Release notes for the Splunk Add-on for CrowdStrike FDR¶
Version 3.2.0 of the Splunk Add-on for CrowdStrike FDR was released
| Component | Description |
|---|---|
| Splunk platform versions | 10.6.x, 10.5.x, 10.4.x, 10.3.x, 10.2.x, 10.1.x, 10.0.x, 9.4.x, 9.3.x |
| CIM | 8.x |
| Platforms | Platform independent |
| Vendor Products | Crowdstrike FDR |
New features¶
Version 3.2.0 of the Splunk Add-on for CrowdStrike FDR includes the following changes:
- Added observability metrics for the CrowdStrike FDR ingestion flow. The add-on records emitted event counts and byte counts while allowing ingestion to continue if observability is unavailable.
- Disabled the Shutdown input after each processed data file (
per_file_exec) setting for managed S3 consumer inputs, removed the option from the input form, and changed the default input interval to 30 seconds.
Fixed issues¶
Version 3.2.0 of the Splunk Add-on for CrowdStrike FDR contains the following, if any, issues.
Known issues¶
Version 3.2.0 of the Splunk Add-on for CrowdStrike FDR contains the following, if any, issues.
Upgrade information¶
When you upgrade from version 3.0.x or 3.1.x, existing managed consumer input stanzas are preserved. If an existing stanza contains per_file_exec = 1, version 3.2.0 overrides the setting to 0 at runtime and runs the consumer in persistent mode. The supported interval range is 1 through 300 seconds, and the default interval for new managed consumer inputs is 30 seconds.
Version 3.2.0 explicitly selects the Python 3.9 runtime while maintaining support for Python 3.9 and Python 3.13. No configuration changes are required during upgrade.
After upgrading and restarting Splunk, complete the following steps:
- Go to the CrowdStrike FDR add-on, open the Inputs page, and open a managed S3 consumer input.
- Verify that Splunk Web displays version 3.2.0 and that the Shutdown input after each processed data file checkbox is no longer visible. If both changes are visible, no refresh action is required.
- If the previous version or checkbox is still displayed, perform a hard refresh using
Cmd + Shift + Ron macOS orCtrl + Shift + Ron Windows or Linux, and check the managed S3 consumer input again. - If the old content remains visible, open
https://<host>:<port>/<locale>/debug/refreshand select Refresh. - Return to the CrowdStrike FDR add-on, open the Inputs page and the managed S3 consumer input, and verify the changes again.
- If the old content is still displayed, open
https://<host>:<port>/<locale>/_bumpand select Bump version to refresh Splunk Web’s cached static resources. This action does not change the installed add-on version. - Repeat the hard refresh using the applicable keyboard shortcut, and confirm that version 3.2.0 and the updated managed S3 consumer form are displayed.
See Customization options and caching in the Splunk Enterprise documentation.
Third-party software attributions¶
Version 3.2.0 adds native Linux runtime components to support observability. The add-on includes grpcio 1.80.0 for both supported Python 3.9 and Python 3.13 Linux runtimes, and protobuf 6.33.6 for the supported Linux runtimes.
Third-party software attributions for the Splunk Add-on for CrowdStrike FDR