Splunk SOAR (f.k.a. Phantom)

What is best practice for the HEC endpoint(s) for the "Phantom Remote Search" app in a clustered environment?

jeffrey_berry
Path Finder

What is best practice for the HEC endpoint(s) for the "Phantom Remote Search" app in a clustered environment?

Per the instructions in the url below for configuring the "Phantom Remote Search" app in a distributed environment, the HEC endpoint(s) are implied to be indexer server(s).

https://docs.splunk.com/Documentation/PhantomRemoteSearch/1.0.14/PhantomRemoteSearch/Connecttodistri...

Our environment uses clustered indexers. Can a heavy forwarder with a HEC endpoint be used to externalize search of a Phantom environment instead of the HEC endpoint(s) being on the indexer(s)?

Labels (2)
Tags (1)
0 Karma

phanTom
SplunkTrust
SplunkTrust

@jeffrey_berry I suspect you have found the answer by now? However for anyone else looking at this question, YES it is totally plausible to use HFWs as an interim HEC point. I have done this a few times at Splunk Cloud customers as they already had HFW route to the Cloud secured and we just piggy-backed rather than punching another hole out of the network to the cloud indexers. 

0 Karma
Get Updates on the Splunk Community!

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...

Updated Team Landing Page in Splunk Observability

We’re making some changes to the team landing page in Splunk Observability, based on your feedback. The ...