Security

Outbound connections required by splunk

Harold
Observer

Doing some hardening on my splunk and would like to block any outgoing connections not required.

Besides DNS as far as i logged on last couple of days splunk only requires outgoing on port 443 over /TCP/SSL on servers using certificates with names that fit "*splunk.com"?

I am talking about license and etc conections required by splunk, for this question assume a standalone enterprise splunk server with no integration with other servers or forwarders.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Harold,

as @scelikok said, if you're speaking about hardening, you should see at https://docs.splunk.com/Documentation/Splunk/8.1.3/Security/WhatyoucansecurewithSplunk, in addition in the last .Conf there was an interesting  webinar https://conf.splunk.com/files/2020/slides/TRU1537C.pdf  about Splunk hardening.

Anyway, if you want the connections used by Splunk, you should see at https://docs.splunk.com/Documentation/Splunk/8.1.3/InheritedDeployment/Ports

Ciao.

Giuseppe

 

0 Karma

scelikok
SplunkTrust
SplunkTrust

Hi @Harold,

Assuming there is no integration, standalone Splunk does not need any outgoing connections. Since we are talking about hardening, *splunk.com connections are also not necessary. They are for Splunk/apps version checking, and sending some telemetry data to Splunk about you usage. It is safe to block all outgoing connections.

If this reply helps you an upvote and "Accept as Solution" is appreciated.
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...