CrowdStrike Falcon Tags

The CrowdStrike Extension provides two major tag types: auto tags and manual tags.

Auto Tags

Auto tags are automatically assigned based on the endpoint’s status information received from CrowdStrike. There are two status categories:

  • CrowdStrike Status – Indicates the endpoint’s security status as determined by CrowdStrike. These reflect the health or threat level of the endpoint and can be:

    • Normal

    • Critical

    • Unknown

    • Warning

  • CrowdStrike Provision Status – Indicates whether the endpoint is correctly provisioned within CrowdStrike. These indicate the provisioning state and can be:

    • Provisioned

    • Not Provisioned

    • Unknown Provision

Manual Tags

Manual tags allow administrators to create custom client classifications based on specific CrowdStrike attributes that are not automatically tagged. To create a manual tag, complete the following steps:

  1. Navigate to the Client Classification card in HPE Aruba Networking Central.

  2. Locate the Create Tag button in the top right corner.

  3. Assign a name to the tag (e.g., CS-Prevention-Policy).

  4. Select CS: Policy Type from the Attributes drop-down.

    • Choose the policy type applied to the client (e.g., Prevention).

    • Click the + icon to add it.

  5. Click Create.

  6. This is an optional setting. Select Tag Application to perform the following tasks:

    • The tag is applied to all clients that have the selected policy type configured in CrowdStrike.

    • This helps in filtering, reporting, and applying network policies based on endpoint security posture.

Use Cases for Manual Tags

Manual tags can be used in various scenarios, such as:

  • Policy-based segmentation: Apply different network access rules based on the CrowdStrike policy.

  • Compliance tracking: Identify clients missing critical policies.

  • Operational visibility: Group clients by security configuration for easier monitoring.