The real-time data pipeline for the agentic SOC
Falcon Onum collects, filters, enriches, and routes real-time telemetry across Falcon and third-party security tools.
Adversaries move faster across fragmented data
AI-accelerated, malware-free attacks exploit gaps across identity, cloud, SaaS, and edge devices.
1. 89% increase in AI-enabled attacks1
2. 82% of detections were malware-free1
3. 27s fastest breakout time: adversaries outpace your data1
4. 171% increase in cloud-conscious attacks2
Turn telemetry into AI-ready security data
Process data in motion to accelerate action, lower cost, and reduce operational friction.
70%
Faster incident response with real-time processing, enrichment, and routing3
50%
Lower storage costs with smart filtering4
40%
Less ingestion overhead, fueling better SOC outcomes4
Connect third-party data that arrives detection ready
Every agent is only as good as the data behind it. Falcon Onum creates the real-time security data foundation for the agentic SOC, governing and routing high-quality telemetry across Falcon and third-party environments. Give AI agents the data they need to accelerate investigations, automation, and response.
Process once. Deliver everywhere.
Process telemetry once and deliver destination-ready data across Falcon and third-party environments. Route high-quality streams to CrowdStrike Falcon® Next-Gen SIEM, CrowdStrike Falcon® LogScale, AI workflows, storage, analytics, SOAR, and more: eliminating duplicate pipelines and unnecessary complexity.
Optimize data. Reduce friction.
Control data before it reaches downstream systems. Falcon Onum intelligently filters, enriches, and routes telemetry to reduce storage, ingestion, and processing costs while preserving the data required for detection, investigation, compliance, and response.
Put data where it matters. Search where it lives.
Route telemetry to the destinations that deliver the most value for detection, investigation, retention, and AI. Combined with Falcon Next-Gen SIEM federated search, analysts can investigate supported data where it lives, reducing duplication while preserving context.
Improve signal before storage
Filter repetitive noise, enrich telemetry and apply supported detection logic while data is still in motion. Falcon Onum surfaces higher-value signals earlier and routes actionable data to the right security and AI workflows.
Watch Falcon Onum in action
Recognized by analysts. Trusted by customers.
See why organizations trust Falcon Next-Gen SIEM
Adversary-informed intelligence. Delivered at scale. Trusted when it matters most.
Latest innovations from
Featured Resources
Falcon Onum FAQs
No. Falcon Onum can be deployed independently to modernize telemetry pipelines, reduce data volume, improve signal quality, and optimize the broader security stack.
When used with Falcon Next-Gen-SIEM, Onum accelerates onboarding, enhances data control, enables intelligent data routing, and makes it easier to enrich data in motion. As certified pipelines become more available, Falcon Onum also helps customers optimize telemetry with greater confidence by validating pipeline changes against downstream security workflows.
As an independent solution, Falcon Onum operates as a high-performance, real-time data pipeline that collects, structures, enriches, and routes telemetry across your security and IT ecosystem. Onum provides:
- Real-time parsing and enrichment of logs in motion
- Noise reduction, filtering, masking, enrichment, and data shaping at the source
- Intelligent, multi-destination routing to SIEMs, data lakes, analytics tools, and storage
- Support for in-pipeline detections and transformations for non Falcon Next-Gen-SIEM destinations
In this mode, Falcon Onum gives teams fine-grained control over how telemetry moves across their environment, helping reduce cost, improve data quality, and accelerate downstream tools.
Falcon Onum works alongside both Falcon Next-Gen SIEM and Falcon Complete as a data control and routing layer, but the level of transformation allowed depends on the destination.
Falcon Next-Gen SIEM
- Falcon Onum handles the data control plane, with routing and PII masking into Falcon Next-Gen SIEM
- Falcon Onum sends raw, CrowdStrike Parsing Standard (CPS)-aligned events directly into Falcon Next-Gen SIEM for indexing and detection
- Falcon Onum enriches, filters, and reshapes telemetry before delivering optimized copies to secondary destinations such as data lakes, analytics tools, and third-party systems
Falcon Complete Next-Gen MDR
- Falcon Complete ingests sensor-native telemetry directly, and Onum does not modify or influence this ingest path
- Falcon Onum may process and route copies of telemetry to secondary destinations (storage, analytics, third-party SIEMs), applying masking, filtering, or enrichment only on those branches while preserving Falcon Complete’s full visibility and MDR efficacy
This joint architecture ensures fast onboarding, control over data flow, and full SIEM detection accuracy.
Falcon Onum can apply transformations for secondary destinations, including:
- Field-level masking and tokenization
- Enrichment (GeoIP, asset data, threat intelligence, tags)
- Filtering, suppression, and shaping
- Format normalization (JSON, KV, CSV, XML, and more)
For data flowing into Falcon Next-Gen SIEM, Onum supports:
- PII masking
- Selective routing and copying to cold storage
- Data hygiene actions that do not alter Falcon Next-Gen SIEM required CPS structure
This ensures customers gain upstream control while preserving Falcon Next-Gen SIEM detection logic. As certified pipelines become more available, additional validation will help customers optimize data while maintaining parser compatibility and downstream security workflows.
Yes. Falcon Onum supports inline detections such as Sigma rule evaluation, IOC matching, and pattern-based triggers when routing to third-party destinations like data lakes, SOAR, observability tools, and external SIEMs.
When used with Falcon Next-Gen SIEM:
- Inline detections are supported only for non-Next-Gen SIEM routes, not for the Next-Gen SIEM ingestion path
- All Next-Gen SIEM detections are performed within Falcon Next-Gen SIEM using CPS-structured raw telemetry
- Falcon Onum can still route the detection results (tags, flags, metadata) to alternate destinations, while keeping Next-Gen SIEM data intact
This gives customers flexibility without impacting Falcon Next-Gen SIEM’s native detection pipeline.
Certified Pipelines are a planned capability designed to help organizations optimize security data with greater confidence.
They provide validation and guardrails that help ensure pipeline changes preserve the fields, schemas, and context required by downstream detections, dashboards, searches, workflows, and AI agents. The goal is to make it easier to reduce cost, improve data quality, and optimize telemetry without unintentionally impacting security operations.
When used with Falcon Next-Gen SIEM, Certified Pipelines are intended to help customers safely optimize data while preserving CrowdStrike Parsing Standard (CPS) compatibility and downstream detection fidelity.
Falcon Onum provides the real-time security data foundation for the agentic SOC by collecting, governing, enriching, and routing high-quality telemetry across Falcon and third-party environments.
By delivering AI-ready data in motion, Falcon Onum helps security teams:
- Accelerate onboarding of new data sources
- Improve data quality for AI agents and analytics
- Reduce noise before downstream processing
- Route telemetry to Falcon Next-Gen SIEM, AI workflows, storage, and third-party systems from a single pipeline
Falcon Onum works with Falcon Next-Gen SIEM and the broader Falcon platform to ensure analysts and AI agents have trusted, contextual data wherever investigations occur.
1 CrowdStrike 2026 Global Threat Report
2 CrowdStrike 2026 Threat Hunting Report
3 Results are from a customer case study. Individual results may vary.
4 These numbers are projected estimates of average benefit based on company’s own internal analysis and recorded metrics provided by customers during pre-sale motions that compare the value of CrowdStrike with the customer’s incumbent solution. Actual realized value will depend on the customer's module deployment and environment.
*As of June 2, 2025, CrowdStrike has an Overall Rating of 4.7 out of 5 and the most reviews in a 12 month period in the Security Information and Event Management, based on 184 reviews on Gartner Peer Insights™