All Apps and Add-ons

CrowdStrike Falcon Event Streams - Token Refresh Check alert

AlfieC
Engager

Hi Folks;

Has anyone had any luck with the new built in "Token Refresh Check" alert that comes with the CrowdStrike Falcon Event Streams TA (version 2.0.9+). This is now part of the TA to restart inputs if they become blocked / unstable (less than 2 events in an hour). We can prove the alert is triggering as we are getting emailed alerts but it doesn't seem to be restarting the inputs if no events are seen in the timeframe, so were having to still manually disable / enable the inputs. As far as we can tell everything is configured correctly.

Anyone have any luck with the alert?

Cheers

Labels (2)
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...