Raised a support case and they suggested to install splunk stream app. This is exactly what I got:
Yes interaction with Splunk cloud to On-prem is possible, we need to use stream app for this purpose. Please refer below splunk document to know how it works and verify whether it suites your requirement. However, based on how this work you might need to architect your environment to achieve.
https://docs.splunk.com/Documentation/StreamApp/7.1.3/DeployStreamApp/DeployStreaminSplunkCloud
https://docs.splunk.com/Documentation/StreamApp/7.1.3/DeployStreamApp/SetupStream
https://docs.splunk.com/Documentation/StreamApp/7.1.3/DeployStreamApp/ConfigureStreamForwarder
Similar way I can use HEC to send data right?
... View more