Splunk Enterprise Security

How do we prevent Content Update popup window in ES 7.0?

Path Finder

We are planning to upgrade ES from 6.6.2 to 7.0.1, one of the new features will have a pop up window indicating that a new Content Update version is available and allows for the option to upgrade to the new version.  We'd like to suppress this pop up and/or prevent the update through the UI.  Would either of the below two settings prevent the pop up?  If we can't suppress the pop up will either of the below two settings help prevent the update from occurring?

web.conf: Setting 'updateCheckerBaseURL' to 0 stops Splunk Web from pinging  Splunk.com for new versions of Splunk software.

app.conf: Setting 'check_for_updates' to 0, this setting determines whether Splunk Enterprise checks Splunkbase for updates to this app.

Automated updates for the Splunk ES Content Update (ESCU) app
When new security content is available, the update process is built into Splunk Enterprise Security so that ES admins always have the latest security content from the Splunk Security Research Team.

Labels (2)
0 Karma
Get Updates on the Splunk Community!

The Splunk Success Framework: Your Guide to Successful Splunk Implementations

Splunk Lantern is a customer success center that provides advice from Splunk experts on valuable data ...

Splunk Training for All: Meet Aspiring Cybersecurity Analyst, Marc Alicea

Splunk Education believes in the value of training and certification in today’s rapidly-changing data-driven ...

Investigate Security and Threat Detection with VirusTotal and Splunk Integration

As security threats and their complexities surge, security analysts deal with increased challenges and ...