This feature is available as an add-on for the Honeycomb Enterprise plan.
Please contact your Honeycomb account team for details.
The Crowdstrike FDR source consumes S3 event notifications for object creation events (s3:ObjectCreated:*) and emits the S3 object as the string body of a log record. This source is similar to the generic S3 Event source. It expects SQS notifications sent from the Crowdstrike FDR platform.
Supported Platforms
Platform
Supported
Linux
✓
Windows
✓
macOS
✓
Kubernetes Gateway
✓
Available in the Bindplane Distro for OpenTelemetry Collector v1.76.4+.
Prerequisites
An AWS account with access to S3 and SQS.
An SQS queue configured to receive S3 event notifications.