CrowdStrike Falcon Intelligence Add-on use to fetch data from Falcon Intelligence and indexes it in Splunk for further analysis.
On Splunk Forwarder:
On Splunk Indexer Nodes:
On Splunk Search Head:
** Note: By default, all data is indexed to the main index. If you want to use a custom index then kindly update "cs_get_intelligence_index" macro in CrowdStrike Falcon Intelligence Add-on.
A good test to see that you are receiving all of the data we expect is to run below search after several minutes:
cs_get_intelligence_index| stats count by sourcetype
In particular, you should see below sourcetype:
Copyright (C) by CrowdStrike. All Rights Reserved.
Updated README file.
As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 10GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps from Splunk, our partners and our community. Find an app for most any data source and user need, or simply create your own with help from our developer portal.