Splunk Enterprise Security

How to get a Splunk Cloud Enterprise Security adaptive response (ping) to run on a local HF/UF/SH?

chaker
Contributor

Running Enterprise Security on Splunk Cloud, how can I get an adaptive response such as a ping to run on a local HF/UF/SH?

Labels (1)
Tags (1)
1 Solution

chaker
Contributor

chaker
Contributor

esix_splunk
Splunk Employee
Splunk Employee

Currently there is no direct fix for this. Splunk Cloud customers can currently run AR on other cloud based services, or you can create your own AR that would connect back to your onpremise deployment.

The later option does require a vetting process, and does have to adhere to guidelines as outlined here : http://dev.splunk.com/view/app-cert/SP-CAAAE85

One of the key take aways here, is that any type of outbound communication from Splunk Cloud has to be over SSL, and any credentials use for authentication cannot be stored in clear text.

I'd recommend building your integration via the Splunk Addon Builder (TA Builder) : https://splunkbase.splunk.com/app/2962/

Cheers

starcher
Influencer

ES adaptive responses run on the ES search head. Not remotely executed on other systems.

0 Karma

chaker
Contributor

How does a Splunk Cloud customer, run adaptive responses on their internal network?

0 Karma
Get Updates on the Splunk Community!

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...