Hardware and software requirements for the Splunk Add-in for CrowdStrike FDR
The modular input for Splunk Add-on for CrowdStrike FDR must be installed on a heavy forwarder, Inputs Data Manager (IDM), or search head. This lets you collect data and push it to a Splunk index.
Splunk Enterprise Victoria is supported for single-indexer configurations, but is not supported for search head clusters and distributed environments.
Splunk platform requirements
Because this add-on runs on the Splunk platform, all of the system requirements apply for the Splunk software on which you install Splunk Add-on for Crowdstrike FDR.
- For Splunk Enterprise system requirements: see System Requirements in the Splunk Enterprise Installation Manual.
- If you are managing on-premises forwarders to get data into Splunk Cloud, see System Requirements in the Splunk Enterprise Installation Manual, which includes information about forwarders.
- If you are using an IDM see Install an add-on in Splunk Cloud
About the Splunk Add-on for CrowdStrike
Installation and configuration overview for the Splunk Add-on for Crowdstrike FDR
This documentation applies to the following versions of Splunk® Supported Add-ons: released