All Apps and Add-ons

Splunk Connect 4 Syslog - IDM

sunaryot
Explorer

Does anyone know if HEC endpoint can be configured directly onto the IDM so SC4S traffic can be sent to it? It is tailor made for Splunk Cloud but I have not read anything that says that in their documentation.

Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

The SC4S team recommends traffic be sent directly to HEC inputs on the indexers.

---
If this reply helps you, Karma would be appreciated.

sunaryot
Explorer

In our splunk cloud environment, we currently do not have any indexers deployed since we have an IDM and multiple HFs. It is strongly recommended that we send the traffic to the HEC endpoints configured directly on the indexers but would it work by configuring the HEC endpoint on Splunk Cloud?

0 Karma

richgalloway
SplunkTrust
SplunkTrust

If you have Splunk Cloud then you have indexers.  Configuring HEC input on Splunk Cloud puts the input on the indexers.

---
If this reply helps you, Karma would be appreciated.

s2_splunk
Splunk Employee
Splunk Employee

If you have a recently provisioned SplunkCloud stack, you have a HEC address provisioned and enabled for you already.

Your target HEC URL should be 

http-inputs-{yourstackname}.splunkcloud.com

You will find more documentation here

You should be able to send HEC traffic directly to this VIP address. If this doesn't work, please open a case with Splunk support.

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

Watch Now Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas     Do you ever feel ...