EnvyPainPoints

Your Splunk stays where it is.
Your data never leaves your network.

Every Envyously app installs into your existing on-prem Splunk — behind your firewall, no inbound ports opened, no public IP exposed. The only thing that ever leaves is a license check: one small outbound call to a Cloudflare-protected endpoint. Here's exactly how, and exactly what we'd need from you.

Zero inboundYou open no firewall ports. All connectivity is outbound-only.
Your data stays putEvents, PII, indexes never transit to us. The app runs inside your Splunk.
~10 minutes of your timeInstall one app, restart, paste one key. We do the rest.
Fails safeLose connectivity and it reverts to the free dashboards. It never breaks.

Three ways to run it — pick your comfort level

All three keep your Splunk on-prem and open zero inbound ports. You can start at Free and move up any time without reinstalling.

Tier 0 · Free

Install & go — no key, no connectivity

Download the app, drop it in $SPLUNK_HOME/etc/apps, restart. The dashboards run on the data you already index. Nothing leaves your network — there's no license call at all. This is your try-before-you-buy on your real data.

  • Requires: nothing but your existing Splunk.
  • Connectivity: none.
Tier 1 · Licensed

One key, one outbound call

Buy a SKU → we email you a license key → you paste it into the app's Setup screen. Every 15 minutes the app makes one outbound HTTPS request to a single Cloudflare-fronted hostname to confirm the key is valid. That request carries only the key — never your event data. Premium detections and voice hunting switch on.

OUTBOUND 443 → app.envyously.com (Cloudflare edge) → license valid? → {tier, features} NO INBOUND. NO DATA. NO PUBLIC IP.
  • Firewall: outbound 443 to one hostname. Most environments already allow this. Egress-locked? Allowlist the single hostname (we supply it + the Cloudflare IP ranges).
  • Fails safe: if the check can't reach us, the app quietly reverts to the free dashboards. Premium simply pauses until connectivity returns — it never errors, never blocks your SOC.
Tier 2 · Managed / connected

We operate it — still zero inbound, via Cloudflare Tunnel

Want us to push content updates, run the Nova voice analyst against your data, or operate the whole thing for you? Install cloudflared — one small binary that dials outward to Cloudflare and builds a secure tunnel. We reach your Splunk through Cloudflare's network. You still open no inbound port and expose no public IP; every session is authenticated per-person through Cloudflare Access (your SSO). Revocable instantly, by you or by us.

  • Your work: run one install command we provide. That's it.
  • No trained SOC engineers required on your side. This work takes deep Splunk + Defender expertise — that's ours to carry, not yours to hire for.
  • This is the exact pattern we run in production today for a live customer.
Splunk Cloud

The walled garden — and why managed wins here

Splunk Cloud won't let you drop an app in. Splunk reviews and approves every app and add-on before it can be installed, and index-time parsing changes are Splunk's to apply, not yours. That makes a DIY fix effectively impossible on Cloud — which is exactly why Cloud tenants are the most stuck. Three ways we serve them:

  • Free parsing + dashboards: shipped as a Splunk-Cloud-vetted, self-service app that works entirely at search time (no index-time change), so your admins install it themselves from Splunkbase.
  • Premium content, no phone-home: the detections unlock with an offline signed license — a token your app verifies locally against a built-in key. Nothing leaves Cloud, nothing to allowlist, and it passes Splunk's app vetting.
  • Managed (recommended for Cloud): we run the detections, correlation, and voice from our side against your Cloud's search API — nothing to install, nothing for Splunk to approve. You get the outcomes; we carry the expertise.
Envy Node · the appliance

A Splunk search head we pre-build — it does the work, your indexers stay untouched

The cleanest option, and the one that sidesteps every install and vetting gate: we hand you a preconfigured Splunk search head — a Docker container, a VM image, or a small dedicated workstation — with all the parsing, detections, dashboards, and the Nova voice analyst already built in. You add it as a search peer to your Splunk (or, on Cloud, Splunk enables the peer), and the fixes apply at search time on our node. Your indexers are never modified, nothing is installed on your Splunk, and Splunk never has to approve an app.

  • Your one step: allow the node as a search peer and open the search path on your firewall. That's the whole integration.
  • Search-time parsing runs on the node — the o365 click fields, CIM tags, and detections are applied when the node queries your data, so the gap is fixed without touching your side.
  • This is the exact approach we already use to build and fix scheduled searches without Splunk's involvement.
  • Licensing lives on the node (it's ours) — nothing for you to paste or manage.
Our written commitment

We do not search, collect, or share your data.

Envyously does not query your events, does not copy your logs off your system, and does not share, sell, or retain any of your telemetry. The apps run inside your Splunk; the only thing that ever leaves is a license check. When you engage managed mode, the exact searches we run — and the promise that we neither retain nor share your data — are written into a Statement of Work you approve and sign via DocuSign before we touch anything. Scope in writing, signed both ways.

What leaves your network — and what never does

DataLeaves your network?Detail
Your logs, events, PII, index dataNeverThe app parses and detects inside your Splunk. We are not a cloud SIEM; your telemetry does not transit to us, ever.
License keyTier 1+Sent on the 15-minute validation call. It's a random token bound to your subscription — not linked to your data.
Searches we run (Tier 2 only)Opt-inOnly if you choose managed mode, and only through the authenticated, revocable Cloudflare Access tunnel you installed.

Why Cloudflare, specifically

Cloudflare sits in front of our endpoints so your outbound call terminates at a hardened, DDoS-protected edge — not a raw server. For managed mode, Cloudflare Tunnel means the connection is outbound-initiated from your side, so your firewall never has to accept an inbound connection or expose Splunk to the internet. It's the same model large enterprises use for zero-trust access.

Fully air-gapped Splunk?

If your Splunk has no internet at all, the free tier works completely offline. For premium detections on an air-gapped box, ask us about the offline license file — a signed, time-boxed key that validates with no network call.

Security review

Every .conf and Python file ships readable in the app folder — nothing is obfuscated. The only network call the app makes is the license check to one hostname; you can read the exact code (bin/envy_validate.py) before you install. Send it to your security team; that's encouraged.

Straight answers

Do I have to open a firewall port?

No. Every connection is outbound-only. Tier 1 is a single outbound HTTPS call; Tier 2's tunnel is also outbound-initiated. Your inbound rules don't change.

Does my log data leave my network?

No. The app runs inside your Splunk and processes your data locally. The only thing that ever leaves is the license key (Tier 1) or, if you opt into managed mode, the specific searches we run over your authenticated tunnel.

Can I try it before paying?

Yes. The free tier is the full set of dashboards running on your real, existing data — no key, no call, no commitment.

What if my Splunk can't reach the internet?

The free tier works fully offline. For premium on an air-gapped system, we provide an offline signed license file that needs no network call.

How do I cancel? Is there a rip-and-replace?

Cancel the subscription and the key stops validating; the app reverts to the free dashboards on its own. Nothing to uninstall, no data to migrate, no lock-in.

Is this a cloud SIEM? Do you resell my telemetry?

No and no. It's an app inside your Splunk. We never ingest, store, or resell your data.

What Splunk do I need?

Splunk Enterprise or Splunk Cloud 8.x+. The O365 Defender Pack layers on top of Splunk's own Splunk_TA_o365 (install that first) — it enhances, it doesn't replace.

What exactly does the license call send?

A JSON body with your key and the app name. No hostnames, no user list, no events. You can read the request in bin/envy_validate.py.

Who does the work — me or you?

You install one app, restart, and paste one key (~10 minutes). We build and maintain the parsing, detections, dashboards, and updates. In managed mode, we operate it end to end.

I'm on Splunk Cloud — can I even install this?

The free parsing + dashboards ship as a Splunk-Cloud-vetted, self-service app you can install yourself. The premium detections unlock with an offline signed license (no outbound call, passes Splunk's vetting). And for the full experience, managed mode needs nothing installed at all — we run it against your Cloud's search API. Cloud tenants are the most stuck by the underlying gap, so this is where managed pays off most.

Do we sign anything about data handling?

Yes. Before any managed engagement we send a Statement of Work over DocuSign that names the exact scope, the specific searches we'll run, and our written commitment that we do not search beyond that scope, collect, retain, or share your data. Nothing starts until it's signed both ways.

The whole checklist

What you do

What we do

Start with a free read of your own Splunk

Read-only, non-invasive, done in an afternoon — we show you which pain points are live in your environment and hand you the fix. No connectivity required.

Book the free assessment