Hi All,
I am looking to send a POST request from Splunk Cloud to start an EnCase forensic investigation which is running on-prem. So far the two options I see are to use the Webhook Alert Action or to create a POST Workflow Action.
I have configured a POST Workflow Action, but I am not seeing any traffic coming from Splunk Cloud back to my Firewall. I have opened the ip and port inbound from the Splunk Cloud Search Head through my FW. I am not seeing anything in the _internal logs on the SH. Any troubleshooting steps I can take?
Has any one gotten this to work in Splunk Cloud? Any suggestions welcome!
Other things to consider:
- There is a HF set up on prem that could be used to communicate with Splunk Cloud and send the request on the internal network
I am currently using HTTP to trigger the POST request. Does it need to be HTTPS from Splunk Cloud to EnCase? What port (443, 8089)?