Splunk Enterprise

Splunk Enterprise or Heavy Forwarder Internet Access

CarlosNoob
Engager

Good Day.

I've browsed for some time the official documentation and the forum, and I haven't found exactly the answer I need, so... this is my question (it applies to HF and Enterprise).

I would like to limit the internet access of my HF. Over the months, two possible connections come to my mind:

  • Updating Splunk
  • Updating Plugins from splunkbase

After some reseach, I haven't found what IP addresses or URL are the right ones to configure in the firewall.

Any help?

Labels (1)
0 Karma
1 Solution

livehybrid
SplunkTrust
SplunkTrust

Hi @CarlosNoob 

If you want to be able to update apps from within your Splunk server's apps list then you need to enable the server to access https://apps.splunk.com/  which is details in server.conf.

If you want the update notifications, *or to access docs* linked from various parts of Splunk then the server needs to be able to access http://quickdraw.splunk.com - this is detailed in web.conf here.

Note - Splunk HF/Enterprise does not have the ability to update itself, it can only notify you of an update. You would need to download the packages from https://splunk.com/download

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

View solution in original post

livehybrid
SplunkTrust
SplunkTrust

Hi @CarlosNoob 

If you want to be able to update apps from within your Splunk server's apps list then you need to enable the server to access https://apps.splunk.com/  which is details in server.conf.

If you want the update notifications, *or to access docs* linked from various parts of Splunk then the server needs to be able to access http://quickdraw.splunk.com - this is detailed in web.conf here.

Note - Splunk HF/Enterprise does not have the ability to update itself, it can only notify you of an update. You would need to download the packages from https://splunk.com/download

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

CarlosNoob
Engager

Good Day @livehybrid 

Yes, It helped.

Some research with Browser Dev Tools shows that all posibilities (login to splunk base, downloading, login to splunk) are inside the main domain:

*.splunk.com

So allowing by domain to splunk.com should be ok.

 

Kind Regards.

0 Karma

PickleRick
SplunkTrust
SplunkTrust

Splunk doesn't automatically update online - you have to manually download a new version and upload it to server(s).

The sources for app downloads are listed in

https://docs.splunk.com/Documentation/Splunk/latest/Admin/Serverconf#Remote_applications_configurati...

0 Karma
Get Updates on the Splunk Community!

Index This | What’s a riddle wrapped in an enigma?

September 2025 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...

BORE at .conf25

Boss Of Regular Expression (BORE) was an interactive session run again this year at .conf25 by the brilliant ...

OpenTelemetry for Legacy Apps? Yes, You Can!

This article is a follow-up to my previous article posted on the OpenTelemetry Blog, "Your Critical Legacy App ...