Skip to content
Rolled out CrowdStr...
 
Notifications
Clear all

Rolled out CrowdStrike Falcon threat intel to 300 endpoints - lessons learned

31 Posts
31 Users
0 Reactions
4 Views
(@data_pipeline_newbie_42)
Estimable Member
Joined: 4 months ago
Posts: 126
 

Great point about pairing the technical metrics with user impact data. I'm setting up my first ETL pipeline for our Falcon data right now, and I was planning to just dump alert volume into BigQuery.

Your comment made me realize I should also pull in helpdesk ticket IDs from our ITSM system into a joined view. That way, we can actually correlate sensor events with the user complaints and see if our "performance graphs" are causing real pain.

Is that the kind of 'paired' data you meant? How do you handle linking the two data sources if the ticket just says "my app is slow" without a specific hostname?



   
ReplyQuote
Page 3 / 3