Splunk Enterprise

How to turn off all Splunk queries towards the internet?

hettervik
Builder

I'm trying to disable all queries from Splunk towards the internet. We have Splunk on Linux, on a closed network, and traffic towards the internet is only creating noise. I've already sat updateCheckerBaseURL=0 in web.conf and remote_tab=false in app.conf, but still there seems to be some traffic from Splunk trying to reach the internet.

Is there any other settings I can disable, or is there any smart way to troubleshoot exactly what Splunk services are trying to reach internet, why, and how to turn them off?

Labels (1)
Tags (2)
0 Karma

fuebel
Explorer

lakshman239
SplunkTrust
SplunkTrust

Have you updated updateCheckerBaseURL=0  in local/app.conf for all the apps  in etc/apps or one off in the etc/system/local/app.conf in your Search head(s)?  Sometime, we may have to do this in all apps as anyone could try to reach internet.

ITWhisperer
SplunkTrust
SplunkTrust

Have you tried something like wireshark to look at the traffic or run it through a proxy so see what is going on?

Get Updates on the Splunk Community!

Splunk APM & RUM | Upcoming Planned Maintenance

There will be planned maintenance of the streaming infrastructure for Splunk APM and Splunk RUM in the coming ...

Part 2: Diving Deeper With AIOps

Getting the Most Out of Event Correlation and Alert Storm Detection in Splunk IT Service Intelligence   Watch ...

User Groups | Upcoming Events!

If by chance you weren't already aware, the Splunk Community is host to numerous User Groups, organized ...