Security

Limitations for Splunk Cloud outgoing traffic

cfcsolutions
Engager

We will be using a Splunk app (https://splunkbase.splunk.com/app/4422/ disclaimer: we made this app) to send out alerts from Splunk Cloud instances.

  1. Is the free Splunk cloud trial limited somehow in outgoing traffic?
  2. Is there any difference with a non-trial version?
  3. Is there any settings/rules that we should do to allow this traffic?
  4. From which component would the traffic go out? This is useful for us to whitelist this traffic.
Tags (2)
0 Karma

felsherif_splun
Splunk Employee
Splunk Employee
  1. Same as licensed Splunk Cloud, 5% of daily ingest for optimal performance, check out the FAQ for more details too, https://docs.splunk.com/Documentation/SplunkCloud/latest/FAQs/FAQs#Splunk_Cloud_Free_Trial_FAQ
  2. Assuming your alerts app alerting on search results like other alerts, then the recommended search results egress through API or even gui again is no more than 5% of ingested data, check also Splunk Cloud service description https://docs.splunk.com/Documentation/SplunkCloud/latest/Service/SplunkCloudservice
  3. You may have to submit a Support request to open the API port on your Splunk Cloud stack
  4. Ensure SSL - TCP 443 and API - TCP 8089 are allowed at your end, and yes you could request whitelist via a Support ticket too
Get Updates on the Splunk Community!

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...