-
Notifications
You must be signed in to change notification settings - Fork 0
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Merge pull request #4 from ZachChristensen28/docs/devel
version 1.0.1 updates
- Loading branch information
Showing
8 changed files
with
62 additions
and
5 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,32 @@ | ||
# Install | ||
|
||
!!! important | ||
This supporting add-on must be installed alongside Splunk Enterprise Security. | ||
|
||
For detailed information on where to install Splunk Apps/add-ons, including best practices, can be found at [Splunk Docs: About Installing Splunk add-ons](https://docs.splunk.com/Documentation/AddOns/released/Overview/Wheretoinstall) | ||
|
||
## Standalone Deployments (with Splunk ES) | ||
|
||
Install this add-on to the single instance. For more information see [Splunk Docs: Install add-on in a single-instance Splunk deployment](https://docs.splunk.com/Documentation/AddOns/released/Overview/Singleserverinstall) | ||
|
||
## Distributed Deployments | ||
|
||
Splunk Instance type | Supported | Required | Comments | ||
-------------------- | --------- | -------- | -------- | ||
Enterprise Security Search Head | Yes | Yes | Install this add-on to the Enterprise Security Search Head. | ||
Splunk Core Search Head (without ES) | No | No | Do not install on regular search heads. | ||
Indexers | No | No | Do not install on Indexers. | ||
Heavy Forwarders | No | No | Do not install on Heavy Forwarders. | ||
Universal Forwarders | No | No | Do not install on Universal Forwarders. | ||
|
||
The installation steps for deploying Apps/add-ons in a distributed environment can be found at [Splunk Docs: Install an add-on in a distributed Splunk deployment](https://docs.splunk.com/Documentation/AddOns/released/Overview/Distributedinstall) | ||
|
||
## Distributed Deployment Compatibility | ||
|
||
Distributed deployment feature | Supported | Comments | ||
------------------------------ | --------- | -------- | ||
Search Head Clusters | Yes | You can install this add-on to an Enterprise Security search head cluster. | ||
Indexer Clusters | No | Do not deploy this add-on to an Indexer cluster. | ||
Deployment Server | No | There is no need to use a deployment server to deploy this add-on. | ||
|
||
\* For more information, see Splunk's [documentation](https://docs.splunk.com/Documentation/AddOns/released/Overview/Installingadd-ons) on installing Add-ons. |
File renamed without changes.
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,5 @@ | ||
# Release history | ||
|
||
## v1.0.0 <small>August 25, 2022</small> | ||
|
||
- Initial Release |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,7 @@ | ||
# Troubleshooting | ||
|
||
There can be many issues when setting up a new app/add-on in Splunk. Below highlights the most common issues with this Add-on. Don't see your issue? Submit a new issue on [Github](https://github.com/ZachChristensen28/SA-CrowdstrikeDevices/issues). | ||
|
||
Issue | Description | Solution | ||
----- | ----------- | -------- | ||
Multiple asset merge | It is possible that some of your devices share a common mac address or another key field which will cause merging by default. | If Crowdstrike is your only asset source you can disable asset merge under global settings. See [Asset Merge Solution](./solution-guides/asset-merge) for more information. |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,6 @@ | ||
# Asset Merge | ||
|
||
It may be possible that your devices share a common mac address or another key field that is causing an erroneous merge of your assets. If Crowdstrike is your only data source for assets, you can disable asset merge in the global settings. | ||
|
||
1. In Enterprise Security navigate to Configure > Data Enrichment > Asset and Identity Management > Global Settings. | ||
1. Toggle off "Assets" under `Enable Merge for Assets or Identities`. |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters