All Apps and Add-ons

Ingest Zoom logs in Splunk Cloud without a Heavy Forwarder?


Is it possible to use Splunk Connect for Zoom in a managed Splunk Cloud environment without an on-prem Heavy Forwarder? As far as I'm aware, Zoom only supports webhook-based logging which isn't compatible with Splunk Cloud (for some reason). Using a Heavy Forwarder isn't an option but open to other workarounds if any exist.

Scenario is:
- Running a managed Splunk Cloud instance on version 7.2.9
- Running an Inputs Data Manager (IDM) instance on version 7.2.9
- No heavy forwarder

Labels (1)

Splunk Employee
Splunk Employee

Alternative is to use http event collector (HEC) raw endpoint directly along with allowQueryStringAuth setting. This will allow you to specify HEC token directly in the URL.

More info here

Note: On cloud you'll have to open a support ticket to set allowQueryStringAuth to true on your HEC endpoint

0 Karma


What route did you end up going?

0 Karma
Get Updates on the Splunk Community!

Registration for Splunk University is Now Open!

Are you ready for an adventure in learning?   Brace yourselves because Splunk University is back, and it's ...

Splunkbase | Splunk Dashboard Examples App for SimpleXML End of Life

The Splunk Dashboard Examples App for SimpleXML will reach end of support on Dec 19, 2024, after which no new ...

Understanding Generative AI Techniques and Their Application in Cybersecurity

Watch On-Demand Artificial intelligence is the talk of the town nowadays, with industries of all kinds ...