Skip to main content
Question

Using cribl TCP source can we whitelist IP addresses

  • March 11, 2025
  • 1 reply
  • 97 views

Hey All,

Trying to setup TCP source to onboard our vendor saas logs in to our onprem splunk. With Cribl can we do IP whitelisting for the TCP source and allow only certain IPs instead of opening it up to public. My setup is onprem so want to see if there are possibilities available in the cribl side.

1 reply

Tony Reinke
  • Inspiring
  • March 11, 2025

In Sources > TCP, under Configure > Advanced Settings, there is a section "IP Allowlist Regex".

https://docs.cribl.io/stream/sources-tcp-raw/#advanced-settings

IP allowlist regex
: Regex matching IP addresses that are allowed to establish a connection. Defaults to .* (i.e,. all IPs).

887_1929a9b555d5406cae3d46768636e2cc.png