Security

How do I access my local Splunk enterprise from outside our local network (Global Access)?

dhirendra761
Contributor

I have installed Splunk enterprise in my local system and It can be accessed within a local network using my system's IP or hostname.

Now, I want to make it global and wish ** to access from outside of the network.**

That’s my question. Can you please help me with this and provide a path forward or do I need to install Splunk cloud instead of Splunk Enterprise?

0 Karma
1 Solution

harsmarvania57
Ultra Champion

Hi @dhirendra761,

To access your Splunk Enterpsie instance which is hosted on on-premise network from Internet, you must have static public IP address assigned to your splunk server or firewall (If firewall then you can NAT public ip address to private IP address) OR you can use Splunk Cloud which is cloud based full Splunk instance but it is free for 14 days (As far as I remember) and after that if you want to continue to use that then you need to purchase subscription.

View solution in original post

harsmarvania57
Ultra Champion

Hi @dhirendra761,

To access your Splunk Enterpsie instance which is hosted on on-premise network from Internet, you must have static public IP address assigned to your splunk server or firewall (If firewall then you can NAT public ip address to private IP address) OR you can use Splunk Cloud which is cloud based full Splunk instance but it is free for 14 days (As far as I remember) and after that if you want to continue to use that then you need to purchase subscription.

dhirendra761
Contributor

Hi @harsmarvania57 Thanks for the answering. 🙂

0 Karma

493669
Super Champion

Hi @dhirendra761,
Try this:-
Go to $SPLUNK_HOME/etc/local/server.conf and add below stanza and restart splunk

[general]
allowRemoteLogin=always

dhirendra761
Contributor

@493669 Hi this seems to be resolve the issue. Will let back to you after implementation.
Thanks for answering.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...