Security

Outbound connections required by splunk

Harold
Observer

Doing some hardening on my splunk and would like to block any outgoing connections not required.

Besides DNS as far as i logged on last couple of days splunk only requires outgoing on port 443 over /TCP/SSL on servers using certificates with names that fit "*splunk.com"?

I am talking about license and etc conections required by splunk, for this question assume a standalone enterprise splunk server with no integration with other servers or forwarders.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Harold,

as @scelikok said, if you're speaking about hardening, you should see at https://docs.splunk.com/Documentation/Splunk/8.1.3/Security/WhatyoucansecurewithSplunk, in addition in the last .Conf there was an interesting  webinar https://conf.splunk.com/files/2020/slides/TRU1537C.pdf  about Splunk hardening.

Anyway, if you want the connections used by Splunk, you should see at https://docs.splunk.com/Documentation/Splunk/8.1.3/InheritedDeployment/Ports

Ciao.

Giuseppe

 

0 Karma

scelikok
SplunkTrust
SplunkTrust

Hi @Harold,

Assuming there is no integration, standalone Splunk does not need any outgoing connections. Since we are talking about hardening, *splunk.com connections are also not necessary. They are for Splunk/apps version checking, and sending some telemetry data to Splunk about you usage. It is safe to block all outgoing connections.

If this reply helps you an upvote and "Accept as Solution" is appreciated.
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...