All Apps and Add-ons

CrowdStrike Falcon Endpoint Add-on: Support Search Head Cluster?

wryanthomas
Contributor

Hi there. Thanks for this add-on. We need to run it on Splunk Cloud w/ Search Head Cluster (SHC). But we are being told the add-on is not SHC compatible.

Can you please make it SHC-compatible?

DenM
Explorer

Hello,

No mention about Search Head cluster support in the doc from Crowdstrike. If you have a test environment you can test it. But i'm sure it's working on search head cluster, i have many apps in production with no mention for shc and it works perfectly.
Try to push the app with your deployer to the shc member (be careful to remove the inputs.conf file on the Search heads)

Refer to: https://docs.splunk.com/Documentation/Splunk/7.3.1/DistSearch/PropagateSHCconfigurationchanges

This app is supported by crowdstrike regarding to Splunk Base, you can ask directly to: integrations(at)crowdstrike(dot)com

Hope it helps,

0 Karma

wryanthomas
Contributor

Thanks DenM. I appreciate the reply. We have a fully managed Splunk Cloud SHC -- we can't install such apps on our own. That is, the interface we have will indicate whether it is deemed SHC compatible or not. If not, we can't install it ourselves. And if we ask Splunk and vetting suggests it's not SHC compatible, they won't install it without remediation.

0 Karma
Get Updates on the Splunk Community!

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...