Deployment Architecture

Splunk SOAR in Cloud Environment

Rjdeleon
New Member

Does Splunk SOAR operate in the cloud, or just on-premises?

Labels (1)
0 Karma

garias_splunk
Splunk Employee
Splunk Employee

SOAR can operate on Premises, that is called "Splunk SOAR (On-premises)"
https://docs.splunk.com/Documentation/Phantom/5.0.1/PhantomIsNowSOAR/SplunkPhantomisnowSplunkSOAR

or in Splunk Cloud Environment, that is called "Splunk SOAR (Cloud) Service"

https://docs.splunk.com/Documentation/SOAR/current/ServiceDescription/SplunkSOARService

Even when the binaries tend to be the same, in the Cloud environment, versions are released more often and some of them will become onPremises version as well.

 

0 Karma

ryansaunders
Explorer

The answer is right on the main Splunk SOAR website.  You can host on-prem or use Splunk's hosted cloud offering.

0 Karma
Get Updates on the Splunk Community!

Combine Multiline Logs into a Single Event with SOCK - a Guide for Advanced Users

This article is the continuation of the “Combine multiline logs into a single event with SOCK - a step-by-step ...

Everything Community at .conf24!

You may have seen mention of the .conf Community Zone 'round these parts and found yourself wondering what ...

Index This | I’m short for "configuration file.” What am I?

May 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with a Special ...