Security

Required Internet Endpoints for Splunk SIEM Functionality

Nikolozts
Explorer

hello,

 

Please write or send me document link which internet endpoints (URL, port) Splunk SIEM needs access to in order to function properly, download updates, apps, and anything else required for its normal operation.

Labels (1)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

On-prem Splunk does not _need_ anything from the internet to work correctly.

Some functionalities can be useful (like aforementioned updates for apps) but they are not obligatory and are often done different way around (manually downloading app/software update from Splunk site and uploading it directly to server(s).

Of course if you can directly use external services in inputs, external lookups, actions and so on but it's up to you.

0 Karma

Nikolozts
Explorer

Thank you. if a user wants to download apps from Splunkbase and install new updates, which internet endpoints need to be accessible?

0 Karma

PickleRick
SplunkTrust
SplunkTrust

https://docs.splunk.com/Documentation/Splunk/latest/Admin/Serverconf#Remote_applications_configurati...

This section lists all URLs Splunk uses for listing apps from Spkunkbase and checking for updates.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...