Hi Team,
We are exploring the Splunk cloud. We need below clarification.
1) Is AWS Splunk Cloud instance supports common information model (CIM) ?
2) Is Splunk enterprise security included into AWS Splunk cloud license ?
3) Can we make the search api call from other application to get the AWS Splunk Cloud indexed data (CIM supported) ?
4) Can You provide a demo of AWS Splunk Cloud (Saas).
1) Yes.
2) No. ES is additional.
3) API calls to Splunk Cloud are allowed. You will have to contact Splunk Support to enable that feature.
4) Your Splunk account team can do that or you can sign up for a free trial of Splunk Cloud.
Thanks for response.