Onboard CrowdStrike data
Use Data Manager to onboard CrowdStrike data source.
Before you create a CrowdStrike input, complete the prerequisites Prerequisites for CrowdStrike data.
Use Data Manager to onboard CrowdStrike data source. The onboarding process guides you through selecting event types, configuring prerequisites, and setting up data routing parameters.
After successful onboarding, the CrowdStrike input begins ingesting event data from the configured SQS queue and forwarding it to the specified Splunk index. You can view the deployment status and manage the input through the Data Manager interface.
Select an input name and the select the Open in Search button to open the Search tab in Splunk Cloud Platform and further analyze the promote data. For more information about the search options, see Exploring the Search views.