This technical add-on enables periodic connections to CrowdStrike's Hosts API to retrieve detailed data that the CrowdStrike Falcon sensor has collected about the device.
Inputs can be filtered by the "platform_name" API field, enabling seperate indexing of Windows, Mac and Linux devices. In addition inputs can be configured to only collect device details for devices where the "last_seen" field value is later than the last successful data collection. This feature can be especially helpful for customers running large VDI environments with constant turnover.
Splunk v8+ with Python 3
CrowdStrike OAuth2 Authentication
CrowdStrike US based, EU and GovCloud environments
Multiple customer environments
the updated /devices/entities/devices/v2 endpoint
CrowdStrike Resource Center: CrowdStrike Falcon Devices Add-On Guide v3.1.5+.
CrowdStrike Resource Center: CrowdStrike Falcon Devices Add-On Guide v3.1.
CrowdStrike App
CrowdStrike Falcon Event Streams Technical Add-On
CrowdStrike Falcon Spotlight Technical Add-On
CrowdStrike Intel Indicator Technical Add-On
CrowdStrike Scheduled Search Technical Add-on
This Version Replaces All other Versions
Update to align with Splunk Cloud requirements.
As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 10GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps from Splunk, our partners and our community. Find an app for most any data source and user need, or simply create your own with help from our developer portal.