Other Usage

Search Alerts - Securing SNS / Webhook alerts?

bswiftly
New Member

We would like to bubble up alerts from Splunk to our alert management platform.

I see there are a couple of options,   AWS SNS Topics, and a Webhook Alert.

With either of those there is a security issue, as it would require  us to open an API or SNS Topic to the world.

What I would like is in the case of SNS,  to know if there is an AWS Account or IP that I could restrict ingress?    For the webhook I guess it could only be an IP restriction from the splunk hosts.

Also - if there is a better option / add-on available to increase security here I would be interested.  I just haven't found anything other than "Observability Cloud" which we do not have a license for. 

Thanks! 

Labels (1)
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...