Splunk Cloud Platform

What is the IP Address range in Splunk for Add-on integration?

Vijayalakshmi
Observer

Hi Team,

 

We want to do the IP allowlist in Crowdstrike. So we want to know the ip address range in Splunk to communicate with Crowdstrike through Falcon Event Streams Add-on

Labels (1)
0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

@Vijayalakshmi - The Add-on uses CrowdStrike Event Stream API. 

Here is what I found from Add-on's doc: https://www.crowdstrike.com/wp-content/uploads/2020/07/CrowdStrike-Falcon-Event-Streams-Add-on-Guide...

The current base URLs for OAuth2 Authentication per cloud are:
US Commercial Cloud : https://api.crowdstrike.com
US Commercial Cloud 2 : https://api.us-2.crowdstrike.com
US GovCloud : https://api.laggar.gcw.crowdstrike.com
EU Cloud : https://api.eu-1.crowdstrike.com

 

I don't IP list though. You can try searching in the CrowdStrike forum. Or ask to CrowdStrike customer support directly.

 

I hope this helps!!!

0 Karma

Vijayalakshmi
Observer

We are using IDM Splunk to hit the Crowdstrike Falcon Event Streams Add-on . Do we have any specific IP address range available for IDM Splunk Cloud?

We want the Splunk IP Address range, Can we get this from crowdstrike vendor?

0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

Ohh Okay Sorry. I thought otherway around.

For that please check with Splunk cloud support team.

0 Karma

Vijayalakshmi
Observer

Thank you

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...