Skip to main content

Stream Every Files.com File-Activity Event Into CrowdStrike

Files.com is the File Orchestration Platform your partner transfers, SFTP sessions, and automations run on. It keeps a record of everything that happens to your files: every login, upload, download, permission change, and automation run. This integration sends that record into CrowdStrike Next-Gen SIEM as it happens, so file activity is searchable next to the endpoint, identity, and threat-intelligence data your team already correlates in Falcon.

No credit card required · 7-day free trial · Live in minutes

#1 MFT vendor in Gartner Peer Insights
Trusted by 4,000+ companies
Every protocol included
CrowdStrikeFiles.com
  • G2 Leader — Managed File Transfer, Summer 2026
  • G2 Best Results — Managed File Transfer, Summer 2026
  • G2 Best Usability — Managed File Transfer, Summer 2026
  • G2 Best Relationship — Managed File Transfer, Summer 2026
  • G2 Easiest Setup — iPaaS, Summer 2026
  • AWS Partner — Files.com is a verified AWS Partner.
  • Google Cloud Partner — Files.com is a verified Google Cloud Partner.
  • Microsoft Partner — Files.com is a verified Microsoft Partner.

4,000+ organizations rely on Files.com every day

Real companies. Real file flows. Real results.

Marc Jacobs logo
Cognizant logo
Bloomberg logo
TowneBank logo
PBS logo
Carrier logo
Hot Topic logo
Planet Fitness logo
Kaplan logo
Ashley Furniture logo
KFC logo
Mitsubishi logo
Stamps.com logo
Kyndryl logo
Toast logo
Equifax logo
Banner Health logo
Norton Rose Fulbright logo
Michelin logo
Redis logo
e.l.f. logo
Lilly Pulitzer logo
New Era logo
Digicert logo
Toyota logo
BBB logo
GoDaddy logo
Hershey logo
Zillow logo
CRISPR Therapeutics logo

Why Teams Stream Files.com Into CrowdStrike

Your security team already runs detections on endpoint, identity, and network data in Falcon. File movement is usually the gap: partner SFTP sessions and transfers of regulated data happen inside the file platform, where the sensor can't see them. Files.com closes that gap by sending its own activity into Next-Gen SIEM.

File Activity Next To Falcon Telemetry

Files.com sends a record of every login, upload, download, permission change, automation run, and API call into CrowdStrike the moment it happens. File activity lands alongside the endpoint, identity, and threat-intelligence data your team already watches in Falcon, so a suspicious transfer correlates with what the endpoint was doing at the same moment.

Sends Straight To Next-Gen SIEM

Files.com delivers events in JSON over HTTP to CrowdStrike's HEC-compatible ingestion endpoint, the path Next-Gen SIEM is built to receive on. There is no collector, forwarder, or middleware to install and keep running.

You Choose Which Logs Flow

Every log type is enabled by default, and you can trim the stream per CrowdStrike instance: send everything, or just the types your detections use. The selection lives in Files.com, so changing it never touches your Falcon configuration.

A Tamper-Proof Record Behind The Stream

Every event sent to CrowdStrike comes from the immutable Files.com audit log. If an investigation needs the original record, it's there: unaltered, retained for 7+ years, and independent of what your SIEM keeps.

The Control CrowdStrike Watches But Doesn't Provide

CrowdStrike reads the events. It doesn't decide who can touch which files or keep the record of what they did. Files.com does that part: access folder by folder, every action written to a record that can't be changed, and the same company logins your team already uses. That record is exactly what gets sent to Falcon.

Give People Access To Only Their Folders

Files.com controls access folder by folder, per user, group, and partner. CrowdStrike sees the events; Files.com is the control that decides who could touch the file in the first place.

A Record Of Everything That Happens

Every file action, session, and settings change is written to an audit log that can't be altered. When someone asks who changed a security setting two weeks ago, the answer is already on the record.

The Same Logins Your Company Already Uses

Files.com plugs into your SSO and identity provider, so the usernames in the events CrowdStrike ingests match the identities the rest of your security stack already tracks.

Delivery That's Encrypted And Logged

The stream to CrowdStrike is encrypted and authenticated with your connector token. Files.com also logs the act of sending, so a failed delivery is visible instead of silent.

Connect CrowdStrike The Way That Fits Your Workload

Live Stream Into Falcon

The main path. Files.com sends each event to your CrowdStrike HEC endpoint the moment it happens, so detections and dashboards run on file activity in near real time. SIEM streaming is an Enterprise-plan feature.

Drop Log Files In A Folder

Files.com can also write log files to a folder on a schedule, from every 5 minutes up to every 6 hours. That fits batch ingestion, a locked-down network, or a long-term archive alongside the live feed.

How Teams Use CrowdStrike On Files.com

Correlate A Transfer With The Endpoint

A user downloads an unusual volume of files and, minutes later, an endpoint starts behaving strangely. Because file events and Falcon telemetry live in the same place, one detection rule sees both, instead of two teams each holding half the story.

Answer "What Did They Take?"

After a compromised credential, your team searches CrowdStrike for every file the account touched: uploads, downloads, links opened, permissions changed. Every event traces back to the tamper-proof Files.com record.

Build Detections On File Behavior

Write detection rules and dashboards in Next-Gen SIEM that include Files.com activity — failed partner logins, off-hours transfers, mass deletions — scored and triaged in the same queue as the rest of your alerts.

Files.com Features That Pair With CrowdStrike

Audit Log

The full activity record behind the stream, searchable inside Files.com and exportable on demand.

Learn More

Automations & Workflows

Every automation run is an event you can watch and alert on in CrowdStrike, so a job that breaks shows up instead of failing quietly.

Learn More

Compliance Reporting

The same trustworthy record feeding CrowdStrike is the evidence a SOC 2, HIPAA, or GDPR review asks for.

Learn More
Files.com's strengths are simplicity, ease of use, and the cloud connectors. We don't have to invent custom infrastructure for every partner.
Tommy Chapley, Equifax
Tommy Chapley
Senior Software Engineer, Equifax
Files.com is versatile — it can manage many different situations from a single platform. We've consolidated multiple tools onto it.
Regis Litre, Rag & Bone
Regis Litre
Chief Information Officer, Rag & Bone
Files.com is robust and scales to a large enterprise. We get multiple files per minute, per second — and we're a 24/7 organization, so everything has to always be up.
Nelson Miranda, Spirit Airlines
Nelson Miranda
Sr. Systems Engineer, Spirit Airlines

Frequently Asked: CrowdStrike On Files.com

How Files.com sends file activity into CrowdStrike Next-Gen SIEM, which plans include the stream, and what your team can do with it in Falcon.

Files.com sends events in JSON format over HTTP to CrowdStrike's HEC-compatible ingestion endpoint. In the Falcon console you create an HEC / HTTP Event Data Connector, then paste its endpoint URL and API key into Files.com as the destination and token. There is nothing to install in between.

Files.com streams logins, file uploads and downloads, permission changes, settings changes, SFTP/FTP/WebDAV sessions, automation runs, and API calls. Every log type is enabled by default, and you can choose which types each CrowdStrike instance receives.

Yes. Once ingested, Files.com logs appear alongside native Falcon telemetry in CrowdStrike Next-Gen SIEM, where they are searchable and available for correlation with endpoint activity, identity events, and threat intelligence across detections, dashboards, and Advanced Event Search.

No. Files.com delivers events directly to the CrowdStrike HEC endpoint over HTTP, so there is no collector, forwarder, or agent to deploy and maintain for this integration.

No. Streaming to a SIEM, including CrowdStrike Next-Gen SIEM, is a Files.com Enterprise-plan feature and is not on the Starter or Power plans. The audit log itself is included on every plan, with retention windows that scale by tier, so the record behind the stream is there whichever plan you run.

Files.com also integrates natively with Microsoft Sentinel, Datadog, New Relic, and Sumo Logic, and ships a generic SIEM (Any Provider) connector that delivers JSON over HTTP to any platform that accepts it. For tools that speak Splunk's HEC protocol, like Cribl Stream or Vector, the Splunk Compatible integration sends the same HEC format and authentication.

Files.com retries a failed CrowdStrike delivery automatically, every 60 seconds for the first five minutes and every 15 minutes after that. Every event also comes from the immutable Files.com audit log, retained independently of the stream. Event Channels can alert your team the moment a CrowdStrike delivery fails, so the gap is noticed immediately.

Yes. Files.com Log File Streaming writes the same audit and activity log categories to a folder on your site at a configured interval, as JSON or CSV, for archival and batch workflows alongside or instead of the live stream into Falcon.

Files.com log streaming batches and forwards complete audit log categories to CrowdStrike roughly every 60 seconds. Event Channels deliver individual operational events, like SSO failures, user lockouts, and automation failures, to a webhook, Slack, Teams, SNS, or Pub/Sub target as they occur.

Files.com keeps its tamper-proof audit log for 7+ years, independent of what your Falcon instance retains. CrowdStrike governs its own retention; the Files.com record stays the long-term system of record for file activity.

See Files.com Stream Into Your Falcon Console

Start a free 7-day trial. Create the HEC connector in Falcon, paste in the endpoint and token, and watch file activity land in Advanced Event Search. No credit card required.

No credit card required • 7-day free trial • Live in minutes