This technical add-on enables periodic connections to CrowdStrike's Hosts API to retrieve detailed data that the CrowdStrike Falcon sensor has collected about the device.
Inputs can be filtered by the "platform_name" API field, enabling separate indexing of Windows, Mac and Linux devices. In addition inputs can be configured to only collect device details for devices where the "last_seen" field value is later than the last successful data collection. This feature can be especially helpful for customers running large VDI environments with constant turnover.
This Version Replaces All other Versions
This Version Replaces All other Versions
Update to align with Splunk Cloud requirements.
As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 10GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps from Splunk, our partners and our community. Find an app for most any data source and user need, or simply create your own with help from our developer portal.