Splunk Cloud
Splunk Forwarders send data to Splunk Cloud rather than the legacy on-premises infrastructure.
The previous shortcuts are no longer supported. Access Splunk by using this link.
Emailed Splunk alerts originate from the “alerts@splunkcloud.com," please consider updating any Outlook rules you may have used previously for “cio-sem-admin@osu.edu“.
For any questions or concerns, please email otdi-logsupport@osu.edu.
Networking Changes
If you have Splunk forwarders or HECs deployed in your environment that do not have outbound access, please make the following changes to your firewalls:
- Forwarder ingestion:
- Action: Allow
- Destination IPs: 52.20.208.232, 13.216.131.231, 34.231.216.90
- Destination FQDNs: inputs[1-15].osu.splunkcloud.com
- Protocol: TCP
- Port(s): 9997
- HEC ingestion:
- Action: Allow
- BEFORE SEPTEMBER 12th Destination IPs: 13.222.48.142, 34.236.83.232, 34.196.17.253
- Destination IPs: 13.216.131.231,34.231.216.90,52.20.208.232
- Destination FQDNs:
- JSON-formatted events: https://http-inputs-osu.splunkcloud.com:443/services/collector/event
- Raw events: https://http-inputs-osu.splunkcloud.com:443/services/collector/raw
- Protocol: TCP
- Port(s): 443
- API/Management:
- Action: Allow
- Destination IPs: 3.210.129.179, 34.230.146.78, 3.209.185.131
- Destination FQDNs: https://osu.splunkcloud.com
- Protocol: TCP
- Port(s): 8089
Forwarder Upgrades
Splunk Cloud requires Universal Forwarders to be upgraded to 9.x.
The Log Management team will contact units that require upgrades. If your unit is not contacted, no action is required — though upgrading to the latest version provided is still encouraged.
You can find the list of forwarders via the OneDrive links below. Additionally, instructions to upgrade can be found in the Upgrading the Forwarder instructional guide.
For all currently supported operating systems, please upgrade your forwarder to 9.4:
- AMD64: splunkforwarder-9.4.4-linux-amd64.deb
- x86_64: splunkforwarder-9.4.4.x86_64.rpm
- Windows: splunkforwarder-9.4.4-windows-x64.msi
If you cannot upgrade to 9.4, please reach out to the Log Management team for alternatives.