Getting Data In

HEC / Webhook / Signed Event Webhook, OAuth

wellsjp
Loves-to-Learn Lots

We use HEC to ingest data from multiple sources but are starting to see the requirement for OAuth and other security features on webhooks.  Does anyone know if it is on the roadmap to support this?  Our current example is using a webhook from sendgrid.

https://www.twilio.com/docs/sendgrid/for-developers/tracking-events/event

 

 

Labels (2)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

I'm sorry but I fail to understand how authenticating the sending side to the HEC receiver or signing the requests is supposed to protect the confidentiality of PII.

The thing here would be to verify the identity of the receiver (most probably using TLS mechnisms) and use encryption for the transport channel.

OAuth is (can be) used for authenticating the sender and signing is (can be) used for integrity/non-repudiation.

So what problem are you trying to solve?

0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @wellsjp 

I personally havent seen anything on a roadmap for this - I would recommend submitting an idea at https://ideas.splunk.com/ - once you've done that let us know the link/Ref and I will upvote it too!

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

0 Karma
Get Updates on the Splunk Community!

See Splunk Platform & Observability Innovations at Cisco Live EMEA

Hi Splunkers, Learn about what’s next for Splunk Platform at Cisco Live EMEA.  Data silos are a big challenge ...

The OpenTelemetry Certified Associate (OTCA) Exam

What’s this OTCA exam? The Linux Foundation offers the OpenTelemetry Certified Associate (OTCA) credential to ...

From Manual to Agentic: Level Up Your SOC at Cisco Live

Welcome to the Era of the Agentic SOC   Are you tired of being a manual alert responder? The security ...