Listing Thumbnail

    CRWD Falcon NGSIEM Management and Tuning Support

     Info
    10 hour block of Crowdstrike Flacon NG SIEM support. Including: Source Onboarding, log management, Detection engineering.

    Overview

    This offering provides a flexible 10-hour block of professional services for organizations implementing, operating, or optimizing CrowdStrike Falcon Next-Gen SIEM. The engagement can support a new deployment, accelerate the onboarding of additional security and infrastructure data sources, address configuration or data-quality issues, refine an existing implementation, or provide targeted assistance to an internal security team. The hours may be allocated across source onboarding, log management, platform configuration, detection engineering, investigation workflows, operational documentation, and knowledge transfer according to the customer’s priorities. This service relates specifically to CrowdStrike Falcon Next-Gen SIEM and may include assistance with telemetry generated by customer-owned AWS environments, cloud services, SaaS applications, security products, identity systems, endpoints, network infrastructure, and on-premises technology. Examples of relevant AWS telemetry may include AWS CloudTrail, Amazon GuardDuty, Amazon VPC Flow Logs, AWS WAF, Amazon Route 53 Resolver logs, Elastic Load Balancing logs, Amazon S3 access logs, AWS IAM activity, Amazon EC2 workloads, and other supported AWS services selected by the customer.

    Source-onboarding activities may include reviewing available data sources, identifying appropriate ingestion methods, assisting with connector or collector configuration, validating incoming events, troubleshooting incomplete or delayed ingestion, reviewing timestamps and source identifiers, and confirming that important fields are available for searching and detection. Log-management activities may include reviewing parsing and normalization, identifying duplicate or low-value events, improving source naming and categorization, refining filters and routing, evaluating data volume, and developing practical recommendations for managing ingestion and retention. Detection-engineering activities may include identifying priority security use cases, reviewing existing detection logic, creating or modifying correlation rules, adjusting thresholds and time windows, developing exclusions for known benign activity, adding contextual enrichment, assigning appropriate severity levels, and improving the information presented to analysts during triage. The block may also be used to create or refine searches, dashboards, investigation queries, alert descriptions, response guidance, and operational workflows that help the customer’s security team use Falcon Next-Gen SIEM more effectively. Where appropriate, detection use cases may be aligned with the customer’s threat model, business risks, technology environment, or selected frameworks such as MITRE ATT&CK.

    The engagement is delivered collaboratively and begins with confirmation of the customer’s objectives, environment, available access, and highest-priority work items. Activities are performed against an agreed backlog so that the available hours are directed toward the work offering the greatest practical value. Depending on the tasks completed, engagement outputs may include configuration changes, newly onboarded or validated data sources, updated detection logic, troubleshooting findings, implementation notes, recommendations, and knowledge-transfer sessions with the customer’s technical or security personnel. This listing covers up to 10 hours of professional-services labor and does not include CrowdStrike software subscriptions, AWS service charges, third-party licenses, managed detection and response, continuous monitoring, 24x7 operational support, formal incident-response retainers, compliance certification, or extensive custom software development. The customer is responsible for maintaining the required CrowdStrike and AWS subscriptions, providing appropriately authorized technical contacts and administrative access, coordinating with relevant data owners, approving changes, and completing any internal security or change-management requirements. Work extending beyond the available 10-hour block may be separately scoped or purchased through an additional services block.

    Highlights

    • 1:1 Engineering Support

    Details

    Delivery method

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Pricing

    Custom pricing options

    Pricing is based on your specific requirements and eligibility. To get a custom quote for your needs, request a private offer.

    How can we make this page better?

    Tell us how we can improve this page, or report an issue with this product.
    Tell us how we can improve this page, or report an issue with this product.

    Legal

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Support

    Vendor support