We have a Splunk install inside a network that will never be publicly accessible in any way shape or form. Seeing as this is the case is it ok to disable the Splunk Secure Gateway app that comes pre-installed? Are there other reasons I should keep it turned on?
We have been disabling it since it was enabled by default in a previous 8.x version.
Note that in 9.x there's a bug with the config tracker and disabling an app. See the known issues SPL 233484. We ended up configuring the config tracker to ignore the secure gateway app that we disabled.
We have been disabling it since it was enabled by default in a previous 8.x version.
Note that in 9.x there's a bug with the config tracker and disabling an app. See the known issues SPL 233484. We ended up configuring the config tracker to ignore the secure gateway app that we disabled.