remove the integration.
2 CrowdStrike Falcon | Revoke API Access
Note
Refer to the CrowdStrike documentation (US-1 US-2, EU-1) for step-by-step instructions on how to remove CrowdStrike Falcon API clients. The Delete an API client steps are found in the Falcon Documentation > CrowdStrike APIs > CrowdStrike APIs - General Info > CrowdStrike OAuth2-Based APIs topic. To view these instructions you'll need to log in with your CrowdStrike account information for the appropriate region.
In your CrowdStrike Falcon console, navigate to the API clients and keys page.
Delete Red Canary’s API client.
3 CrowdStrike Falcon | Remove FDR Feed
Note
Refer to the CrowdStrike documentation (US-1 US-2, EU-1) for step-by-step instructions on how to remove CrowdStrike FDR feeds. The Delete a feed steps are found in the Falcon Documentation > Tools and Reference > Falcon Data Replicator topic. To view these instructions you'll need to log in with your CrowdStrike account information for the appropriate region.
If you are removing a CrowdStrike Falcon EDR integration, you must also remove the FDR feed.
In your CrowdStrike Falcon console, navigate to the Falcon Data Replicator page.
Delete Red Canary’s FDR feed.