Splunk Enterprise

public application to on-prem splunk enterprise, what's the best way to collect the logs?

faitken
New Member

Hi, 
What's a safe way for a public application to submit REST POST calls to an on-prem splunk enterprise instance?

Ideally I'm looking to do this
- Application makes a REST post call to URL with log entry as payload
- URL resolves to cloud vm
- cloud vm forwards to on-prem instance via VPN

I first thought of using the Universal Forwarded on the cloud vm but HEC is not supported.
Other than running a heavy forwarder on the cloud vm, is there a better way of doing this?
I've considered running my own API on the cloud vm as the forwarder but I'd prefer to go with something that is universally tested and hardened, ie. UF

Thank you

0 Karma
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...