Skip to content

Release notes for the Splunk Add-on for CrowdStrike FDR

Version 3.2.0 of the Splunk Add-on for CrowdStrike FDR was released . It is compatible with the following software, CIM versions, and platforms.

Component Description
Splunk platform versions 10.6.x, 10.5.x, 10.4.x, 10.3.x, 10.2.x, 10.1.x, 10.0.x, 9.4.x, 9.3.x
CIM 8.x
Platforms Platform independent
Vendor Products Crowdstrike FDR

New features

Version 3.2.0 of the Splunk Add-on for CrowdStrike FDR includes the following changes:

  • Added observability metrics for the CrowdStrike FDR ingestion flow. The add-on records emitted event counts and byte counts while allowing ingestion to continue if observability is unavailable.
  • Disabled the Shutdown input after each processed data file (per_file_exec) setting for managed S3 consumer inputs, removed the option from the input form, and changed the default input interval to 30 seconds.

Fixed issues

Version 3.2.0 of the Splunk Add-on for CrowdStrike FDR contains the following, if any, issues.

Known issues

Version 3.2.0 of the Splunk Add-on for CrowdStrike FDR contains the following, if any, issues.

Upgrade information

When you upgrade from version 3.0.x or 3.1.x, existing managed consumer input stanzas are preserved. If an existing stanza contains per_file_exec = 1, version 3.2.0 overrides the setting to 0 at runtime and runs the consumer in persistent mode. The supported interval range is 1 through 300 seconds, and the default interval for new managed consumer inputs is 30 seconds.

Version 3.2.0 explicitly selects the Python 3.9 runtime while maintaining support for Python 3.9 and Python 3.13. No configuration changes are required during upgrade.

After upgrading and restarting Splunk, complete the following steps:

  1. Go to the CrowdStrike FDR add-on, open the Inputs page, and open a managed S3 consumer input.
  2. Verify that Splunk Web displays version 3.2.0 and that the Shutdown input after each processed data file checkbox is no longer visible. If both changes are visible, no refresh action is required.
  3. If the previous version or checkbox is still displayed, perform a hard refresh using Cmd + Shift + R on macOS or Ctrl + Shift + R on Windows or Linux, and check the managed S3 consumer input again.
  4. If the old content remains visible, open https://<host>:<port>/<locale>/debug/refresh and select Refresh.
  5. Return to the CrowdStrike FDR add-on, open the Inputs page and the managed S3 consumer input, and verify the changes again.
  6. If the old content is still displayed, open https://<host>:<port>/<locale>/_bump and select Bump version to refresh Splunk Web’s cached static resources. This action does not change the installed add-on version.
  7. Repeat the hard refresh using the applicable keyboard shortcut, and confirm that version 3.2.0 and the updated managed S3 consumer form are displayed.

See Customization options and caching in the Splunk Enterprise documentation.

Third-party software attributions

Version 3.2.0 adds native Linux runtime components to support observability. The add-on includes grpcio 1.80.0 for both supported Python 3.9 and Python 3.13 Linux runtimes, and protobuf 6.33.6 for the supported Linux runtimes.

Third-party software attributions for the Splunk Add-on for CrowdStrike FDR