Splunk Enterprise Security

Splunk ES Content Updates- Keeping it up to date

ttokkaris1
Engager

I need to allow the Splunk ES SH to access the Internet to allow the Splunk ES Use Cases / Content updates to be updated and kept up to date.

 

Does anyone know if the URL(s) and port(s) that the Splunk ES Search head needs to access? 

Same question goes on Threat Intel downloads. Are the URLs for the free intel feeds documented anywhere?

Thank you

Labels (1)

Azeemering
Builder

Splunk states:

Prerequisites

  • Your Splunk Enterprise deployment must be connected to the Internet. If your deployment is not connected to the Internet, disable these sources or source them in an alternate way.
  • To set up firewall rules for these sources, you might want to use a proxy server to collect the intelligence before forwarding it to Splunk Enterprise Security and allow the IP address for the proxy server to access Splunk Enterprise Security. The IP addresses for these sources can change.

So we use a proxy server and whitelist urls in it to download threat intel.

I would not recommend automatic updates of the DA-ESS-ContentUpdate. I do a manual check every month to see if there is an update and download it and apply it to my search heads.

If you just want to open up ports then you need to open your search head to https / port 443 to be able to communicate with the internet. 

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...