CrowdStrike Unified Alert Add-on provide CrowdStrike customers with the ability to collect multiple types of detections and alerts from a single Splunk Add-on leveraging CrowdStrike's Unified Alerts API. The data sets provided in the Unified Alerts events are some of the most comprehensive provided via CrowdStrike API. Customers that want to collect more detailed information around detections than what's provided in the Event Streams API should deploy this add-on. NOTE: The types of detections shown depend on the active Falcon subscriptions. The some examples of the types of detections that are available for collection are: Endpoint detections Mobile detections Identity-based detections Cloud runtime detections
(0)
Categories
Created By
Type
Downloads
Licensing
Splunk Answers
Resources