CrowdStrike API Logs Not Parsing #14103
-
Version2.4.110 Installation MethodNetwork installation on Ubuntu (unsupported) Descriptionother (please provide detail below) Installation TypeDistributed Locationon-prem with Internet access Hardware SpecsExceeds minimum requirements CPU16 RAM128 Storage for /500GB Storage for /nsm8TB Network Traffic Collectionspan port Network Traffic SpeedsLess than 1Gbps StatusYes, all services on all nodes are running OK Salt StatusNo, there are no failures LogsNo, there are no additional clues DetailHello all! I have connected my SO distributed deployment to CrowdStrike and I am ingesting CrowdStrike Alert and Host data via the API just fine. However, 'message' is not being parsed. After looking around at other posts, I found a few helpful commands:
It's like the ingested data is just skipping the ingest pipelines for CrowdStrike Alert and Host. I'm not sure where else to look and what else to try. Thank you for any help or pointers. Guidelines
|
Beta Was this translation helpful? Give feedback.
Replies: 1 comment 3 replies
-
Beta Was this translation helpful? Give feedback.
Ahh, looks like I was looking at my development instance of Security Onion. Yes, the host index template is missing. It is going to be fixed in the .120 release. My recommendation would be to wait until .120 so you can soup and then verify your logs are correctly parsed. If not please re-comment here and we can look closer. Sorry for the additional confusion!