Splunk Enterprise

Splunk Crowdstrike Logs Ingestion

sahiltcs
Path Finder
Hello Team,
 
We have installed Crowd strike Add on 1.0.7 and ingested the logs via API in Splunk, Challenge we are facing every week logs are stop reporting to Splunk and manually we need to refresh the connection from Splunk, Can you please help why this issue is happened.
 
Is there any bug in Add on or do we need to set the limit in Crowdstrike add on to refresh the connection?
 
Thanks,
Sahil  
Labels (1)
0 Karma
Get Updates on the Splunk Community!

Detecting Brute Force Account Takeover Fraud with Splunk

This article is the second in a three-part series exploring advanced fraud detection techniques using Splunk. ...

Buttercup Games: Further Dashboarding Techniques (Part 9)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...

Buttercup Games: Further Dashboarding Techniques (Part 8)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...