Splunk® Business Flow (Legacy)

Admin Manual

Splunk Business Flow is no longer available for purchase as of June 20, 2020. Customers who have already purchased Business Flow will continue to have support and maintenance per standard support terms for the remainder of contractual commitments.

How does the SBF hybrid architecture work?

Splunk Business Flow (SBF) uses a hybrid on-premises and hosted architecture. The user interface is served from the SBF Hosted Environment, and event processing occurs on your on-premises Splunk Enterprise deployment. To use Splunk Business Flow, your local Splunk search head and browser must be connected to the internet. Your local Splunk search head must have outbound access to the SBF Hosted Environment and your browser must be also able to access the SBF Hosted Environment, so that you can register the SBF application and access the user interface. You can facilitate access between the local search head and SBF Hosted Environment by allowing direct connections, adding a allow rule to your network configuration, or configuring a proxy. To set up an HTTPS proxy server, see Customize proxy settings in sbf.conf.

The following diagram shows a high level overview of the SBF architecture.
The SBF event processing occurs on your on-premises splunk deployment. Journey metadata is stored in the SBF Hosted Environment. The SBF UI is served from a browser. The browser must be able to connect to your search head.

How the SBF hybrid architecture affects releases

The hybrid architecture allows SBF to release new features, and fix issues without an on-premises update facilitated by a Splunk admin.

Last modified on 11 August, 2020
SBF concepts and terminology   What metadata is stored in the SBF Hosted Environment?

This documentation applies to the following versions of Splunk® Business Flow (Legacy): -Latest-


Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters