
Built for Splunk Cloud HEC and search API source allow lists and customer-controlled HTTPS clients. QuotaGuard gives eligible clients two stable IPv4 sources to register as /32 entries while Splunk tokens, credentials, roles, and permissions remain in force.
QuotaGuard routes customer-controlled Splunk Cloud HEC and search API HTTPS traffic through the two fixed IPv4 addresses assigned to its subscription. Register both addresses as /32 entries in the applicable Splunk feature allow lists while existing HEC tokens, API credentials, roles, and permissions continue to control the approved client. QuotaGuard has provided static-IP proxy service since 2013.
- HTTP Client Setup: Add the QuotaGuard connection URL to an eligible application, configure its HTTP client to proxy the relevant Splunk Cloud HTTPS requests, and register both dashboard IPs. Creating and testing the Splunk allow-list policy is a separate cutover step.
- Feature-Scoped Enforcement: Use the hec list for HTTP Event Collector traffic on port 443 and search-api for automated search-head API traffic on port 8089. Add the two QuotaGuard addresses to every feature list used by that subscription.
- Separate Forwarder Path: Universal and heavy forwarders use raw TCP on port 9997 under the s2s feature. That traffic does not use the same HTTP client proxy setting and needs a separately supported TCP tunnel design for the actual forwarder runtime.
- Controlled Runtime Support: Use the HTTP path with customer-controlled applications, jobs, containers, functions, or services whose client supports an HTTP or HTTPS proxy. Do not assume one proxy setting applies to every hosting platform or Splunk client.
- Production-Grade Reliability: Each subscription receives two load-balanced static IPv4 addresses with health checks and automated failover. Add both to Splunk so either approved route can reach the protected feature.
- Shield for the Customer-to-Proxy Hop: QuotaGuard Shield encrypts the connection from the application to the proxy while preserving the application's HTTPS session to Splunk Cloud without decrypting its payload. Product selection does not make the Splunk environment compliant by itself.
Splunk default-state note: search-api is closed by default. search-ui is also closed by default on PCI and HIPAA stacks but open otherwise, while HEC and s2s remain open until restricted. FedRAMP High allow-list changes must go through Splunk Support.
