All Apps and Add-ons

Kenesis Firehose and Splunk HECs

sjsoto
Observer

Does the use of HECs require traversing the public internet to get data into Splunk? Example, if my customer was the government and the data passed through Firehose into Splunk is to not touch the internet. 

Labels (1)
0 Karma

dmacintosh_splu
Splunk Employee
Splunk Employee

I think there are some more questions that need to be asked around the requirements. Splunk Enterprise(if so, hosted where?) or Splunk Cloud? If it is Splunk Cloud, I imagine FedRAMP/GovCloud might be required?

In either case, I believe that the data stream from Firehose to Splunk is encrypted if configured properly, whether it traverses the public internet is another question.

0 Karma
Get Updates on the Splunk Community!

See just what you’ve been missing | Observability tracks at Splunk University

Looking to sharpen your observability skills so you can better understand how to collect and analyze data from ...

Weezer at .conf25? Say it ain’t so!

Hello Splunkers, The countdown to .conf25 is on-and we've just turned up the volume! We're thrilled to ...

How SC4S Makes Suricata Logs Ingestion Simple

Network security monitoring has become increasingly critical for organizations of all sizes. Splunk has ...