Security

What is the splunk update services address for a Firewall?

jbradbury6p6
New Member

I need to understand what methodology Splunk applies in order to update. This is to allow updates through a Firewall. I need to understand what ports and URLs/Addresses to allow our instance to connect with externally, to allow update services such as security patches.

0 Karma

skalliger
Motivator

Hi,

Splunk updates are not done via an online update process. To get an overview of the (standard) ports Splunk is using, refer to these URLs #1 (docs), #2 (Aplura Cheat Port Sheet).

For further information of how to update your environment, refer to the docs (according to your version) here. Be sure to follow the docs that are meant for your environment - standalone server, distributed, indexer cluster or indexer cluster with search head cluster.

Skalli

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...