Documentation Index

Fetch the complete documentation index at: https://docs.redcanary.com/llms.txt

Use this file to discover all available pages before exploring further.

Remove CrowdStrike Falcon from Red Canary

Prev Next

To fully remove a CrowdStrike Falcon integration from Red Canary, you must perform steps in both Red Canary and CrowdStrike.

CrowdStrike Falcon Identity Protection

  • Delete the integration from Red Canary.

  • Delete the corresponding API client in CrowdStrike.

CrowdStrike Falcon EDR

  • Delete the integration from Red Canary.

  • Delete the corresponding API client in CrowdStrike.

  • Delete the FDR feed in CrowdStrike.

  • Wait for Red Canary to remove the backend data service.

Important

Please contact your Customer Success Manager (CSM) to inform them that you would like to remove an integration.

Prerequisites

Before you remove the Crowdstrike Falcon Identity Protection or CrowdStrike Falcon EDR integrations, please make sure the following requirements are met:

  • You have contacted your CSM and informed them that you want to remove your CrowdStrike Falcon integration

  • You have the Administrator role in Red Canary

  • You have the Falcon Administrator role in the CrowdStrike Falcon console

1 Red Canary | Remove the Integration

If you have a CrowdStrike Falcon EDR integration that is associated with an active CrowdStrike Falcon Identity Protection integration, you must remove both integrations using the following steps.

  1. From your Red Canary homepage, go to the Integrations page.

    Integrations menu option highlighted in Red Canary.

  2. Search for and select the CrowdStrike integration you want to remove.
    CrowdStrike integration highlighted in integrations list.

  3. On the Red Canary configuration page, click the action.
    Delete option highlighted on integration page.

  4. Click Save to remove the integration.

2 CrowdStrike Falcon | Revoke API Access

Note

Refer to the CrowdStrike documentation (US-1 US-2, EU-1) for step-by-step instructions on how to remove CrowdStrike Falcon API clients. The Delete an API client steps are found in the Falcon Documentation > CrowdStrike APIs > CrowdStrike APIs - General Info > CrowdStrike OAuth2-Based APIs topic. To view these instructions you'll need to log in with your CrowdStrike account information for the appropriate region.

  1. In your CrowdStrike Falcon console, navigate to the API clients and keys page.

  2. Delete Red Canary’s API client.

3 CrowdStrike Falcon | Remove FDR Feed

Note

Refer to the CrowdStrike documentation (US-1 US-2, EU-1) for step-by-step instructions on how to remove CrowdStrike FDR feeds. The Delete a feed steps are found in the Falcon Documentation > Tools and Reference > Falcon Data Replicator topic. To view these instructions you'll need to log in with your CrowdStrike account information for the appropriate region.

If you are removing a CrowdStrike Falcon EDR integration, you must also remove the FDR feed.

  1. In your CrowdStrike Falcon console, navigate to the Falcon Data Replicator page.

  2. Delete Red Canary’s FDR feed.