Transform AWS Security Operations with Falcon Next-Gen SIEM

CrowdStrike advances Falcon Next-Gen SIEM and cloud security access on AWS with simplified onboarding, flexible pricing, and expanded integrations for cost-efficient operations.

CrowdStrike is redefining how SOC teams turn cloud data into actionable intelligence by unifying speed, scale, and cost efficiency in one platform built for the cloud and AI era. Together with AWS, today we are announcing new integrations and consumption options designed to further simplify how customers secure and operationalize workloads on Amazon Web Services (AWS).

Together, we are introducing Quick Start for AWS for CrowdStrike Falcon® Next-Gen SIEM, pay-as-you-go pricing for Falcon Next-Gen SIEM and CrowdStrike Falcon® Cloud Security, and expanded integration with Amazon Athena. With these innovations, customers can onboard faster, scale as needed, and improve cost efficiency in accessing security and operational data across their AWS environments.

The cloud era demands elasticity and scalability. Falcon Next-Gen SIEM, built for modern security operations, seamlessly scales with workloads to deliver unified visibility and context across AWS and hybrid environments. It’s built with native AI and automation to streamline manual tasks and provides intelligent data access to optimize what’s stored or searched based on business and security needs.

With today’s innovations, CrowdStrike and AWS are making it easier for customers to adopt and scale with the CrowdStrike Falcon® platform across AWS environments.

Simplify AWS Security Operations with Falcon Next-Gen SIEM

Falcon Next-Gen SIEM correlates AWS data with telemetry from across the security ecosystem to provide the insights SOC teams need to detect, investigate, and respond to threats across cloud environments. It offers out-of-the-box dashboards for CloudTrail, VPC, and S3 monitoring and over 200 correlation rule templates for Cloudtrail. With Falcon Next-Gen SIEM and AWS data, teams can quickly identify threats like stolen AWS keys, unauthorized access, privilege escalation, and unusual traffic.

Teams with Falcon Cloud Security can also query data directly from Falcon Next-Gen SIEM, reducing complexity with the power of the Falcon platform. By unifying AWS telemetry with data from endpoints, identities, and more, CrowdStrike provides the full picture of an attack, not just cloud activity. With AI and automation built into the Falcon platform, SOCs can simplify cloud complexity so teams can act with confidence at scale.

At AWS re:Invent, we’re announcing new innovations that deepen our partnership with the leader in cloud and expand the power of Falcon Next-Gen SIEM in AWS environments.

Quick Start for AWS: Gain Visibility in Minutes

CrowdStrike is the first cybersecurity partner to introduce Quick Start for AWS. This guided setup directly connects Falcon Next-Gen SIEM to core AWS security services including AWS CloudTrail, AWS Security Hub, and Amazon GuardDuty.

Customers can use this guided onboarding process to automate key steps:

  • Discover active AWS security services like CloudTrail, GuardDuty, and Security Hub for continuous monitoring and ingest telemetry within minutes.

  • Connect data sources through a guided onboarding wizard without the need for manual setup or special permissions.

  • Activate log parsers to normalize and enrich AWS events. 

  • Deploy prebuilt detection rules to correlate AWS activity with other security data and uncover sophisticated threats.

By streamlining how customers connect their AWS environments to CrowdStrike, organizations can unify data from endpoints, cloud workloads, and identities with AWS telemetry for comprehensive, cross-domain threat detection and response.

Federated Search with Amazon Athena: Query Smarter, Store Less

Federated search will combine the power of Falcon Next-Gen SIEM with the scale and cost efficiency of AWS. New federated search capabilities via Amazon Athena will provide fast and flexible access to data stored in Amazon S3 buckets. Analysts will be able to query data in place without needing to duplicate or reingest, enabling them to:

  • Perform on-demand queries for forensics, compliance, or audit use cases.

  • Create a cost-effective data strategy by routing data to S3 using telemetry pipelines like CrowdStrike Falcon® Onum.

These integrations deliver an AWS-optimized approach to detection and response that is both scalable and cost-efficient. Teams can keep high-value data in Falcon Next-Gen SIEM for active investigations while storing rarely accessed data in low-cost storage. The result is faster insight when needed and smarter data management overall.

Figure 1. Federated search will enable connections to query external data stores like Amazon Athena Figure 1. Federated search will enable connections to query external data stores like Amazon Athena

Introducing Pay-as-You-Go Pricing for Flexible Consumption

To further simplify adoption, CrowdStrike is offering pay-as-you-go pricing for Falcon Next-Gen SIEM and Falcon Cloud Security in AWS Marketplace. New customers can deploy and start protecting AWS workloads in minutes. They pay only for what they use and can scale as their environments expand within AWS’s unified billing and procurement system. This new model simplifies how security is bought and managed in the cloud and makes advanced AI-powered security accessible to organizations of all sizes.  

The Power of CrowdStrike and AWS for a Unified Cloud Defense 

With Falcon Next-Gen SIEM’s built-in AI and automation, SOC teams can detect and respond to cloud threats faster than ever. The Falcon platform gives complete visibility across AWS data sources and the rest of the security ecosystem, helping analysts pinpoint threats, manage data efficiently, and keep costs under control. The outcome is a more efficient and adaptable SOC that operates confidently and clearly at cloud scale.

Additional Resources

  • Explore how CrowdStrike and AWS work together to unify visibility, accelerate detection, and simplify cloud security operations. 
  • See the power of Falcon Next-Gen SIEM and Quick Start for AWS to detect, investigate, and stop threats across AWS environments. 
  • Begin ingesting AWS data in minutes, automatically onboard data and enable instant visibility with Quick Start for AWS. 

Forward-Looking Statements

This blog includes descriptions of products, features, or functionality that may not be currently generally available. Any such references are provided for information purposes only. The development, release, and timing of all features or functionality remain at our sole discretion and may change without notice. These statements are subject to risks, uncertainties, and assumptions that may cause actual results to differ materially from those expressed or implied.  Customers should make purchasing decisions based only on services and features that are currently generally available. For more information on our existing offerings, please talk to your CrowdStrike representative.