Hi Everyone,
As per Chronicle documenation , we have 4 below pre built parsers. Would you please let me know the difference bewteen them ? I can see two parsers for the same category EDR.
Vendor / Product Category Ingestion label Format Latest Update
CrowdStrike Detection Monitoring | EDR | CS_DETECTS | JSON | 2023-07-21 View Change |
CrowdStrike Falcon | EDR | CS_EDR | JSON | 2023-12-22 View Change |
CrowdStrike Falcon Stream | Alerts | CS_STREAM | KV (LEEF) | 2022-07-18 View Change |
Crowdstrike IOC | IOC | CROWDSTRIKE_IOC | JSON | 2023-08-23 View Change |