CrowdStrike Falcon Intelligence Add-on use to fetch data from Falcon Intelligence and indexes it in Splunk for further analysis.
On Splunk Forwarder:
On Splunk Indexer Nodes:
On Splunk Search Head:
** Note: By default, all data is indexed to the main index. If you want to use a custom index then kindly update "cs_get_intelligence_index" macro in CrowdStrike Falcon Intelligence Add-on.
A good test to see that you are receiving all of the data we expect is to run below search after several minutes:
cs_get_intelligence_index| stats count by sourcetype
In particular, you should see below sourcetype:
Copyright (C) by CrowdStrike. All Rights Reserved.
* Version 1.0.1
- Updated README file.
* Version 1.0.0
- Account setup to fetch data from Falcon Intelligence.
As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 10GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps and add-ons from Splunk, our partners and our community. Find an app or add-on for most any data source and user need, or simply create your own with help from our developer portal.