Getting CS logs via streaming api, and send it to LogScale Community Edition. Logs are sent every minute.
Japanese document is here.
Create API ID and Secret with the following scope.
Event streams: read
Save the following text as config.env and modify it.
CS_CLIENT_ID=XXXXXXXXXXXXXXXXXXXXXXXXXXXX
CS_CLIENT_SECRET=XXXXXXXXXXXXXXXXXXXXXXXXXXXX
CS_APIURL=https://api.crowdstrike.com
STREAM_APPID=cs-stream-logscale-connector
LS_URL=https://cloud.community.humio.com/api/v1/ingest/hec/raw
LS_INGEST_TOKEN=XXXXXXXXXXXXXXXXXXXXXXXXXXXX
PROCESS_CHECK_INTERVAL=60
# Option: You can specify an offset to start retrieving events from the specific offset.
CS_STREAM_OFFSET=
Basic command
docker run -d --env-file [config.env path] --name cslc prex55/cs-stream-logscale-connector:[tag]
Example
docker run -d --env-file ./config.env --name cslc prex55/cs-stream-logscale-connector:2.1
docker logs -f cslc
Mon Dec 19 00:19:30 UTC 2022 --- Query offset -
Mon Dec 19 00:19:30 UTC 2022 --- getting oauth2 token
curl: (22) The requested URL returned error: 401 Unauthorized
Mon Dec 19 00:19:31 UTC 2022 --- getting streaming url
curl: (22) The requested URL returned error: 401 Unauthorized
config.env. If you believe there is no another application, this is a temporary error; wait 30 minutes and this error should go away.jq: error (at <stdin>:1): Cannot iterate over null (null)
Content type
Image
Digest
sha256:4f09541ec…
Size
61.2 MB
Last updated
over 3 years ago
docker pull prex55/cs-stream-logscale-connector:2.1