Couldn’t make Fal.Con? Get in on Fal.Con Digital. Learn more
CrowdStrike Falcon® Onum

The real-time data pipeline for the agentic SOC

Falcon Onum collects, filters, enriches, and routes real-time telemetry across Falcon and third-party security tools.

Adversaries move faster across fragmented data

AI-accelerated, malware-free attacks exploit gaps across identity, cloud, SaaS, and edge devices.

Famous Chollima

1. 89% increase in AI-enabled attacks1

2. 82% of detections were malware-free1

3. 27s fastest breakout time: adversaries outpace your data1

4. 171% increase in cloud-conscious attacks2

Turn telemetry into AI-ready security data


Process data in motion to accelerate action, lower cost, and reduce operational friction.

lifecycle graphic for next-gen SIEM

70%

Faster incident response with real-time processing, enrichment, and routing3


50%

Lower storage costs with smart filtering4


40%

Less ingestion overhead, fueling better SOC outcomes4

Connect third-party data that arrives detection ready


Every agent is only as good as the data behind it. Falcon Onum creates the real-time security data foundation for the agentic SOC, governing and routing high-quality telemetry across Falcon and third-party environments. Give AI agents the data they need to accelerate investigations, automation, and response.

Charlotte AI dashboard
×

Process once. Deliver everywhere.


Process telemetry once and deliver destination-ready data across Falcon and third-party environments. Route high-quality streams to CrowdStrike Falcon® Next-Gen SIEM, CrowdStrike Falcon® LogScale, AI workflows, storage, analytics, SOAR, and more:  eliminating duplicate pipelines and unnecessary complexity.

Optimize data. Reduce friction.


Control data before it reaches downstream systems. Falcon Onum intelligently filters, enriches, and routes telemetry to reduce storage, ingestion, and processing costs while preserving the data required for detection, investigation, compliance, and response.

Charlotte AI dashboard showing data sinks
×
Charlotte AI dashboard showing pipelines
×

Put data where it matters. Search where it lives. 


Route telemetry to the destinations that deliver the most value for detection, investigation, retention, and AI. Combined with Falcon Next-Gen SIEM federated search, analysts can investigate supported data where it lives, reducing duplication while preserving context.

Improve signal before storage


Filter repetitive noise, enrich telemetry and apply supported detection logic while data is still in motion. Falcon Onum surfaces higher-value signals earlier and routes actionable data to the right security and AI workflows.

Data sink dashboard
×

Watch Falcon Onum in action

Recognized by analysts. Trusted by customers.

See why organizations trust Falcon Next-Gen SIEM


Adversary-informed intelligence. Delivered at scale. Trusted when it matters most.

Consolidating security on the Falcon platform allows us to address our unique security needs from a single, centralized interface. We can create custom dashboards, conduct tailored analyses, and quickly determine appropriate responses to incidents.”
Mathias Espeloer, Director of IT, HEUKING
HEUKING logo
We don't have the time or energy to go search into millions of logs. So having AI layered on top of CrowdStrike’s SIEM product is where we want to be.”
Wayne Cross, Director, Cybersecurity and Infrastructure Operations, BLG
BLG logo
With Falcon Next-Gen SIEM, we were writing custom detections and getting results on day one…We're super excited about Falcon Fusion. It's intuitive, and having that type of automation within the Falcon platform is huge for us. There's a lot of custom ad hoc rules that we leverage, and having that SOAR capability to automate any of those steps is valuable.”
Nathan Kelly, Senior Information Security Engineer, TaylorMade
Taylormade logo

 

Latest innovations from

Fal.Con 2026 Logo
CrowdStrike Delivers the Next Evolution of the Agentic SOC
5 High-Impact Use Cases for Falcon Onum
Modernize security operations without rip and replace

Featured Resources

Customer Story
Global Telecom Turns Network Telemetry into Real-Time Intelligence with CrowdStrike Falcon Onum
Data Sheet
Fuel every agentic workflow with a high-performance security data control plane
Live Demo
Accelerate Your Agentic SOC Transformation with Falcon Onum

Accelerate your agentic SOC transformation

Learn how Falcon Onum eliminates data migration bottlenecks, friction, and cost.

Falcon Onum FAQs

No. Falcon Onum can be deployed independently to modernize telemetry pipelines, reduce data volume, improve signal quality, and optimize the broader security stack.

When used with Falcon Next-Gen-SIEM, Onum accelerates onboarding, enhances data control, enables intelligent data routing, and makes it easier to enrich data in motion. As certified pipelines become more available, Falcon Onum also helps customers optimize telemetry with greater confidence by validating pipeline changes against downstream security workflows.

As an independent solution, Falcon Onum operates as a high-performance, real-time data pipeline that collects, structures, enriches, and routes telemetry across your security and IT ecosystem. Onum provides:

  • Real-time parsing and enrichment of logs in motion
  • Noise reduction, filtering, masking, enrichment, and data shaping at the source
  • Intelligent, multi-destination routing to SIEMs, data lakes, analytics tools, and storage
  • Support for in-pipeline detections and transformations for non Falcon Next-Gen-SIEM destinations

In this mode, Falcon Onum gives teams fine-grained control over how telemetry moves across their environment, helping reduce cost, improve data quality, and accelerate downstream tools.

Falcon Onum works alongside both Falcon Next-Gen SIEM and Falcon Complete as a data control and routing layer, but the level of transformation allowed depends on the destination.

Falcon Next-Gen SIEM

  • Falcon Onum handles the data control plane, with routing and PII masking into Falcon Next-Gen SIEM
  • Falcon Onum sends raw, CrowdStrike Parsing Standard (CPS)-aligned events directly into Falcon Next-Gen SIEM for indexing and detection
  • Falcon Onum enriches, filters, and reshapes telemetry before delivering optimized copies to secondary destinations such as data lakes, analytics tools, and third-party systems

Falcon Complete Next-Gen MDR

  • Falcon Complete ingests sensor-native telemetry directly, and Onum does not modify or influence this ingest path
  • Falcon Onum may process and route copies of telemetry to secondary destinations (storage, analytics, third-party SIEMs), applying masking, filtering, or enrichment only on those branches while preserving Falcon Complete’s full visibility and MDR efficacy

This joint architecture ensures fast onboarding, control over data flow, and full SIEM detection accuracy.

Falcon Onum can apply transformations for secondary destinations, including:

  • Field-level masking and tokenization
  • Enrichment (GeoIP, asset data, threat intelligence, tags)
  • Filtering, suppression, and shaping
  • Format normalization (JSON, KV, CSV, XML, and more)

For data flowing into Falcon Next-Gen SIEM, Onum supports:

  • PII masking
  • Selective routing and copying to cold storage
  • Data hygiene actions that do not alter Falcon Next-Gen SIEM required CPS structure

This ensures customers gain upstream control while preserving Falcon Next-Gen SIEM detection logic. As certified pipelines become more available, additional validation will help customers optimize data while maintaining parser compatibility and downstream security workflows.

Yes. Falcon Onum supports inline detections such as Sigma rule evaluation, IOC matching, and pattern-based triggers when routing to third-party destinations like data lakes, SOAR, observability tools, and external SIEMs.

When used with Falcon Next-Gen SIEM:

  • Inline detections are supported only for non-Next-Gen SIEM routes, not for the Next-Gen SIEM ingestion path
  • All Next-Gen SIEM detections are performed within Falcon Next-Gen SIEM using CPS-structured raw telemetry
  • Falcon Onum can still route the detection results (tags, flags, metadata) to alternate destinations, while keeping Next-Gen SIEM data intact

This gives customers flexibility without impacting Falcon Next-Gen SIEM’s native detection pipeline.

Certified Pipelines are a planned capability designed to help organizations optimize security data with greater confidence.

They provide validation and guardrails that help ensure pipeline changes preserve the fields, schemas, and context required by downstream detections, dashboards, searches, workflows, and AI agents. The goal is to make it easier to reduce cost, improve data quality, and optimize telemetry without unintentionally impacting security operations.

When used with Falcon Next-Gen SIEM, Certified Pipelines are intended to help customers safely optimize data while preserving CrowdStrike Parsing Standard (CPS) compatibility and downstream detection fidelity.

Falcon Onum provides the real-time security data foundation for the agentic SOC by collecting, governing, enriching, and routing high-quality telemetry across Falcon and third-party environments.

By delivering AI-ready data in motion, Falcon Onum helps security teams:

  • Accelerate onboarding of new data sources
  • Improve data quality for AI agents and analytics
  • Reduce noise before downstream processing
  • Route telemetry to Falcon Next-Gen SIEM, AI workflows, storage, and third-party systems from a single pipeline

Falcon Onum works with Falcon Next-Gen SIEM and the broader Falcon platform to ensure analysts and AI agents have trusted, contextual data wherever investigations occur.

1 CrowdStrike 2026 Global Threat Report

2 CrowdStrike 2026 Threat Hunting Report

3 Results are from a customer case study. Individual results may vary.

4 These numbers are projected estimates of average benefit based on company’s own internal analysis and recorded metrics provided by customers during pre-sale motions that compare the value of CrowdStrike with the customer’s incumbent solution. Actual realized value will depend on the customer's module deployment and environment.

*As of June 2, 2025, CrowdStrike has an Overall Rating of 4.7 out of 5 and the most reviews in a 12 month period in the Security Information and Event Management, based on 184 reviews on Gartner Peer Insights™