Skip to main content
Question

Splunk cloud integartion with SecOps SOAR

  • December 23, 2025
  • 1 reply
  • 65 views

Nagarjuna11
Forum|alt.badge.img+5

Hi All,

Just wanted to know if we are integrating splunk cloud with Secops SOAR do we need to allow the Ingress & Egress IP & Port : 8089 at the firewall level?

1 reply

Eoved
Forum|alt.badge.img+8
  • Bronze 2
  • December 23, 2025

Hello,
There are two supported methods, pull‑based and push‑based.
If you use the pull‑based method, you will need the following network requirement:
“Network access to Splunk API from Google SecOps to Splunk: allow traffic over port 8089.”
This method is available from the SecOps Marketplace.

Since you mentioned you are using Splunk Cloud, I think you can use the cloud‑to‑cloud native push‑based integration.
Using this method, the Splunk app performs API calls to Google SecOps to add a new case. To use this method, you need to generate a Google SecOps API key and add the Google SecOps URI in the app configuration.
There is no need to make any changes in your firewall configuration.

You can read more here:
https://docs.cloud.google.com/chronicle/docs/soar/marketplace-integrations/splunk