Splunk v8+ with Python 3
CrowdStrike OAuth2 Authentication
CrowdStrike US based, EU and GovCloud environments
Multiple customer environments
Multiple connections to a single Event Streams API, providing the AppID is unique within the CrowdStrike environment
CrowdStrike Resource Center: CrowdStrike Falcon Event Streams Add-On Guide
CrowdStrike Resource Center: CrowdStrike Falcon Event Streams Transition Guide
CrowdStrike Resource Center: CrowdStrike Falcon Event Streams Add-On Guide v3
CrowdStrike Falcon Event Streams Technical Add-On
CrowdStrike Falcon Devices Technical Add-On
Updates/Modifications/Bug Fixes in this version:
Restores EVAL-dest, EVAL-vendor_account field mappings to their previous configurations
Added eventtype crowdstrike_customIOC_event
Added tag crowdstrike_customIOC_event
Added crowdStrike_cloud_security_IOM_event
Added detection and error handling to gracefully handle Application ID collisions
The following events and their associated tags have been marked for removal in an upcoming release. Please plan accordingly:
CrowdStrike_CustomIOC_Event
crowdStrike_customIOC_event
CrowdStrike_IdentityProtection_Event
crowdStrike_identity_protection_event
crowdstrike_identity_protection_Event
This Version Replaces All other Versions
This Version Replaces All other Versions
This Version Replaces All other Versions
As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 10GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps from Splunk, our partners and our community. Find an app for most any data source and user need, or simply create your own with help from our developer portal.