CrowdStrike Event Streams Data
In order to collect CrowdStrike’s Event Streams logs, the CrowdStrike Falcon Event Streams Technical Add-On is required for data parsing and field extraction.
There are two main components that need to be configured for the CrowdStrike Add-on:
-
Add Account:
-
Create New Input:
-
Refer to the CrowdStrike Resource Center: CrowdStrike Falcon Event Streams Add-On Guide for the Add-on’s configuration steps.