Skip to main content

CollectorsCloud Collectors Administration Guide

Choose the Right Splunk Collector

For increased flexibility, there are two Splunk collectors available on Exabeam Security Operations Platform that you can use depending on your type of Splunk deployment. Choose the appropriate collector based on your deployment specifications.

Source

Deployment

Collector Recommendation

Limitations

Splunk On-Premises

(Existing or new deployments)

  • Advanced Analytics i62 and i63 releases, Data Lake, Exabeam Security Operations Platform

  • Existing Site Collector deployments that collect logs from on-premises Splunk via Site Collector or New Deployment

Use Site Collector to set up Splunk Collector.

  • Maximum supported EPS per Site Collector is 15K.

  • Site Collector does not support historical fetch (ingestion of past events).

Splunk Cloud

(Existing deployment)

Advanced Analytics i62 releases

Continue using Advanced Analytics Splunk Fetch

No changes required until Advanced Analytics i63 migration time.

  • Advanced Analytics i62 releases

  • Desired EPS > 7K (more than the current Advanced Analytics Splunk Fetch limit)

Migrate to use the Splunk Cloud Collector.

Historical fetch is not required for migration.

  • Historical ingestion is not supported in this deployment, as Advanced Analytics does not currently consume historic data via UIP to build models.

  • Advanced Analytics does not currently consume historic data via Syslog to build models.

Splunk Cloud

(New deployment)

  • Advanced Analytics i63 releases

  • Exabeam Fusion, Exabeam Security Investigation, and Exabeam Security Analytics licenses

Configure the Splunk Cloud Collector

  • Historical ingestion is not supported in this deployment, as Advanced Analytics does not currently consume historic data via UIP to build models.

  • Search or SaaS Data Lake

  • Exabeam Security Log Management and Exabeam SIEM licenses

Configure the Splunk Cloud Collector

The Splunk Cloud Collector supports historical fetch (ingestion of past events) up to 30 days.

To ingest historical events, choose the threshold in which you want to include events by setting the Ingest From date. After the data ingestion starts, you cannot modify the Ingest From date.