<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Limitations for Splunk Cloud outgoing traffic in Security</title>
    <link>https://community.splunk.com/t5/Security/Limitations-for-Splunk-Cloud-outgoing-traffic/m-p/389500#M9512</link>
    <description>&lt;P&gt;We will be using a Splunk app (&lt;A href="https://splunkbase.splunk.com/app/4422/"&gt;https://splunkbase.splunk.com/app/4422/&lt;/A&gt; disclaimer: we made this app) to send out alerts from Splunk Cloud instances.&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;Is the free Splunk cloud trial limited somehow in outgoing traffic? &lt;/LI&gt;
&lt;LI&gt;Is there any difference with a non-trial version? &lt;/LI&gt;
&lt;LI&gt;Is there any settings/rules that we should do to allow this traffic?&lt;/LI&gt;
&lt;LI&gt;From which component would the traffic go out? This is useful for us to whitelist this traffic.&lt;/LI&gt;
&lt;/OL&gt;</description>
    <pubDate>Wed, 03 Apr 2019 12:30:21 GMT</pubDate>
    <dc:creator>cfcsolutions</dc:creator>
    <dc:date>2019-04-03T12:30:21Z</dc:date>
    <item>
      <title>Limitations for Splunk Cloud outgoing traffic</title>
      <link>https://community.splunk.com/t5/Security/Limitations-for-Splunk-Cloud-outgoing-traffic/m-p/389500#M9512</link>
      <description>&lt;P&gt;We will be using a Splunk app (&lt;A href="https://splunkbase.splunk.com/app/4422/"&gt;https://splunkbase.splunk.com/app/4422/&lt;/A&gt; disclaimer: we made this app) to send out alerts from Splunk Cloud instances.&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;Is the free Splunk cloud trial limited somehow in outgoing traffic? &lt;/LI&gt;
&lt;LI&gt;Is there any difference with a non-trial version? &lt;/LI&gt;
&lt;LI&gt;Is there any settings/rules that we should do to allow this traffic?&lt;/LI&gt;
&lt;LI&gt;From which component would the traffic go out? This is useful for us to whitelist this traffic.&lt;/LI&gt;
&lt;/OL&gt;</description>
      <pubDate>Wed, 03 Apr 2019 12:30:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Limitations-for-Splunk-Cloud-outgoing-traffic/m-p/389500#M9512</guid>
      <dc:creator>cfcsolutions</dc:creator>
      <dc:date>2019-04-03T12:30:21Z</dc:date>
    </item>
    <item>
      <title>Re: Limitations for Splunk Cloud outgoing traffic</title>
      <link>https://community.splunk.com/t5/Security/Limitations-for-Splunk-Cloud-outgoing-traffic/m-p/389501#M9513</link>
      <description>&lt;OL&gt;
&lt;LI&gt;Same as licensed Splunk Cloud, 5% of daily ingest for optimal performance, check out the FAQ for more details too, &lt;A href="https://docs.splunk.com/Documentation/SplunkCloud/latest/FAQs/FAQs#Splunk_Cloud_Free_Trial_FAQ"&gt;https://docs.splunk.com/Documentation/SplunkCloud/latest/FAQs/FAQs#Splunk_Cloud_Free_Trial_FAQ&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;Assuming your alerts app alerting on search results like other alerts, then the recommended search results egress through API or even gui again is no more than 5% of ingested data, check also Splunk Cloud service description &lt;A href="https://docs.splunk.com/Documentation/SplunkCloud/latest/Service/SplunkCloudservice"&gt;https://docs.splunk.com/Documentation/SplunkCloud/latest/Service/SplunkCloudservice&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;You may have to submit a Support request to open the API port on your Splunk Cloud stack&lt;/LI&gt;
&lt;LI&gt;Ensure SSL - TCP 443 and API - TCP 8089 are allowed at your end, and yes you could request whitelist via a Support ticket too&lt;/LI&gt;
&lt;/OL&gt;</description>
      <pubDate>Wed, 03 Apr 2019 16:51:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Limitations-for-Splunk-Cloud-outgoing-traffic/m-p/389501#M9513</guid>
      <dc:creator>felsherif_splun</dc:creator>
      <dc:date>2019-04-03T16:51:31Z</dc:date>
    </item>
  </channel>
</rss>

