AWS Cloudwatch logs ingestion to splunk using hec

62 Views Asked by At

AWS Cloudwatch logs can be delivered to Splunk using hec where Splunk instance is a SaaS instance. The solution uses kinesis firehose to deliver the logs to Splunk hec. My question is on the Splunk side we need to whitelist the entire AWS region CIDR (us-east-1 in our case). AWS us-east-1 CIDRs are 1000+. What is the best solution? should we whitelist the Splunk hec end point to the internet?

0

There are 0 best solutions below