Splunk SOAR

What is best practice for the HEC endpoint(s) for the "Phantom Remote Search" app in a clustered environment?

jeffrey_berry
Path Finder

What is best practice for the HEC endpoint(s) for the "Phantom Remote Search" app in a clustered environment?

Per the instructions in the url below for configuring the "Phantom Remote Search" app in a distributed environment, the HEC endpoint(s) are implied to be indexer server(s).

https://docs.splunk.com/Documentation/PhantomRemoteSearch/1.0.14/PhantomRemoteSearch/Connecttodistri...

Our environment uses clustered indexers. Can a heavy forwarder with a HEC endpoint be used to externalize search of a Phantom environment instead of the HEC endpoint(s) being on the indexer(s)?

Labels (2)
Tags (1)
0 Karma

phanTom
SplunkTrust
SplunkTrust

@jeffrey_berry I suspect you have found the answer by now? However for anyone else looking at this question, YES it is totally plausible to use HFWs as an interim HEC point. I have done this a few times at Splunk Cloud customers as they already had HFW route to the Cloud secured and we just piggy-backed rather than punching another hole out of the network to the cloud indexers. 

0 Karma
Get Updates on the Splunk Community!

Fall Into Learning with New Splunk Education Courses

Every month, Splunk Education releases new courses to help you branch out, strengthen your data science roots, ...

Super Optimize your Splunk Stats Searches: Unlocking the Power of tstats, TERM, and ...

By Martin Hettervik, Senior Consultant and Team Leader at Accelerate at Iver, Splunk MVPThe stats command is ...

How Splunk Observability Cloud Prevented a Major Payment Crisis in Minutes

Your bank's payment processing system is humming along during a busy afternoon, handling millions in hourly ...