Splunk Enterprise

How to turn off all Splunk queries towards the internet?

hettervik
Builder

I'm trying to disable all queries from Splunk towards the internet. We have Splunk on Linux, on a closed network, and traffic towards the internet is only creating noise. I've already sat updateCheckerBaseURL=0 in web.conf and remote_tab=false in app.conf, but still there seems to be some traffic from Splunk trying to reach the internet.

Is there any other settings I can disable, or is there any smart way to troubleshoot exactly what Splunk services are trying to reach internet, why, and how to turn them off?

Labels (1)
Tags (2)
0 Karma

fuebel
Explorer

lakshman239
SplunkTrust
SplunkTrust

Have you updated updateCheckerBaseURL=0  in local/app.conf for all the apps  in etc/apps or one off in the etc/system/local/app.conf in your Search head(s)?  Sometime, we may have to do this in all apps as anyone could try to reach internet.

ITWhisperer
SplunkTrust
SplunkTrust

Have you tried something like wireshark to look at the traffic or run it through a proxy so see what is going on?

Get Updates on the Splunk Community!

Admin Your Splunk Cloud, Your Way

Join us to maximize different techniques to best tune Splunk Cloud. In this Tech Enablement, you will get ...

Cloud Platform | Discontinuing support for TLS version 1.0 and 1.1

Overview Transport Layer Security (TLS) is a security communications protocol that lets two computers, ...

New Customer Testimonials

Enterprises of all sizes and across different industries are accelerating cloud adoption by migrating ...