I need to allow the Splunk ES SH to access the Internet to allow the Splunk ES Use Cases / Content updates to be updated and kept up to date.
Does anyone know if the URL(s) and port(s) that the Splunk ES Search head needs to access?
Same question goes on Threat Intel downloads. Are the URLs for the free intel feeds documented anywhere?
Thank you
Splunk states:
Prerequisites
So we use a proxy server and whitelist urls in it to download threat intel.
I would not recommend automatic updates of the DA-ESS-ContentUpdate. I do a manual check every month to see if there is an update and download it and apply it to my search heads.
If you just want to open up ports then you need to open your search head to https / port 443 to be able to communicate with the internet.