Skip to content
fernet.consultores

Splunk Cloud

Splunk Cloud Architecture.

Design of the Splunk Cloud Platform architecture: indexes, retention, ingest paths, forwarders and access.

The problem we solve.

An improvised architecture shows up late: mixed indexes, retention that doesn't meet regulatory requirements, forwarders that saturate the network, or permissions that are too broad. Fixing it once the platform is in production costs far more than designing it right from the start.

What’s included.

  • Design of indexes, retention and archiving
  • Ingest paths from your network: Universal and Heavy Forwarders, HTTP Event Collector
  • Roles, permissions and authentication model
  • Apps and add-ons strategy
  • Architecture document reviewed with your team

How we work.

Five phases, always in the same order. Select each one to see what happens in it. In full projects they map onto the stages of our method.

We review your platform, your data sources, your searches and your licence consumption to know where you stand.

We design the solution on Splunk Cloud Platform: indexes, retention, ingest paths, apps and access controls.

We document indexes, retention, ingest paths, roles and apps, with diagrams and configuration templates ready to apply.

We review the design with security, networking and operations, and test the critical ingest paths before signing it off.

We measure usage, performance and cost after go-live and adjust what isn't adding value.

Technical capabilities.

  • Splunk Cloud Platform
  • Universal and Heavy Forwarder
  • HTTP Event Collector
  • Ingest Actions and Edge Processor
  • Admin Config Service
  • Dynamic Data Active Archive

Use cases.

First implementation

Start from a validated design instead of fixing things as you go.

Segmented networks

Get data to the cloud from networks without direct internet egress.

Retention requirements

Meet retention periods without paying for excess storage.

Benefits for your organisation.

  • Growth without forced redesigns
  • Retention aligned with your obligations
  • Minimal, auditable access
  • Less traffic and less useless data

Deliverables.

  • Architecture document
  • Data flow diagram
  • Index and retention matrix
  • Roles and permissions model

Frequently asked questions.

Do you also design the part that stays on our network?

Yes. Forwarders, routes, load balancing and proxies are part of the design, because that's where most problems appear.

What if we already have Splunk Cloud running?

We review the current architecture and propose changes that can be applied without stopping the service.

Do you use Edge Processor or Ingest Actions?

When they add value: they're used to filter, mask or route data before indexing. We decide based on your volumes and your requirements.

Shall we talk about Architecture?

Tell us about your situation. If this service is not what you need, we will tell you; if it is, we will propose a concrete first step.

Request this service