Splunk Dev

How do I configure firewall when forwarding from on-premise to Cloud?

panderla
Loves-to-Learn Lots

I am building firewall policies to implement an on-premise Splunk Enterprise system and need to forward some data to a Splunk Cloud instance.

What communication ports are used?

0 Karma

mattymo
Splunk Employee
Splunk Employee

Hi Panderla,

There is an excellent answer available here:

https://answers.splunk.com/answers/153990/what-security-settings-do-i-need-to-setup-for-splunk-cloud...

In short, you need to allow your TCP port 9997 to the cloud indexers, which you can find/resolve from the splunk_forwarder_app in outputs.conf

- MattyMo
0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...