Quick Start¶
Important
This supporting add-on must be installed alongside Splunk Enterprise Security. Ensure the prequisites have been completed before proceeding.
This add-on has a savedsearch and identity configuration input enabled by default.
Overview¶
- Updated default macro.
- Force Initial Build.
- Enable identity correlation.
- (optional) Disable existing identity sources.
- (optional) Update default savedsearch schedule.
Update default macro¶
Failure to update the macro to the correct setting will cause no identities to be available in Splunk Enterprise Security.
Macro | Default | Description |
---|---|---|
sa_crowdstrike_identities_index | index=crowdstrike | Index definition for CrowdStrike identity index. |
Update Macro Procedure¶
Update the index definition to the correct index that contains the crowdstrike:identities
sourcetype.
Perform one of the following:
- (recommended) Update via Splunk ES General Settings.
- Update via Macro Definition.
ES General Settings¶
option 1 (recommended option)
- (In Splunk Enterprise Security) Navigate to Configure > General > General Settings.
- From the "App" dropdown select
SA-CrowdStrikeIdentities
. - Update the SA-CrowdStrikeIdentities Index definition and click "Save."
Macro Definition¶
option 2
- Navigate to Settings > Advanced Search > Search Macros.
- From the "App" dropdown choose
SA-CrowdStrikeIdentities
. - Set the "Owner" dropdown to
any
. - Click the macro named
sa_crowdstrike_identities_index
to update the index definition.
Force Initial Build¶
The initial build of the CrowdStrike identities will not occur until the first scheduled runtime (see Update default savedsearch schedule). To force the initial build perform the following:
- Navigate to Settings > Searches, reports, and alerts.
- Set the "App" dropdown to
SA-CrowdStrikeIdentities
. - Set the "Owner" dropdown to
All
. - Click "Run" under actions for the search
CrowdStrike Identities Lookup - Gen
.
Note
The search will run in a new tab over the default time period of 60 minutes. Expand the time frame to a larger window if the number of identities in the last 60 minutes does not seem accurate. The default search is configured to run hourly to continually append new identities reported from CrowdStrike.
Enable asset correlation¶
Confirm asset correlation has been setup in Enterprise Security.
- Navigate to Enterprise Security > Configure > Data Enrichment > Asset and Identity Management.
- Switch to the "Correlation Setup" tab.
- Either enable for all sourcetypes (Recommended) or selectively by sourcetype.
- If you choose to enable select sourcetypes, ensure the
stash
sourcetype is also selected so Notable events will be enriched with asset information.
- If you choose to enable select sourcetypes, ensure the
- Save.
Disable existing identity sources¶
optional
It may be possible that you have existing Identity Lookups defined. If CrowdStrike is the main "source of truth" in your environment the existing lookups may no longer be needed.
Update default savedsearch schedule¶
optional
The default saved search runs on the 29th minute of every hour to update and continually build the CrowdStrike identities. To update the default schedule perform the following steps:
- Navigate to Settings > Searches, reports, and alerts.
- Set the "App" dropdown to
SA-CrowdStrikeIdentities
. - Set the "Owner" dropdown to
All
. - Click "Edit" under actions for the search
CrowdStrike Identities Lookup - Gen
. - Click "Edit Schedule" and update the schedule and necessary.