Terraform Cloud for Splunk setup instructions
HashiCorp Terraform Cloud customers can integrate with Splunk® using the official Terraform Cloud for Splunk app to understand Terraform Cloud operations. Audit logs from Terraform Cloud are regularly pulled into Splunk, immediately giving visibility into key platform events within the predefined dashboards. Identify the most active policies, significant changes in resource operations, or filter actions by specific users within your organization. The app can be used with Splunk Cloud and Splunk Enterprise.
Note: Audit trails are available in Terraform Cloud Plus Edition. Refer to Terraform Cloud pricing for details. The Audit Trails API is not available for Terraform Enterprise.
Access and support for the Terraform Cloud for Splunk app requires audit logging, which is available in Terraform Cloud Plus Edition.
There are no special prerequisites for Splunk Cloud users.
Note: This app is currently not supported on a clustered deployment of Splunk Enterprise.
In order for the Terraform Cloud for Splunk app to function properly, it must be able to make outbound requests over HTTPS (TCP port 443) to the Terraform Cloud application APIs. This may require perimeter networking as well as container host networking changes, depending on your environment. The IP ranges are documented in the Terraform Cloud IP Ranges documentation. The services which run on these IP ranges are described in the table below.
|app.terraform.io||tcp/443, HTTPS||Outbound||Polling for new audit log events via the Terraform Cloud API|
The current release of the Terraform Cloud for Splunk app supports the following versions:
- Splunk Platform: 8.0 and later
- CIM: 4.3 and later
- Install the Terraform Cloud for Splunk app via Splunkbase
- Splunk Cloud users should consult the latest instructions on how to use IDM with cloud-based add-ons within the Splunk documentation.
- Click "Configure the application"
- Generate an Organization token within Terraform Cloud
- Click "complete setup"
Once configured, you’ll be redirected to the Splunk search interface with the pre-configured Terraform Cloud dashboards. Splunk will begin importing and indexing the last 14 days of audit log information and populating the dashboards. This process may take a few minutes to complete.
To upgrade to a new version of the Terraform Cloud for Splunk app, repeat the installation and configuration steps above.
Terraform Cloud only retains 14 days of audit log information. If there are connectivity issues between your Splunk service and Terraform Cloud, Splunk will recover events from the last event received up to a maximum period of 14 days.