Every Envyously app installs into your existing on-prem Splunk — behind your firewall, no inbound ports opened, no public IP exposed. The only thing that ever leaves is a license check: one small outbound call to a Cloudflare-protected endpoint. Here's exactly how, and exactly what we'd need from you.
All three keep your Splunk on-prem and open zero inbound ports. You can start at Free and move up any time without reinstalling.
Download the app, drop it in $SPLUNK_HOME/etc/apps, restart. The dashboards run on the data you already index. Nothing leaves your network — there's no license call at all. This is your try-before-you-buy on your real data.
Buy a SKU → we email you a license key → you paste it into the app's Setup screen. Every 15 minutes the app makes one outbound HTTPS request to a single Cloudflare-fronted hostname to confirm the key is valid. That request carries only the key — never your event data. Premium detections and voice hunting switch on.
Want us to push content updates, run the Nova voice analyst against your data, or operate the whole thing for you? Install cloudflared — one small binary that dials outward to Cloudflare and builds a secure tunnel. We reach your Splunk through Cloudflare's network. You still open no inbound port and expose no public IP; every session is authenticated per-person through Cloudflare Access (your SSO). Revocable instantly, by you or by us.
Splunk Cloud won't let you drop an app in. Splunk reviews and approves every app and add-on before it can be installed, and index-time parsing changes are Splunk's to apply, not yours. That makes a DIY fix effectively impossible on Cloud — which is exactly why Cloud tenants are the most stuck. Three ways we serve them:
The cleanest option, and the one that sidesteps every install and vetting gate: we hand you a preconfigured Splunk search head — a Docker container, a VM image, or a small dedicated workstation — with all the parsing, detections, dashboards, and the Nova voice analyst already built in. You add it as a search peer to your Splunk (or, on Cloud, Splunk enables the peer), and the fixes apply at search time on our node. Your indexers are never modified, nothing is installed on your Splunk, and Splunk never has to approve an app.
Envyously does not query your events, does not copy your logs off your system, and does not share, sell, or retain any of your telemetry. The apps run inside your Splunk; the only thing that ever leaves is a license check. When you engage managed mode, the exact searches we run — and the promise that we neither retain nor share your data — are written into a Statement of Work you approve and sign via DocuSign before we touch anything. Scope in writing, signed both ways.
| Data | Leaves your network? | Detail |
|---|---|---|
| Your logs, events, PII, index data | Never | The app parses and detects inside your Splunk. We are not a cloud SIEM; your telemetry does not transit to us, ever. |
| License key | Tier 1+ | Sent on the 15-minute validation call. It's a random token bound to your subscription — not linked to your data. |
| Searches we run (Tier 2 only) | Opt-in | Only if you choose managed mode, and only through the authenticated, revocable Cloudflare Access tunnel you installed. |
Cloudflare sits in front of our endpoints so your outbound call terminates at a hardened, DDoS-protected edge — not a raw server. For managed mode, Cloudflare Tunnel means the connection is outbound-initiated from your side, so your firewall never has to accept an inbound connection or expose Splunk to the internet. It's the same model large enterprises use for zero-trust access.
If your Splunk has no internet at all, the free tier works completely offline. For premium detections on an air-gapped box, ask us about the offline license file — a signed, time-boxed key that validates with no network call.
Every .conf and Python file ships readable in the app folder — nothing is obfuscated. The only network call the app makes is the license check to one hostname; you can read the exact code (bin/envy_validate.py) before you install. Send it to your security team; that's encouraged.
No. Every connection is outbound-only. Tier 1 is a single outbound HTTPS call; Tier 2's tunnel is also outbound-initiated. Your inbound rules don't change.
No. The app runs inside your Splunk and processes your data locally. The only thing that ever leaves is the license key (Tier 1) or, if you opt into managed mode, the specific searches we run over your authenticated tunnel.
Yes. The free tier is the full set of dashboards running on your real, existing data — no key, no call, no commitment.
The free tier works fully offline. For premium on an air-gapped system, we provide an offline signed license file that needs no network call.
Cancel the subscription and the key stops validating; the app reverts to the free dashboards on its own. Nothing to uninstall, no data to migrate, no lock-in.
No and no. It's an app inside your Splunk. We never ingest, store, or resell your data.
Splunk Enterprise or Splunk Cloud 8.x+. The O365 Defender Pack layers on top of Splunk's own Splunk_TA_o365 (install that first) — it enhances, it doesn't replace.
A JSON body with your key and the app name. No hostnames, no user list, no events. You can read the request in bin/envy_validate.py.
You install one app, restart, and paste one key (~10 minutes). We build and maintain the parsing, detections, dashboards, and updates. In managed mode, we operate it end to end.
The free parsing + dashboards ship as a Splunk-Cloud-vetted, self-service app you can install yourself. The premium detections unlock with an offline signed license (no outbound call, passes Splunk's vetting). And for the full experience, managed mode needs nothing installed at all — we run it against your Cloud's search API. Cloud tenants are the most stuck by the underlying gap, so this is where managed pays off most.
Yes. Before any managed engagement we send a Statement of Work over DocuSign that names the exact scope, the specific searches we'll run, and our written commitment that we do not search beyond that scope, collect, retain, or share your data. Nothing starts until it's signed both ways.
$SPLUNK_HOME/etc/apps and restart Splunk (~10 min).cloudflared install command we provide.Read-only, non-invasive, done in an afternoon — we show you which pain points are live in your environment and hand you the fix. No connectivity required.
Book the free assessment