Monitoring Splunk

How to completely disable ProxyConfig?

ricotries
Communicator

I have a Splunk Enterprise instance (v7.3.4) and I am wondering if there is a way to completely disable ProxyConfig in server.conf? Every time the software restarts there's 4 informational logs in splunkd.log related to the 4 proxy settings (http_proxy, https_proxy, proxy_rules, and no_proxy), but I don't really care since I won't be enabling any outside communication. Is this required behavior or did I do something to trigger these startup messages?

0 Karma
1 Solution

PavelP
Motivator

Hello @ricotries,

AFAIK this function is compiled in the splunk binary, so you cannot disable it.

What you can do is to change the logging level for ProxyConfig to WARN. Create a file /opt/splunk/etc/log-local.cfg with following content:

[splunkd]
category.ProxyConfig=WARN

and restart splunk

View solution in original post

0 Karma

PavelP
Motivator

Hello @ricotries,

AFAIK this function is compiled in the splunk binary, so you cannot disable it.

What you can do is to change the logging level for ProxyConfig to WARN. Create a file /opt/splunk/etc/log-local.cfg with following content:

[splunkd]
category.ProxyConfig=WARN

and restart splunk

0 Karma

Jamie
Path Finder

Hello.  Has anyone pushed out this configuration to Universal Forwarders using a Deployment Manager?  Thanks.

0 Karma

sbrice18
Path Finder

What was your findings on pushing this out to a universal forwarder?  I am looking at the same thing since we see this error from 3k+ forwarders. 🙂

0 Karma

Jamie
Path Finder

It didn't work for the UFs (but did for Splunk servers from memory).

ricotries
Communicator

Is this the equivalent of filtering by severity level in syslog?

0 Karma

PavelP
Motivator

Hello @ricotries

yes, sort of
https://docs.splunk.com/Documentation/Splunk/8.0.3/AdvancedDev/ModInputsLog

I've tested this solution and it works

0 Karma
Get Updates on the Splunk Community!

Community Content Calendar, November Edition

Welcome to the November edition of our Community Spotlight! Each month, we dive into the Splunk Community to ...

October Community Champions: A Shoutout to Our Contributors!

As October comes to a close, we want to take a moment to celebrate the people who make the Splunk Community ...

Stay Connected: Your Guide to November Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...