splunk_data_sources.tf 4.2 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364656667686970717273747576777879808182838485868788899091929394959697
  1. locals {
  2. # Source IPs for splunk data
  3. splunk_data_sources_default = []
  4. splunk_data_sources_exceptions = {
  5. mdr-prod-afs = [
  6. "170.248.172.0/23", # Corporate Network
  7. "20.190.250.137/32", # Azure: EastUS2_External_Access
  8. "52.232.227.197/32", # Azure: Azure US-East Palo
  9. "52.185.64.173/32", # Azure: CentralUS_External_Access
  10. "52.242.225.98/32", # Azure: Azure US-Central Palo 20200721
  11. "52.177.84.83/32", # Azure: Lab_External_Access
  12. ],
  13. mdr-prod-nga = [
  14. "199.16.64.3/32",
  15. ],
  16. mdr-prod-bas = [
  17. "52.61.137.158/32",
  18. ],
  19. mdr-prod-dgi = [
  20. "3.32.175.159/32",
  21. "15.200.13.143/32", # MSOCI-1776
  22. ],
  23. mdr-prod-ca-c19 = [
  24. "44.226.172.7/32", # ca-c19-splunk-ds-1 2022-06-22 From Ben Troglia WEST MSOCI-2214
  25. "52.24.211.95/32", # ca-c19-splunk-syslog-1
  26. "52.35.39.247/32", # ca-c19-splunk-syslog-2
  27. "3.226.9.146/32", # ca-c19-splunk-ds-2 2022-06-22 From Ben Troglia EAST MSOCI-2214
  28. "44.207.196.144/32", # ca-c19-splunk-syslog-3
  29. "44.207.241.26/32", # ca-c19-splunk-syslog-4
  30. ],
  31. afs-mdr-prod-c2-gov = [
  32. "170.248.172.0/23", # legacy afs_whitelist
  33. "20.190.250.137/32", # legacy afs_azure_whitelist: EastUS2_External_Access
  34. "52.232.227.197/32", # legacy afs_azure_whitelist: Azure US-East Palo
  35. "52.185.64.173/32", # legacy afs_azure_whitelist: CentralUS_External_Access
  36. "52.242.225.98/32", # legacy afs_azure_whitelist: Azure US-Central Palo 20200721
  37. "52.177.84.83/32", # legacy afs_azure_whitelist: Lab_External_Access
  38. "199.16.64.3/32", # legacy nga_whitelist
  39. "54.205.60.17/32", # FRTIB ALIGHT
  40. "52.206.203.98/32", # FRTIB ALIGHT
  41. "34.233.188.131/32", # FRTIB ALIGHT
  42. "34.214.247.125/32", # FRTIB ALIGHT2
  43. "44.235.174.214/32", # FRTIB ALIGHT2
  44. "52.89.203.9/32", # FRTIB ALIGHT2
  45. "52.61.113.202/32", # FRTIB VDI
  46. "15.200.226.57/32", # FRTIB CMPS
  47. "52.61.137.158/32", # BAS-Commerce CMPS
  48. "44.226.172.7/32", # ca-c19-splunk-ds-1 2022-06-22 From Ben Troglia WEST MSOCI-2214
  49. "52.24.211.95/32", # ca-c19-splunk-syslog-1
  50. "52.35.39.247/32", # ca-c19-splunk-syslog-2
  51. "3.226.9.146/32", # ca-c19-splunk-ds-2 2022-06-22 From Ben Troglia EAST MSOCI-2214
  52. "44.207.196.144/32", # ca-c19-splunk-syslog-3
  53. "44.207.241.26/32", # ca-c19-splunk-syslog-4
  54. "3.32.175.159/32", # DGI
  55. "15.200.13.143/32", # DGI
  56. "3.221.245.113/32", # FRTIB Chaos us-east-1
  57. "34.237.100.242/32", # FRTIB Chaos us-east-1
  58. "35.172.75.107/32", # FRTIB Chaos us-east-1
  59. "54.164.205.89/32", # FRTIB Chaos us-east-1
  60. "54.209.105.32/32", # FRTIB Chaos us-east-1
  61. "54.224.69.136/32", # FRTIB Chaos us-east-1
  62. "34.237.183.65/32", # FRTIB Chaos prod us-east-1
  63. "34.227.214.27/32", # FRTIB Chaos prod us-east-1
  64. "3.232.76.136/32", # FRTIB Chaos prod us-east-1
  65. ],
  66. mdr-prod-frtib = [
  67. "52.61.113.202/32",
  68. "54.205.60.17/32", # 2021-05-04 From John Conrad john.conrad.2@alight.com
  69. "52.206.203.98/32",
  70. "34.233.188.131/32",
  71. "15.200.226.57/32", # 2021-07-12 From "Nguyen, Brian A." <brian.a.nguyen@accenturefederal.com>
  72. "34.214.247.125/32", # 2022-01-20 From John Conrad john.conrad.2@alight.com
  73. "44.235.174.214/32",
  74. "52.89.203.9/32",
  75. "3.221.245.113/32", # FRTIB Chaos us-east-1
  76. "34.237.100.242/32", # FRTIB Chaos us-east-1
  77. "35.172.75.107/32", # FRTIB Chaos us-east-1
  78. "54.164.205.89/32", # FRTIB Chaos us-east-1
  79. "54.209.105.32/32", # FRTIB Chaos us-east-1
  80. "54.224.69.136/32", # FRTIB Chaos us-east-1
  81. "34.237.183.65/32", # FRTIB Chaos prod us-east-1
  82. "34.227.214.27/32", # FRTIB Chaos prod us-east-1
  83. "3.232.76.136/32", # FRTIB Chaos prod us-east-1
  84. ],
  85. afs-mdr-test-c2-gov = [
  86. "170.248.172.0/23", # ?
  87. "20.190.250.137/32", # ?
  88. "52.232.227.197/32", # ?
  89. "52.185.64.173/32", # ?
  90. "52.242.225.98/32", # ?
  91. "52.177.84.83/32", # ?
  92. "199.16.64.3/32", #?
  93. "99.56.213.129/32", # Fred Damstra's Home IP - For testing
  94. ],
  95. }
  96. splunk_data_sources = lookup(local.splunk_data_sources_exceptions, var.account_name, local.splunk_data_sources_default)
  97. }