# Crowdstrike API Integration

**URL:** <https://discuss.elastic.co/t/crowdstrike-api-integration/367132>\
**Category:** Kibana\
**Created:** [September 25, 2024, 8:22pm UTC](https://discuss.elastic.co/t/crowdstrike-api-integration/367132 "2024-09-25T20:22:26Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![wesleyj-hub](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wesleyj-hub/32/137873_2.png) [@wesleyj-hub](https://discuss.elastic.co/u/wesleyj-hub)\
**Post date:** [September 25, 2024, 8:22pm UTC](https://discuss.elastic.co/t/crowdstrike-api-integration/367132/1 "2024-09-25T20:22:26Z")

</div>

I am having an issue with getting the API instance set up to connect Crowdstrike. Crowdstrike seems to need a POST request in order to pull the token, but it doesn't appear to be a way to add that if it is needed. After adding the Base URL, Client ID/Key, and Token URL provided by Crowdstrike, I get several errors. Could someone please advise the proper setup for the gov cloud instance? Below is the error I get in document form from Kibana.

"[  
POST:{  
"meta": {  
"query\_time": 0.000350391,  
"powered\_by": "device-api",  
"trace\_id": "4506edf4-a4a6-4b1d-9c31-e9aaecc4de4c"  
},  
"resources": null,  
"errors": [  
{  
"code": 400,  
"message": "The 'ids' parameter must be present at least once."  
}  
]  
},  
Processor json with tag json\_event\_original in pipeline logs-crowdstrike.host-1.42.0 failed with message: field [original] not present as part of path [event.original],  
Processor conditional with tag in pipeline logs-crowdstrike.host-1.42.0 failed with message: cannot access method/field [policies] from a null def reference  
]"
