All Apps and Add-ons

TA Falcon FileVantage bug in version 2.1.0 - events merged -> proposal of fix

Path Finder

CrowdStrike Falcon FileVantage Technical Add-On

When the api return more than one event, the result in splunk is one event with the all jsons merged together making splunk json parsing to fail.

For the python code it is seem to be what was wished with the join here  :






            helper.log_info(f"{log_label}: Preparing to send: {len(event_data)} FileVantage events to Splunk index: {data_index}")
 -->           events = '\n'.join(json.dumps(line) for line in event_data)
            filevantage_data = helper.new_event(source=helper.get_input_type(), index=helper.get_output_index(), sourcetype=helper.get_sourcetype(), data=events)
            helper.log_info(f"{log_label}: Data for {len(event_data)} events from FileVantage successfully pushed to Splunk index: {data_index}")






So it is important to make a proper splunk props.conf to un-split events with a LINE_BREAKER :






splunk@ncesplkpoc01:~/etc/apps/TA_crowdstrike_falcon_filevantage$ cat local/props.conf 







Labels (1)
0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...