All Apps and Add-ons

Kenesis Firehose and Splunk HECs

sjsoto
Observer

Does the use of HECs require traversing the public internet to get data into Splunk? Example, if my customer was the government and the data passed through Firehose into Splunk is to not touch the internet. 

Labels (1)
0 Karma

dmacintosh_splu
Splunk Employee
Splunk Employee

I think there are some more questions that need to be asked around the requirements. Splunk Enterprise(if so, hosted where?) or Splunk Cloud? If it is Splunk Cloud, I imagine FedRAMP/GovCloud might be required?

In either case, I believe that the data stream from Firehose to Splunk is encrypted if configured properly, whether it traverses the public internet is another question.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

(view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...