Splunk Cloud Platform

Splunk Cloud

rajveer005
Engager

Is there any difference between the splunk enterprise and splunk cloud's configuration. and how can i configure palo alto firewall and splunk cloud so Splunk cloud an ingest some data from palo alto firewall.

Tags (1)
0 Karma
1 Solution

nickhills
Ultra Champion

Fundamentally they are the exact same product, however there are a few differences in the level of access you have to some of the performance tuning elements, and of course you dont have direct access to the configuration files for Splunk Cloud.

Most settings can be managed via the Cloud UI, and for some specifc use cases you can ask Splunk Support to make changes which would need access to the files directly.

Most applictions and TA's can be deployed to both platforms, but there are some specialist applications which can not be deployed to Splunk cloud.

To collect data from PA, you install a heavy forwarder on site and install the PA-TA onto your heavy forwarder where you have full contol. Your HF then sends your log data to either Splunk Enterprise (on Prem) or Splunk Cloud.

If my comment helps, please give it a thumbs up!

View solution in original post

mydog8it
Builder

An alternative to installing the PA app on an HF is to send data from the PA to syslog and use a UF on the syslog server to send to SplunkCloud.

0 Karma

nickhills
Ultra Champion

Fundamentally they are the exact same product, however there are a few differences in the level of access you have to some of the performance tuning elements, and of course you dont have direct access to the configuration files for Splunk Cloud.

Most settings can be managed via the Cloud UI, and for some specifc use cases you can ask Splunk Support to make changes which would need access to the files directly.

Most applictions and TA's can be deployed to both platforms, but there are some specialist applications which can not be deployed to Splunk cloud.

To collect data from PA, you install a heavy forwarder on site and install the PA-TA onto your heavy forwarder where you have full contol. Your HF then sends your log data to either Splunk Enterprise (on Prem) or Splunk Cloud.

If my comment helps, please give it a thumbs up!
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Data Management Digest – September 2026

    Welcome to the September 2026 edition of Data Management Digest! September brought a fresh wave of ...

Federated Search for CloudWatch Unified Data Store Is Generally Available

As organizations modernize their cloud environments, AWS workloads generate more security, operational, and ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...