IMPORTANT: If you are deploying this add-on to Splunk Cloud Victoria stacks please first validate that they are 8.2.2201+. Previous releases of Victoria do not include a key performance optimization that is important for high FDR event volumes.
Splunk does not support running CrowdStrike Falcon Data Replicator (FDR) S3 Technical Add-On or CrowdStrike Falcon Data Replicator (FDR) SQS Technical Add-On on the same deployment as Splunk Add-on for CrowdStrike FDR.
For details on the Splunk Add-on for CrowdStrike FDR, please refer to the Splunk Docs
As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 10GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps from Splunk, our partners and our community. Find an app for most any data source and user need, or simply create your own with help from our developer portal.