Splunk SOAR (f.k.a. Phantom)

What is best practice for the HEC endpoint(s) for the "Phantom Remote Search" app in a clustered environment?

jeffrey_berry
Path Finder

What is best practice for the HEC endpoint(s) for the "Phantom Remote Search" app in a clustered environment?

Per the instructions in the url below for configuring the "Phantom Remote Search" app in a distributed environment, the HEC endpoint(s) are implied to be indexer server(s).

https://docs.splunk.com/Documentation/PhantomRemoteSearch/1.0.14/PhantomRemoteSearch/Connecttodistri...

Our environment uses clustered indexers. Can a heavy forwarder with a HEC endpoint be used to externalize search of a Phantom environment instead of the HEC endpoint(s) being on the indexer(s)?

Labels (2)
Tags (1)
0 Karma

phanTom
SplunkTrust
SplunkTrust

@jeffrey_berry I suspect you have found the answer by now? However for anyone else looking at this question, YES it is totally plausible to use HFWs as an interim HEC point. I have done this a few times at Splunk Cloud customers as they already had HFW route to the Cloud secured and we just piggy-backed rather than punching another hole out of the network to the cloud indexers. 

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...