Splunk Enterprise

Splunk Enterprise or Heavy Forwarder Internet Access

CarlosNoob
Engager

Good Day.

I've browsed for some time the official documentation and the forum, and I haven't found exactly the answer I need, so... this is my question (it applies to HF and Enterprise).

I would like to limit the internet access of my HF. Over the months, two possible connections come to my mind:

  • Updating Splunk
  • Updating Plugins from splunkbase

After some reseach, I haven't found what IP addresses or URL are the right ones to configure in the firewall.

Any help?

Labels (1)
0 Karma
1 Solution

livehybrid
Super Champion

Hi @CarlosNoob 

If you want to be able to update apps from within your Splunk server's apps list then you need to enable the server to access https://apps.splunk.com/  which is details in server.conf.

If you want the update notifications, *or to access docs* linked from various parts of Splunk then the server needs to be able to access http://quickdraw.splunk.com - this is detailed in web.conf here.

Note - Splunk HF/Enterprise does not have the ability to update itself, it can only notify you of an update. You would need to download the packages from https://splunk.com/download

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

View solution in original post

livehybrid
Super Champion

Hi @CarlosNoob 

If you want to be able to update apps from within your Splunk server's apps list then you need to enable the server to access https://apps.splunk.com/  which is details in server.conf.

If you want the update notifications, *or to access docs* linked from various parts of Splunk then the server needs to be able to access http://quickdraw.splunk.com - this is detailed in web.conf here.

Note - Splunk HF/Enterprise does not have the ability to update itself, it can only notify you of an update. You would need to download the packages from https://splunk.com/download

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

CarlosNoob
Engager

Good Day @livehybrid 

Yes, It helped.

Some research with Browser Dev Tools shows that all posibilities (login to splunk base, downloading, login to splunk) are inside the main domain:

*.splunk.com

So allowing by domain to splunk.com should be ok.

 

Kind Regards.

0 Karma

PickleRick
SplunkTrust
SplunkTrust

Splunk doesn't automatically update online - you have to manually download a new version and upload it to server(s).

The sources for app downloads are listed in

https://docs.splunk.com/Documentation/Splunk/latest/Admin/Serverconf#Remote_applications_configurati...

0 Karma
Get Updates on the Splunk Community!

Aligning Observability Costs with Business Value: Practical Strategies

 Join us for an engaging Tech Talk on Aligning Observability Costs with Business Value: Practical ...

Mastering Data Pipelines: Unlocking Value with Splunk

 In today's AI-driven world, organizations must balance the challenges of managing the explosion of data with ...

Splunk Up Your Game: Why It's Time to Embrace Python 3.9+ and OpenSSL 3.0

Did you know that for Splunk Enterprise 9.4, Python 3.9 is the default interpreter? This shift is not just a ...