On This Page

Home / Stream/ Integrations/ Integrating with Other Services/ Splunk/Splunk Cloud Platform and BYOL Integrations

Splunk Cloud Platform and BYOL Integrations

The Splunk HTTP Event Collector (HEC) is the preferred method for integrating with the Splunk Cloud Platform. It’s easy to set up, offers superior compression, and efficiently load balances data across multiple indexers in a distributed Splunk environment. While Splunk-to-Splunk (S2S) can be used for specific scenarios, such as legacy integrations or granular data distribution, HEC generally provides a more straightforward and efficient integration process.

Cribl Stream provides multiple integrations for sending data to the Splunk Cloud Platform. The following table outlines the supported Cribl Stream Destinations and Splunk protocols for different Splunk Cloud Platform deployment scenarios:

Cribl Stream DestinationSplunk ProtocolSplunk Deployment
Splunk HEC DestinationSplunk HEC- Distributed Splunk Cloud Platform
- Bring Your Own License (BYOL) deployment (either in a non-Splunk cloud or on-prem)
Splunk Load Balanced DestinationS2S- Distributed Splunk Cloud Platform
- BYOL deployment
Splunk Single Instance DestinationS2S- Single-instance Splunk Cloud Platform (trial or smaller deployments)

For BYOL deployments, leverage the .pem and outputs.conf files already in use on your Splunk Universal Forwarders to maintain consistency and simplify the security setup. The Splunk documentation has detailed instructions on securing your Splunk indexers to ensure the overall security of your deployment.