Falcon Next-Gen SIEM Data Sink

Most recent version: v2.0.1

Learn more about this Data sink type in this article.

v2.0.1

Released on 10/22/2025

  • Gzip compression is now always used.

v2.0.0

Released on 10/09/2025

  • Added 443 as default port

  • Added support for fields in json format

  • Changed raw Content-Type to text/plain

  • Removed "Splunk " token prefix and added "Bearer " if not present

  • Removed Splunk specific parameters (channel, host, index, source, sourcetype)

v1.0.2

Released on 09/10/2025

Initial version

Last updated

Was this helpful?