Instructions
- In Advanced Mode, converting SPL to CQL can generate intermediate output with uf (unknown fields).
- Map uf fields to relevant LogScale/NGSIEM fields and convert again to get final results.
- Conversion Log shows warnings and unsupported functionality.
- Manually validate and adjust queries when needed.
- Some commands are available only with premium support.
- With premium support, our team helps migrate from Splunk to CrowdStrike.
Product Walkthrough
SPL TO CQL
Advanced Mode
Input SPL
Output CrowdStrike CQL
Your converted CQL will appear here...
Field names and dataset references match your Falcon LogScale mappings.
→
Understands observability SPL patterns out of the box.Clean, schema aware CrowdStrike CQL.