Splunk Enterprise Security

Should Splunk have Internet access

SamHTexas
Builder

Should Splunk be connected to internet , have internet access? What are the pluses & minuses ?

Labels (1)
Tags (2)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Whether Splunk should have an Internet connection is up to you.  There are many places where Splunk runs successfully without one.

Some of the features the won't work without Internet access:

  • Checking for new versions of Splunk
  • Installing or upgrading apps directly from splunkbase
  • The Manage Apps screen will not say which apps have upgrades available
  • Any "Learn more" links to sites outside the local enclave
  • The "Documentation" and "Tutorial" links on the Search & Reporting home page
  • Threat feeds from outside sources
  • Telemetry information cannot be sent to Splunk HQ.

I'm sure are others I'm forgetting, but you get the idea.  Splunk will work just fine, but with a few minor "inconveniences".

See also https://wiki.splunk.com/Community:ConfigureNoInternet

---
If this reply helps you, Karma would be appreciated.

isoutamo
SplunkTrust
SplunkTrust
There is no real need to have internet connection. In security point of view w/o it is better option. Of course then you must get all packages etc via jump servers or other way to those nodes before install.
There is also option to use proxy to connect nodes in internet (e.g. use splunk cloud gateway).
My personal proposal is not to use direct connection to internet unless it’s absolutely necessary (I cannot figure what this can be).
R. Ismo
0 Karma

SamHTexas
Builder

Thank u very much for your message. Is Splunk Cloud gateway an app or add-on ? Or are there apps or add-on that you'd recommend? Thank u again.

0 Karma

isoutamo
SplunkTrust
SplunkTrust
Since 8.1.x it’s part of core splunk, before that it’s an app.
I haven’t any recommendations for apps and TAs, that totally depends on your needs.
r. Ismo
0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...