Security

Limitations for Splunk Cloud outgoing traffic

cfcsolutions
Engager

We will be using a Splunk app (https://splunkbase.splunk.com/app/4422/ disclaimer: we made this app) to send out alerts from Splunk Cloud instances.

  1. Is the free Splunk cloud trial limited somehow in outgoing traffic?
  2. Is there any difference with a non-trial version?
  3. Is there any settings/rules that we should do to allow this traffic?
  4. From which component would the traffic go out? This is useful for us to whitelist this traffic.
Tags (2)
0 Karma

felsherif_splun
Splunk Employee
Splunk Employee
  1. Same as licensed Splunk Cloud, 5% of daily ingest for optimal performance, check out the FAQ for more details too, https://docs.splunk.com/Documentation/SplunkCloud/latest/FAQs/FAQs#Splunk_Cloud_Free_Trial_FAQ
  2. Assuming your alerts app alerting on search results like other alerts, then the recommended search results egress through API or even gui again is no more than 5% of ingested data, check also Splunk Cloud service description https://docs.splunk.com/Documentation/SplunkCloud/latest/Service/SplunkCloudservice
  3. You may have to submit a Support request to open the API port on your Splunk Cloud stack
  4. Ensure SSL - TCP 443 and API - TCP 8089 are allowed at your end, and yes you could request whitelist via a Support ticket too
Get Updates on the Splunk Community!

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to Officially Supported Splunk ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI! Discover how Splunk’s agentic AI ...