<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Connect 4 Syslog - IDM in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Connect-4-Syslog-IDM/m-p/545908#M65249</link>
    <description>&lt;P&gt;If you have Splunk Cloud then you have indexers.&amp;nbsp; Configuring HEC input on Splunk Cloud puts the input on the indexers.&lt;/P&gt;</description>
    <pubDate>Mon, 29 Mar 2021 18:09:34 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2021-03-29T18:09:34Z</dc:date>
    <item>
      <title>Splunk Connect 4 Syslog - IDM</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Connect-4-Syslog-IDM/m-p/545872#M65244</link>
      <description>&lt;P&gt;Does anyone know if HEC endpoint can be configured directly onto the IDM so SC4S traffic can be sent to it? It is tailor made for Splunk Cloud but I have not read anything that says that in their documentation.&lt;/P&gt;</description>
      <pubDate>Mon, 29 Mar 2021 15:22:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Connect-4-Syslog-IDM/m-p/545872#M65244</guid>
      <dc:creator>sunaryot</dc:creator>
      <dc:date>2021-03-29T15:22:35Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Connect 4 Syslog - IDM</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Connect-4-Syslog-IDM/m-p/545882#M65246</link>
      <description>&lt;P&gt;The SC4S team recommends traffic be sent directly to HEC inputs on the indexers.&lt;/P&gt;</description>
      <pubDate>Mon, 29 Mar 2021 16:03:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Connect-4-Syslog-IDM/m-p/545882#M65246</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-03-29T16:03:12Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Connect 4 Syslog - IDM</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Connect-4-Syslog-IDM/m-p/545889#M65247</link>
      <description>&lt;P&gt;In our splunk cloud environment, we currently do not have any indexers deployed since we have an IDM and multiple HFs. It is strongly recommended that we send the traffic to the HEC endpoints configured directly on the indexers but would it work by configuring the HEC endpoint on Splunk Cloud?&lt;/P&gt;</description>
      <pubDate>Mon, 29 Mar 2021 16:33:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Connect-4-Syslog-IDM/m-p/545889#M65247</guid>
      <dc:creator>sunaryot</dc:creator>
      <dc:date>2021-03-29T16:33:03Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Connect 4 Syslog - IDM</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Connect-4-Syslog-IDM/m-p/545897#M65248</link>
      <description>&lt;P&gt;If you have a recently provisioned SplunkCloud stack, you have a HEC address provisioned and enabled for you already.&lt;/P&gt;&lt;P&gt;Your target HEC URL should be&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;http-inputs-{yourstackname}.splunkcloud.com&lt;/LI-CODE&gt;&lt;P&gt;You will find more documentation &lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Data/UsetheHTTPEventCollector#HEC_and_managed_Splunk_Cloud" target="_self"&gt;here&lt;/A&gt;.&amp;nbsp;&lt;/P&gt;&lt;P&gt;You should be able to send HEC traffic directly to this VIP address. If this doesn't work, please open a case with Splunk support.&lt;/P&gt;</description>
      <pubDate>Mon, 29 Mar 2021 17:16:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Connect-4-Syslog-IDM/m-p/545897#M65248</guid>
      <dc:creator>s2_splunk</dc:creator>
      <dc:date>2021-03-29T17:16:59Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Connect 4 Syslog - IDM</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Connect-4-Syslog-IDM/m-p/545908#M65249</link>
      <description>&lt;P&gt;If you have Splunk Cloud then you have indexers.&amp;nbsp; Configuring HEC input on Splunk Cloud puts the input on the indexers.&lt;/P&gt;</description>
      <pubDate>Mon, 29 Mar 2021 18:09:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Connect-4-Syslog-IDM/m-p/545908#M65249</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-03-29T18:09:34Z</dc:date>
    </item>
  </channel>
</rss>

