All Apps and Add-ons

CrowdStrike Falcon Event Streams Add-On: Inputs app

sfraine
New Member

Hi, we're hoping to onboard to Splunk these 2 event types from Crowdstrike:

CorrelationRuleDetectionSummaryEvent 
BehavioralRuleDetectionSummaryEvent

In our Splunk Dev environment we have upgraded the
CrowdStrike Falcon Event Streams Add-On: Inputs app up to 3.7.2. When we launch the app, and go to 'Create New Input' and search for them under 'Event Types', CorrelationRuleDetectionSummaryEvent is present there, but BehavioralRuleDetectionSummaryEvent is not, so cannot be onboarded.  Who can we go to for help to get this included?
Thanks!

Labels (2)
0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @sfraine 

The app only has the following inputs configured:

APIActivityAuditEvent
AuthActivityAuditEvent
AutomatedLeadSummaryEvent
CSPMIOAStreamingEvent
CSPMSearchStreamingEvent
CloudSecurityIOMEvent
CorrelationRuleDetectionSummaryEvent
CustomerIOCEvent
DataProtectionDetectionSummaryEvent
DetectionSummaryEvent
EppDetectionSummaryEvent
FalconActivityAuditEvent
FcsIoaDetectionSummaryEvent
FirewallMatchEvent
HashSpreadingEvent
IdentityProtectionEvent
IdpDetectionSummaryEvent
IncidentSummaryEvent
LoginAuditEvent
MobileDetectionSummaryEvent
ReconNotificationSummaryEvent
RemoteResponseSessionEndEvent
RemoteResponseSessionStartEvent
ScheduledReportNotificationEvent
UserActivityAuditEvent
XdrDetectionSummaryEvent

However there is an 'all' option - out of interest, if you select this do you get the BehavioralRuleDetectionSummaryEvent data? If so you might be able to modify your inputs.conf manually to set this input up with the BehavioralRuleDetectionSummaryEvent data.

Alternatively I would recommend opening a support case with CrowdStrike directly as they develop and support this add-on: https://supportportal.crowdstrike.com/

🌟 Did this answer help you? If so, please consider:

    • Adding karma to show it was useful
    • Marking it as the solution if it resolved your issue
    • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing.

sfraine
New Member

Thanks for getting back to me on this. 
Unfortunately the BehavioralRuleDetectionSummaryEvent data doesn't appear when I use 'all'. 
I'll probably end up opening a Crowdstrike support case. 

0 Karma

tscroggins
SplunkTrust
SplunkTrust

You can add tilde-delimited event type values to TA-crowdstrike-falcon-event-streams/local/inputs.conf:

[crowdstrike_event_streams://example]
...
event_types = ...~BehavioralRuleDetectionSummaryEvent

The Splunk add-on trails behind the CrowdStrike SIEM Connector (falconhoseclient) in supplied event types, but most or all should work.

I second contacting CrowdStrike support. In my experience (not an endorsement), they're open to fixes and improvements to their Splunk add-ons.

0 Karma

sfraine
New Member

Thanks for your reply.  Yeah ... I think I'll go down the Crowdstrike support route as suggested. 

0 Karma

tscroggins
SplunkTrust
SplunkTrust

You really can just add event types. I do this myself for parity with falconhoseclient. The code loops over them. Support will go the extra step of updating the UI and publishing a new add-on.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Persistent Queue at TcpOut — One of Splunk's Most Practical Features

Splunk introduced persistent queueing at the tcpout layer as one of the most practical resilience features in ...

Skip the Awkward Silence: Have a .conf-ersation at .conf26

Picture this. You arrive at .conf26 already having your socializing and networking plans mapped out. No ...

Rethinking Zero Trust: From Product Purchases to Logical Control Evidence

Note: This post outlines a proposed architecture and serves as an interest check. If we secure commitments ...