Under the agreement, CrowdStrike’s Falcon platform will be available through the Snowflake Marketplace, allowing customers to use existing Snowflake commitments to purchase Falcon through Snowflake’s Marketplace Capacity Drawdown program.
The companies are also integrating their platforms, with Snowflake data becoming accessible directly from Falcon investigations through federated search.
CrowdStrike’s Falcon Next-Gen SIEM will ingest and correlate Snowflake data with security telemetry, while Falcon Onum will allow organisations to route security telemetry into Snowflake and other destinations.
“Security teams need the freedom to put their data to work wherever it lives,” Daniel Bernard, chief business officer at CrowdStrike, said from the Fal.Con event in Las Vegas.
“Our collaboration with Snowflake will make Falcon easier to buy and deploy while giving customers more choice in how and where they operationalise their security data. That’s how we reduce complexity, accelerate security outcomes, and stop threats faster.”
The integration is for enterprises that already hold substantial volumes of operational and business data in Snowflake but want to bring that information into security investigations without copying or relocating it.
Through federated search, security teams will be able to query Snowflake data from within Falcon investigations, providing additional context without switching between tools or moving the underlying data.
Snowflake data can also be brought into Falcon Next-Gen SIEM, where it can be correlated with CrowdStrike telemetry and third-party security data to give security teams a broader view of potential threats.
CrowdStrike’s Falcon Onum will provide another link between the platforms, allowing security telemetry to be routed natively to Snowflake, Falcon Next-Gen SIEM and other destinations. The companies said this is designed to reduce friction and costs associated with moving security data between platforms.
“Enterprises already bring their most critical data to Snowflake, and that broader enterprise context is what makes security decisions better,” said Mayank Upadhyay, chief security and trust officer at Snowflake. “Our collaboration with CrowdStrike will let security teams build stronger detections and run more complete investigations against data they already trust, without moving it.”
The partnership comes as security teams face growing volumes of telemetry alongside increasingly distributed data estates. Rather than forcing organisations to consolidate all data into a dedicated security platform, CrowdStrike and Snowflake are positioning the integration around federated access and interoperability.
For CrowdStrike, the agreement also creates a new procurement route for Falcon while extending its strategy of making security telemetry and enterprise data accessible across the wider technology stack.
Want to see more stories from trusted news sources?Make Cyber Daily a preferred news source on Google.