How to Integrate Dell Trusted Device Data into CrowdStrike Next-Gen SIEM

Summary: Learn how Dell Trusted Device’s telemetry enhances CrowdStrike Next-Gen SIEM, empowering IT professionals to detect and respond to advanced threats with a comprehensive view of device health and security. ...

This article applies to This article does not apply to This article is not tied to any specific product. Not all product versions are identified in this article.

Instructions

Affected Products:

  • Dell Trusted Device
  • CrowdStrike

Dell Trusted Device collects telemetry data from below the operating system, providing valuable insights for various actionable tasks. By uploading this telemetry to CrowdStrike Next-Gen SIEM, IT professionals can enhance their ability to detect and respond to advanced threats. This integration offers a comprehensive view of device health and security, enabling more effective monitoring and incident response. The following sections guide you through the complete setup process, which should be followed in the order presented.

Table of Contents

Prerequisites

  • CrowdStrike Falcon Next-Gen SIEM

Back to Top

Confirm Dell Trusted Device Installation

Dell Trusted Device must be installed and generating telemetry. These articles help you download and install Dell Trusted Device if needed.

Back to Top

Log in to CrowdStrike Falcon

  1. In a Google Chrome or Microsoft Edge browser, go to your Falcon console login URL.
  2. Log In to the Falcon Console.
    Log In to the Falcon Console

Back to Top

Configure and activate the HEC/HTTP data connector in CrowdStrike

  1. In the left menu pane, Click Next-Gen SIEM and then select Data onboarding.
    Click Next-Gen SIEM and then select Data onboarding
  2. In the Connections section, click + Add connection.
    Click + Add connection
  3. Click Filter by connector name and enter HEC/HTTP Event Connector, then click Apply.
    Click Filter by connector name and enter HEC/HTTP Event Connector
    Note: Alternatively, you can browse all connectors and locate HEC/HTTP manually.
  4. Click HEC/HTTP Event Connector.
    Click HEC/HTTP Event Connector
  5. On the New connection pane, click Configure.
    Click Configure
  6. On the Add new connector page enter the information below, click the checkbox to accept the Terms and Conditions, and click Create connection.
    • Data Source: Customer Created
    • Connector Name: Customer Created
    • Description (Optional): Customer Created
    • Parsers: dell-trusteddevice (Dell Trusted Device)
    Click Create connection
  7. On the Connector setup in progress dialog, click Close.
    Click Close
  8. Click Data connections on the upper left.
    Click Data connections
    Note: Alternatively, you can repeat Step 3 to return to the same area.
  9. On the Data Onboarding page, locate the data connection created in Configure and activate the HEC/HTTP data connector in CrowdStrike (Step 6 from above), and select the Connection name.
    Select the Connection name
  10. Click Generate API key to generate a new API key.
    Click Generate API key
    Note: The API key is only displayed once. Copy it and store it safely for use in a future step.
  11. Once you have your API key documented, click Close.
    Click Close
    Note: If you must regenerate the API key, you can repeat Step 11 and use the Regenerate API Key button from the upper right.
    Regenerate API Key button

Back to Top

Configure the data shipper

  1. In the left menu pane, Click Next-Gen SIEM and then select Data onboarding.
    Select Data onboarding
  2. From the Data onboarding page, click Fleet management.
    Click Fleet management
  3. From the Fleet management page, click Config overview.
    Click Config overview
  4. On the Config overview page, click + New config
    Click + New config
  5. In the New Config dialog, enter a Name, select Empty config, then click Create new.
    Click Create new
  6. In the Draft editor, enter the information below. For the Token and URL values, refer to Configure and activate the HEC/HTTP data connector in CrowdStrike (Step 13).
    //unformattedcode
    Example config using default listening port 514
     
    sources:
      windowsEvents:
        type: wineventlog
        sink: logscaleSink
        channels:
          - name: "Dell Trusted Device"
          - name: Dell
    sinks:
      ngsiem:
        type: hec
        proxy: none
        token: <API_key_generated_during_data_connector_setup>
        url: <API_URL_generated_during_data_connector_setup>
    //unformattedcode
    
  7. Once you have the information entered from Step 6 click Save, and then click Publish.
    Click Publish
  8. From Fleet management, click Enrollment tokens.
    Click Enrollment tokens
  9. Click + New token.
    Click + New token
  10. On the new Enrollment token dialog provide a token name, using the assigned config picklist select the configuration name from Step 5, then click Create token.
    Click Create token

Back to Top

Installing the LogScale Collector

  1. In the left menu pane, Click Next-Gen SIEM and then select Data onboarding.
    Select Data onboarding
  2. From the Data onboarding page, click Fleet management.
    Click Fleet management
  3. Click Get LogScale Collector.
    Click Get LogScale Collector
  4. On the Get Falcon LogScale Collector dialog click Windows, in the Select an enrollment token picklist pick the token created during Configure the data shipper (Step 10), then click the Copy button.
    Click the Copy button
  5. In Windows Right the Start Button and select Terminal (Admin).
    Select Terminal (Admin)
    Note: Click Yes if prompted for Windows User Account Control.
  6. In the Terminal window paste the command copied from Configure the data shipper (step 6) and press Enter.
    Paste the command copied from Configure the data shipper (step 6) and press Enter
  7. Once the command successfully completes, you see a "Bootstrap complete" message like below.
    Once the command successfully completes, you see a "Bootstrap complete" message

Back to Top

Affected Products

CrowdStrike, Dell Trusted Device
Article Properties
Article Number: 000368563
Article Type: How To
Last Modified: 12 Sep 2025
Version:  1
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.