All Apps and Add-ons

CrowdStrike Falcon Event Streams Add-On: Inputs app

sfraine
New Member

Hi, we're hoping to onboard to Splunk these 2 event types from Crowdstrike:

CorrelationRuleDetectionSummaryEvent 
BehavioralRuleDetectionSummaryEvent

In our Splunk Dev environment we have upgraded the
CrowdStrike Falcon Event Streams Add-On: Inputs app up to 3.7.2. When we launch the app, and go to 'Create New Input' and search for them under 'Event Types', CorrelationRuleDetectionSummaryEvent is present there, but BehavioralRuleDetectionSummaryEvent is not, so cannot be onboarded.  Who can we go to for help to get this included?
Thanks!

Labels (2)
0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @sfraine 

The app only has the following inputs configured:

APIActivityAuditEvent
AuthActivityAuditEvent
AutomatedLeadSummaryEvent
CSPMIOAStreamingEvent
CSPMSearchStreamingEvent
CloudSecurityIOMEvent
CorrelationRuleDetectionSummaryEvent
CustomerIOCEvent
DataProtectionDetectionSummaryEvent
DetectionSummaryEvent
EppDetectionSummaryEvent
FalconActivityAuditEvent
FcsIoaDetectionSummaryEvent
FirewallMatchEvent
HashSpreadingEvent
IdentityProtectionEvent
IdpDetectionSummaryEvent
IncidentSummaryEvent
LoginAuditEvent
MobileDetectionSummaryEvent
ReconNotificationSummaryEvent
RemoteResponseSessionEndEvent
RemoteResponseSessionStartEvent
ScheduledReportNotificationEvent
UserActivityAuditEvent
XdrDetectionSummaryEvent

However there is an 'all' option - out of interest, if you select this do you get the BehavioralRuleDetectionSummaryEvent data? If so you might be able to modify your inputs.conf manually to set this input up with the BehavioralRuleDetectionSummaryEvent data.

Alternatively I would recommend opening a support case with CrowdStrike directly as they develop and support this add-on: https://supportportal.crowdstrike.com/

🌟 Did this answer help you? If so, please consider:

    • Adding karma to show it was useful
    • Marking it as the solution if it resolved your issue
    • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing.

sfraine
New Member

Thanks for getting back to me on this. 
Unfortunately the BehavioralRuleDetectionSummaryEvent data doesn't appear when I use 'all'. 
I'll probably end up opening a Crowdstrike support case. 

0 Karma

tscroggins
Champion

You can add tilde-delimited event type values to TA-crowdstrike-falcon-event-streams/local/inputs.conf:

[crowdstrike_event_streams://example]
...
event_types = ...~BehavioralRuleDetectionSummaryEvent

The Splunk add-on trails behind the CrowdStrike SIEM Connector (falconhoseclient) in supplied event types, but most or all should work.

I second contacting CrowdStrike support. In my experience (not an endorsement), they're open to fixes and improvements to their Splunk add-ons.

0 Karma

sfraine
New Member

Thanks for your reply.  Yeah ... I think I'll go down the Crowdstrike support route as suggested. 

0 Karma

tscroggins
Champion

You really can just add event types. I do this myself for parity with falconhoseclient. The code loops over them. Support will go the extra step of updating the UI and publishing a new add-on.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Automated Threat Analysis: Available in ES Premier

Automated Threat Analysis: Centralize and Accelerate Phishing Investigations in Splunk Enterprise ...

What’s New in Splunk AI: Volume 02

Welcome to the second edition of “What’s New in Splunk AI” where we look at the latest and greatest updates, ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...