Monitoring Splunk

How to completely disable ProxyConfig?

ricotries
Communicator

I have a Splunk Enterprise instance (v7.3.4) and I am wondering if there is a way to completely disable ProxyConfig in server.conf? Every time the software restarts there's 4 informational logs in splunkd.log related to the 4 proxy settings (http_proxy, https_proxy, proxy_rules, and no_proxy), but I don't really care since I won't be enabling any outside communication. Is this required behavior or did I do something to trigger these startup messages?

0 Karma
1 Solution

PavelP
Motivator

Hello @ricotries,

AFAIK this function is compiled in the splunk binary, so you cannot disable it.

What you can do is to change the logging level for ProxyConfig to WARN. Create a file /opt/splunk/etc/log-local.cfg with following content:

[splunkd]
category.ProxyConfig=WARN

and restart splunk

View solution in original post

0 Karma

PavelP
Motivator

Hello @ricotries,

AFAIK this function is compiled in the splunk binary, so you cannot disable it.

What you can do is to change the logging level for ProxyConfig to WARN. Create a file /opt/splunk/etc/log-local.cfg with following content:

[splunkd]
category.ProxyConfig=WARN

and restart splunk

0 Karma

Jamie
Path Finder

Hello.  Has anyone pushed out this configuration to Universal Forwarders using a Deployment Manager?  Thanks.

0 Karma

sbrice18
Path Finder

What was your findings on pushing this out to a universal forwarder?  I am looking at the same thing since we see this error from 3k+ forwarders. 🙂

0 Karma

Jamie
Path Finder

It didn't work for the UFs (but did for Splunk servers from memory).

ricotries
Communicator

Is this the equivalent of filtering by severity level in syslog?

0 Karma

PavelP
Motivator

Hello @ricotries

yes, sort of
https://docs.splunk.com/Documentation/Splunk/8.0.3/AdvancedDev/ModInputsLog

I've tested this solution and it works

0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

 Prepare to elevate your security operations with the powerful upgrade to Splunk Enterprise Security 8.x! This ...

Get Early Access to AI Playbook Authoring: Apply for the Alpha Private Preview ...

Passionate about security automation? Apply now to our AI Playbook Authoring Alpha private preview ...

Reduce and Transform Your Firewall Data with Splunk Data Management

Managing high-volume firewall data has always been a challenge. Noisy events and verbose traffic logs often ...