Security

Limitations for Splunk Cloud outgoing traffic

cfcsolutions
Engager

We will be using a Splunk app (https://splunkbase.splunk.com/app/4422/ disclaimer: we made this app) to send out alerts from Splunk Cloud instances.

  1. Is the free Splunk cloud trial limited somehow in outgoing traffic?
  2. Is there any difference with a non-trial version?
  3. Is there any settings/rules that we should do to allow this traffic?
  4. From which component would the traffic go out? This is useful for us to whitelist this traffic.
Tags (2)
0 Karma

felsherif_splun
Splunk Employee
Splunk Employee
  1. Same as licensed Splunk Cloud, 5% of daily ingest for optimal performance, check out the FAQ for more details too, https://docs.splunk.com/Documentation/SplunkCloud/latest/FAQs/FAQs#Splunk_Cloud_Free_Trial_FAQ
  2. Assuming your alerts app alerting on search results like other alerts, then the recommended search results egress through API or even gui again is no more than 5% of ingested data, check also Splunk Cloud service description https://docs.splunk.com/Documentation/SplunkCloud/latest/Service/SplunkCloudservice
  3. You may have to submit a Support request to open the API port on your Splunk Cloud stack
  4. Ensure SSL - TCP 443 and API - TCP 8089 are allowed at your end, and yes you could request whitelist via a Support ticket too
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Agent Mode Engaged! Enchaining Agentic Operations with Splunk AI Assistant 2.0

    Are you ready to transform how your team handles complex data requests? We invite you to our upcoming ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...