Splunk Enterprise Security

Should Splunk have Internet access

SamHTexas
Builder

Should Splunk be connected to internet , have internet access? What are the pluses & minuses ?

Labels (1)
Tags (2)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Whether Splunk should have an Internet connection is up to you.  There are many places where Splunk runs successfully without one.

Some of the features the won't work without Internet access:

  • Checking for new versions of Splunk
  • Installing or upgrading apps directly from splunkbase
  • The Manage Apps screen will not say which apps have upgrades available
  • Any "Learn more" links to sites outside the local enclave
  • The "Documentation" and "Tutorial" links on the Search & Reporting home page
  • Threat feeds from outside sources
  • Telemetry information cannot be sent to Splunk HQ.

I'm sure are others I'm forgetting, but you get the idea.  Splunk will work just fine, but with a few minor "inconveniences".

See also https://wiki.splunk.com/Community:ConfigureNoInternet

---
If this reply helps you, Karma would be appreciated.

isoutamo
SplunkTrust
SplunkTrust
There is no real need to have internet connection. In security point of view w/o it is better option. Of course then you must get all packages etc via jump servers or other way to those nodes before install.
There is also option to use proxy to connect nodes in internet (e.g. use splunk cloud gateway).
My personal proposal is not to use direct connection to internet unless it’s absolutely necessary (I cannot figure what this can be).
R. Ismo
0 Karma

SamHTexas
Builder

Thank u very much for your message. Is Splunk Cloud gateway an app or add-on ? Or are there apps or add-on that you'd recommend? Thank u again.

0 Karma

isoutamo
SplunkTrust
SplunkTrust
Since 8.1.x it’s part of core splunk, before that it’s an app.
I haven’t any recommendations for apps and TAs, that totally depends on your needs.
r. Ismo
0 Karma
Get Updates on the Splunk Community!

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...