splunk-cloud-platform-shared-responsibility-model
splunk-cloud-platform-shared-responsibility-model
The Splunk Cloud Platform SaaS operates on a shared responsibility model to ensure the optimum customer
experience. This shared model can help relieve the customer’s operational burden as Splunk operates, manages and
controls the Splunk Cloud Platform service components, which includes services from our cloud service provider
partners, as needed. The nature of this shared responsibility provides customers flexibility and control of their
Splunk Cloud Platform environment. Splunk Cloud Platform provides a complete suite of self-service capabilities to
simplify actions customers can take as part of the shared responsibility model.
The following table helps customers better understand the distribution of responsibility for their Splunk Cloud
Platform service. Customer responsibility varies based on many factors, including use case, subscription type, and
the laws and regulations applicable to their organization. Therefore, the following table is for illustrative purposes
only and is not exhaustive. Please see Splunk Documentation for additional detail.
Application Splunk Supported Apps Splunk publishes the list of You ensure the latest compatible
Lifecycle and Add-Ons: These are Splunk-supported apps and version of the app available
apps and add-ons that add-ons on Splunkbase. In on Splunkbase is installed so
are available through addition, you are informed of any service updates are unblocked.
Splunkbase and marked incompatible apps that need to
as Splunk-supported. be upgraded prior to a service Be prepared for the possibility
update. that the data structures of
Splunk-supported apps and
Splunk reserves the right to add-ons may change. If app data
change app data models and models and data structures do
data structures to optimize change, you can adapt your use
usage of the apps. Splunk may case to the updated models and
deprecate Splunk-supported structures.
apps.
Private Apps: These are Splunk allows you to build, vet When you build your own
apps and add-ons that and install your private apps private apps or add-ons, you are
you build. or add-ons on Splunk Cloud responsible for all aspects of
Platform. Splunk maintains our the app's or add-on’s lifecycle,
cloud app vetting service to vet including planning, development,
your private apps and add-ons release and maintenance.
prior to installation. Splunk may Follow the app lifecycle best
make platform changes for practices as described in the
compliance and security-related Developer Guide for Splunk
changes. Cloud Platform and Splunk
Enterprise. Please be sure to
follow policies specific to Splunk
Cloud Platform.
SOLUTION GUIDE
Data Agent-based: Splunk Splunk makes available binaries You manage the full lifecycle of
Collection Forwarder (Splunk to and licenses required for Splunk- Splunk agents deployed in your
Splunk). to-Splunk data collection, such environment.
as for Splunk forwarders and
Pull-based: Data deployment server licenses, to You select which data is
Manager and add-ons help ensure compatibility and collected using the appropriate
with modular inputs, with ease of management at scale. mechanism. You configure this
scripted inputs and with data collection mechanism
apps. Splunk provides documentation based on your use case and
on best practices and Splunk-recommended best
example configurations for practices. You perform timely
data collection. In addition, updates of agent certificates
optional instructor-led and keep all configurations
education courses and Splunk up-to-date to ensure accurate
Professional Services are also collection of data.
available.
You monitor this data collection
Splunk maintains Splunk Cloud mechanism to ensure
Platform endpoints as well as successful forwarding of your
polling-based data collection data.
mechanisms.
As applicable for your
Splunk provides license usage subscription type, you ensure
information. your data collection usage
is in accordance with your
subscription entitlement.
REST-based API: Splunk Splunk maintains HEC data You select which data is
HTTP Event Collector collection mechanisms, collected using this mechanism.
(HEC) data collection including supported push-based You configure and monitor this
mechanisms, including data collection from data buses data forwarding mechanism
supported push-based and streaming solutions. based on your use case and
data collection from data Splunk-recommended best
buses and streaming practices.
solutions.
Data Index Management Splunk enforces retention You manage the lifecycle of data
Retention policies as defined by you on a through index management
per-index basis. settings, as well as the creation,
management and removal of
data indexes, summaries and
other acceleration mechanisms.
Data Storage Management Splunk applies data resiliency You select the best storage
Retention and backup policies in option available for your Splunk
(cont.) accordance with our Splunk Cloud Platform subscription, and
Cloud Platform Service Details. you manage these settings in
Splunk Web or REST-based API.
Splunk Cloud Platform elastically
expands to retain your data You ensure storage usage
per your retention settings. in accordance with your
In addition, we provide data subscription entitlement. If your
retention and storage usage Splunk Cloud Platform storage
telemetry to help you manage usage exceeds your storage
your Splunk Cloud Platform entitlement, you may incur a
subscription entitlement. true-up charge.
Network Splunk maintains ingest, login You ensure the public or private
Connectivity and search endpoints so they internet connectivity between
are reachable from the public all of your users (such as
internet, or on a case-by-case admins and end users) and the
basis, through a private network. Splunk Cloud Platform ingest,
This includes monitoring the login and search endpoints. In
availability of these endpoints. addition, ensure your IP allow
list configuration is updated to
Splunk will provide you with manage access to your Splunk
advanced notice in the rare Cloud Platform environment.
occurrence of a network
address change that impacts You ensure your outbound
the ingest, login and search firewall rules are promptly
endpoints. updated in the rare occurrence
of a network address change
that impacts the ingest, login
and search endpoints.
Search Splunk maintains the search You create your searches using
endpoints per the Splunk Cloud SPL, or using alternative ways
Platform SLA. In addition, to display and analyze data
we provide documentation graphically without composing
and best practices for SPL queries.
composing efficient Splunk
Search Processing Language You ensure your search load
(SPL) queries and creating is in accordance with the
dashboards. documented service limits.
Splunk, Splunk> and Turn Data Into Doing are trademarks and registered trademarks of Splunk Inc. in the United States and other countries.
All other brand names, product names or trademarks belong to their respective owners. © 2022 Splunk Inc. All rights reserved. 22-22220-Splunk-Cloud Platform Shared Responsibility Model-SG-101