<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Attempting to write a search to find all CrowdStrike agents that are installed on the hosts in our environment in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Attempting-to-write-a-search-to-find-all-CrowdStrike-agents-that/m-p/745526#M241471</link>
    <description>&lt;P&gt;i do have access to it its under index=falcon with a &lt;SPAN&gt;sourcetype="crowdstrike:events:sensor or crowdstrike*". Just trying to find a full proof way to view 100% of the hosts that have the agent installed with each of the hosts source IP. if I could get a true and false statement saying no crowdstrike&amp;nbsp; agent is installed on the list that would be great. But sadly im not that versed at Splunkfu.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 05 May 2025 20:26:14 GMT</pubDate>
    <dc:creator>Ghost</dc:creator>
    <dc:date>2025-05-05T20:26:14Z</dc:date>
    <item>
      <title>Attempting to write a search to find all CrowdStrike agents that are installed on the hosts in our environment</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Attempting-to-write-a-search-to-find-all-CrowdStrike-agents-that/m-p/745519#M241467</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Got tasked with finding all hosts that didnt have the crowdstrike agent installed and running into problems with my searches.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ive used the following "CSFalconservice.exe | stats count by host" &amp;amp; "index=*sourcetype="crowdstrike:events:sensor" | stats count by host" but its not giving me the information per each individual hosts.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;V/r&lt;/P&gt;&lt;P&gt;Ghost&lt;/P&gt;</description>
      <pubDate>Mon, 05 May 2025 19:49:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Attempting-to-write-a-search-to-find-all-CrowdStrike-agents-that/m-p/745519#M241467</guid>
      <dc:creator>Ghost</dc:creator>
      <dc:date>2025-05-05T19:49:33Z</dc:date>
    </item>
    <item>
      <title>Re: Attempting to write a search to find all CrowdStrike agents that are installed on the hosts in our environment</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Attempting-to-write-a-search-to-find-all-CrowdStrike-agents-that/m-p/745521#M241469</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/309869"&gt;@Ghost&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Its generally not advisable to run index=* if you can avoid it - do you know where you crowdstrike data is being ingested, and are you able to confirm that you have access to it?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":glowing_star:"&gt;🌟&lt;/span&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Did this answer help you?&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;If so, please consider:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Adding karma to show it was useful&lt;/LI&gt;&lt;LI&gt;Marking it as the solution if it resolved your issue&lt;/LI&gt;&lt;LI&gt;Commenting if you need any clarification&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Your feedback encourages the volunteers in this community to continue contributing&lt;/P&gt;</description>
      <pubDate>Mon, 05 May 2025 20:12:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Attempting-to-write-a-search-to-find-all-CrowdStrike-agents-that/m-p/745521#M241469</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2025-05-05T20:12:00Z</dc:date>
    </item>
    <item>
      <title>Re: Attempting to write a search to find all CrowdStrike agents that are installed on the hosts in our environment</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Attempting-to-write-a-search-to-find-all-CrowdStrike-agents-that/m-p/745526#M241471</link>
      <description>&lt;P&gt;i do have access to it its under index=falcon with a &lt;SPAN&gt;sourcetype="crowdstrike:events:sensor or crowdstrike*". Just trying to find a full proof way to view 100% of the hosts that have the agent installed with each of the hosts source IP. if I could get a true and false statement saying no crowdstrike&amp;nbsp; agent is installed on the list that would be great. But sadly im not that versed at Splunkfu.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 05 May 2025 20:26:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Attempting-to-write-a-search-to-find-all-CrowdStrike-agents-that/m-p/745526#M241471</guid>
      <dc:creator>Ghost</dc:creator>
      <dc:date>2025-05-05T20:26:14Z</dc:date>
    </item>
  </channel>
</rss>

