Skip to content

Releases: splunk/SA-CrowdstrikeDevices

SA-CrowdstrikeDevices v1.1.5

09 Oct 00:35
63270fc
Compare
Choose a tag to compare
Info Description
SA-CrowdstrikeDevices v1.1.5 - Splunkbase
Splunk Enterprise Security Version (Required) 8.x | 7.x | 6.x
Crowdstrike Devices Add-on (Required) 3.x
Add-on has a web UI This add-on does not contain views.

Version 1.1.5 by @ZachTheSplunker in #69

New

  • Added CSV lookup for ES to use.
  • Added Serial Number to category field - closes feature request #67

Improved

  • Disabled KVstore replication to improve performance.
  • Increased batch size of KVstore lookup to improve performance.
  • Removed type definition for KVstore fields.

Full Changelog: v1.1.4...v1.1.5

SA-CrowdstrikeDevices v1.1.4

13 Dec 05:58
71fde46
Compare
Choose a tag to compare
Info Description
SA-CrowdstrikeDevices v1.1.4 - Splunkbase
Splunk Enterprise Security Version (Required) 7.x | 6.x
Crowdstrike Devices Add-on (Required) 3.x
Add-on has a web UI This add-on does not contain views.

What's Changed

Version 1.1.4 by @ZachTheSplunker in #66

  • Added managed configurations for Splunk Enterprise Security to control the retention of lookup file --> Schedule Search
  • Deprecating use of the search macro "sa_crowdstrike_retention" and the corresponding saved search.

Full Changelog: v1.1.3...v1.1.4

SA-CrowdstrikeDevices v1.1.3

08 Dec 05:50
9325618
Compare
Choose a tag to compare
Info Description
SA-CrowdstrikeDevices v1.1.3 - Splunkbase
Splunk Enterprise Security Version (Required) 7.x | 6.x
Crowdstrike Devices Add-on (Required) 3.x
Add-on has a web UI This add-on does not contain views.

What's Changed

Version 1.1.3 by @ZachTheSplunker in #65

  • Added managed configurations for Splunk Enterprise Security to control retention of lookup file --> Schedule Search
  • Deprecating use of the search macro "sa_crowdstrike_retention" and the corresponding saved search.

Full Changelog: v1.1.2...v1.1.3

SA-CrowdstrikeDevices v1.1.2

01 Dec 23:54
1cac894
Compare
Choose a tag to compare
Info Description
SA-CrowdstrikeDevices v1.1.2 - Splunkbase
Splunk Enterprise Security Version (Required) 7.x | 6.x
Crowdstrike Devices Add-on (Required) 3.x
Add-on has a web UI This add-on does not contain views.

What's Changed

  • Splunkworks compatibility

Full Changelog: v1.1.1...v1.1.2

SA-CrowdstrikeDevices v1.1.1

20 Apr 05:12
Compare
Choose a tag to compare
Info Description
SA-CrowdstrikeDevices 1.1.1 - Splunkbase | GitHub
Splunk Enterprise Security Version (Required) 7.x | 6.x
Crowdstrike Devices Add-on (Required) 3.x
Add-on has a web UI This add-on does not contain views.

What's Changed

  • Hotfix for incorrect regex on priority field - #58
  • New format for the category field by @ZachChristensen28:
    • The cs_ prefix has been removed from many fields.
    • Spaces have been added for easier readability.

Full Changelog: v1.0.5...v1.1.1

SA-CrowdstrikeDevices v1.1.0

27 Mar 03:20
4ce4c96
Compare
Choose a tag to compare
Info Description
SA-CrowdstrikeDevices 1.1.0 - Splunkbase | GitHub
Splunk Enterprise Security Version (Required) 7.x | 6.x
Crowdstrike Devices Add-on (Required) 3.x
Add-on has a web UI This add-on does not contain views.

What's Changed

  • New format for the category field by @ZachChristensen28:
    • The cs_ prefix has been removed from many fields.
    • Spaces have been added for easier readability.

Full Changelog: v1.0.5...v1.1.0

SA-CrowdstrikeDevices v1.0.5

20 Dec 18:13
749d99a
Compare
Choose a tag to compare
Info Description
SA-CrowdstrikeDevices 1.0.5 - Splunkbase | GitHub
Splunk Enterprise Security Version (Required) 7.x | 6.x
Crowdstrike Devices Add-on (Required) 3.x
Add-on has a web UI No, this add-on does not contain views.

What's Changed

Full Changelog: v1.0.4...v1.0.5

SA-CrowdstrikeDevices v1.0.4

22 Nov 22:22
b56e7b8
Compare
Choose a tag to compare
Info Description
SA-CrowdstrikeDevices 1.0.4 - Splunkbase | GitHub
Splunk Enterprise Security Version (Required) 7.x | 6.x
Crowdstrike Devices Add-on (Required) 3.x
Add-on has a web UI No, this add-on does not contain views.

What's Changed

Full Changelog: v1.0.3...v1.0.4

SA-CrowdstrikeDevices v1.0.3

20 Sep 18:59
bd67d4b
Compare
Choose a tag to compare
Info Description
SA-CrowdstrikeDevices 1.0.3 - Splunkbase | GitHub
Splunk Enterprise Security Version (Required) 7.x | 6.x
Crowdstrike Devices Add-on (Required) 3.x
Add-on has a web UI No, this add-on does not contain views.

New

  • added cleanup search to remove old/stale devices (#18).
  • added search macro for device retention period (#18).

Updated

  • updated collection to include last seen field (#18).
  • updated lookup generating search to include last time seen (#18).

Full Changelog: v1.0.2...v1.0.3

SA-CrowdstrikeDevices v1.0.2

08 Sep 14:50
2d79d50
Compare
Choose a tag to compare
Info Description
SA-CrowdstrikeDevices 1.0.2 - Splunkbase | GitHub
Splunk Enterprise Security Version (Required) 7.x | 6.x
Crowdstrike Devices Add-on (Required) 3.x
Add-on has a web UI No, this add-on does not contain views.

New

  • added first_seen, last_seen, and last_updated to category field (#8).
  • added site_name to existing bunit field (#13).

Updated

  • Changed app logo background to transparent.

Fixed

  • Updated saved search to preserve hosts with multiple IP/MAC addresses (#11).