splunk_data_sources.tf 4.0 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103
  1. locals {
  2. # Source IPs for splunk data
  3. splunk_data_sources_default = []
  4. splunk_data_sources_exceptions = {
  5. mdr-prod-afs = [
  6. "170.248.172.0/23", # Corporate Network
  7. "20.190.250.137/32", # Azure: EastUS2_External_Access
  8. "52.232.227.197/32", # Azure: Azure US-East Palo
  9. "52.185.64.173/32", # Azure: CentralUS_External_Access
  10. "52.242.225.98/32", # Azure: Azure US-Central Palo 20200721
  11. "52.177.84.83/32", # Azure: Lab_External_Access
  12. ],
  13. mdr-prod-nga = [
  14. "199.16.64.3/32",
  15. ],
  16. mdr-prod-bas = [
  17. "52.61.137.158/32",
  18. ],
  19. mdr-prod-dgi = [
  20. "3.32.175.159/32",
  21. "15.200.13.143/32", # MSOCI-1776
  22. ],
  23. mdr-prod-ca-c19 = [
  24. "44.242.164.146/32",
  25. "44.234.190.14/32",
  26. "44.228.141.151/32",
  27. "18.215.158.202/32",
  28. "54.234.108.195/32",
  29. "34.228.38.91/32",
  30. "44.226.172.7/32", # 2022-06-22 From Ben Troglia WEST MSOCI-2214
  31. "52.24.211.95/32",
  32. "52.35.39.247/32",
  33. "3.226.9.146/32", # 2022-06-22 From Ben Troglia EAST MSOCI-2214
  34. "44.207.196.144/32",
  35. "44.207.241.26/32",
  36. ],
  37. afs-mdr-prod-c2-gov = [
  38. "170.248.172.0/23", # legacy afs_whitelist
  39. "20.190.250.137/32", # legacy afs_azure_whitelist: EastUS2_External_Access
  40. "52.232.227.197/32", # legacy afs_azure_whitelist: Azure US-East Palo
  41. "52.185.64.173/32", # legacy afs_azure_whitelist: CentralUS_External_Access
  42. "52.242.225.98/32", # legacy afs_azure_whitelist: Azure US-Central Palo 20200721
  43. "52.177.84.83/32", # legacy afs_azure_whitelist: Lab_External_Access
  44. "199.16.64.3/32", # legacy nga_whitelist
  45. "54.205.60.17/32", #FRTIB ALIGHT
  46. "52.206.203.98/32", #FRTIB ALIGHT
  47. "34.233.188.131/32", #FRTIB ALIGHT
  48. "34.214.247.125/32", #FRTIB ALIGHT2
  49. "44.235.174.214/32", #FRTIB ALIGHT2
  50. "52.89.203.9/32", #FRTIB ALIGHT2
  51. "52.61.113.202/32", #FRTIB VDI
  52. "15.200.226.57/32", #FRTIB CMPS
  53. "52.61.137.158/32", #BAS-Commerce CMPS
  54. "34.223.59.103/32", # CA-C19
  55. "44.234.190.14/32", # CA-C19
  56. "44.228.141.151/32", # CA-C19
  57. "18.215.158.202/32", # CA-C19
  58. "54.234.108.195/32", # CA-C19
  59. "34.228.38.91/32", # CA-C19
  60. "3.32.175.159/32", # DGI
  61. "15.200.13.143/32", # DGI
  62. "3.221.245.113/32", # FRTIB Chaos us-east-1
  63. "34.237.100.242/32", # FRTIB Chaos us-east-1
  64. "35.172.75.107/32", # FRTIB Chaos us-east-1
  65. "54.164.205.89/32", # FRTIB Chaos us-east-1
  66. "54.209.105.32/32", # FRTIB Chaos us-east-1
  67. "54.224.69.136/32", # FRTIB Chaos us-east-1
  68. "34.237.183.65/32", # FRTIB Chaos prod us-east-1
  69. "34.227.214.27/32", # FRTIB Chaos prod us-east-1
  70. "3.232.76.136/32", # FRTIB Chaos prod us-east-1
  71. ],
  72. mdr-prod-frtib = [
  73. "52.61.113.202/32",
  74. "54.205.60.17/32", # 2021-05-04 From John Conrad john.conrad.2@alight.com
  75. "52.206.203.98/32",
  76. "34.233.188.131/32",
  77. "15.200.226.57/32", # 2021-07-12 From "Nguyen, Brian A." <brian.a.nguyen@accenturefederal.com>
  78. "34.214.247.125/32", # 2022-01-20 From John Conrad john.conrad.2@alight.com
  79. "44.235.174.214/32",
  80. "52.89.203.9/32",
  81. "3.221.245.113/32", # FRTIB Chaos us-east-1
  82. "34.237.100.242/32", # FRTIB Chaos us-east-1
  83. "35.172.75.107/32", # FRTIB Chaos us-east-1
  84. "54.164.205.89/32", # FRTIB Chaos us-east-1
  85. "54.209.105.32/32", # FRTIB Chaos us-east-1
  86. "54.224.69.136/32", # FRTIB Chaos us-east-1
  87. "34.237.183.65/32", # FRTIB Chaos prod us-east-1
  88. "34.227.214.27/32", # FRTIB Chaos prod us-east-1
  89. "3.232.76.136/32", # FRTIB Chaos prod us-east-1
  90. ],
  91. afs-mdr-test-c2-gov = [
  92. "170.248.172.0/23", # ?
  93. "20.190.250.137/32", # ?
  94. "52.232.227.197/32", # ?
  95. "52.185.64.173/32", # ?
  96. "52.242.225.98/32", # ?
  97. "52.177.84.83/32", # ?
  98. "199.16.64.3/32", #?
  99. "99.56.213.129/32", # Fred Damstra's Home IP - For testing
  100. ],
  101. }
  102. splunk_data_sources = lookup(local.splunk_data_sources_exceptions, var.account_name, local.splunk_data_sources_default)
  103. }