Splunk Enterprise Security

Should Splunk have Internet access

SamHTexas
Builder

Should Splunk be connected to internet , have internet access? What are the pluses & minuses ?

Labels (1)
Tags (2)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Whether Splunk should have an Internet connection is up to you.  There are many places where Splunk runs successfully without one.

Some of the features the won't work without Internet access:

  • Checking for new versions of Splunk
  • Installing or upgrading apps directly from splunkbase
  • The Manage Apps screen will not say which apps have upgrades available
  • Any "Learn more" links to sites outside the local enclave
  • The "Documentation" and "Tutorial" links on the Search & Reporting home page
  • Threat feeds from outside sources
  • Telemetry information cannot be sent to Splunk HQ.

I'm sure are others I'm forgetting, but you get the idea.  Splunk will work just fine, but with a few minor "inconveniences".

See also https://wiki.splunk.com/Community:ConfigureNoInternet

---
If this reply helps you, Karma would be appreciated.

isoutamo
SplunkTrust
SplunkTrust
There is no real need to have internet connection. In security point of view w/o it is better option. Of course then you must get all packages etc via jump servers or other way to those nodes before install.
There is also option to use proxy to connect nodes in internet (e.g. use splunk cloud gateway).
My personal proposal is not to use direct connection to internet unless it’s absolutely necessary (I cannot figure what this can be).
R. Ismo
0 Karma

SamHTexas
Builder

Thank u very much for your message. Is Splunk Cloud gateway an app or add-on ? Or are there apps or add-on that you'd recommend? Thank u again.

0 Karma

isoutamo
SplunkTrust
SplunkTrust
Since 8.1.x it’s part of core splunk, before that it’s an app.
I haven’t any recommendations for apps and TAs, that totally depends on your needs.
r. Ismo
0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Get the T-shirt to Prove You Survived Splunk University Bootcamp

As if Splunk University, in Las Vegas, in-person, with three days of bootcamps and labs weren’t enough, now ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...