Hi Team,
We want to do the IP allowlist in Crowdstrike. So we want to know the ip address range in Splunk to communicate with Crowdstrike through Falcon Event Streams Add-on
@Vijayalakshmi - The Add-on uses CrowdStrike Event Stream API.
Here is what I found from Add-on's doc: https://www.crowdstrike.com/wp-content/uploads/2020/07/CrowdStrike-Falcon-Event-Streams-Add-on-Guide...
The current base URLs for OAuth2 Authentication per cloud are:
US Commercial Cloud : https://api.crowdstrike.com
US Commercial Cloud 2 : https://api.us-2.crowdstrike.com
US GovCloud : https://api.laggar.gcw.crowdstrike.com
EU Cloud : https://api.eu-1.crowdstrike.com
I don't IP list though. You can try searching in the CrowdStrike forum. Or ask to CrowdStrike customer support directly.
I hope this helps!!!
We are using IDM Splunk to hit the Crowdstrike Falcon Event Streams Add-on . Do we have any specific IP address range available for IDM Splunk Cloud?
We want the Splunk IP Address range, Can we get this from crowdstrike vendor?
Ohh Okay Sorry. I thought otherway around.
For that please check with Splunk cloud support team.
Thank you