Splunk Enterprise

What are the pro's & Cons of connecting Splunk Enterprise & ES to Internet?

SamHTexas
Builder

Also is it advisable to leave them connected to internet only for short times for for example " Threat list" for Mittre-attack to gets downloaded? I get a lot of errors when updates don't get updated.

Labels (1)
Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

If you need Splunk connected to the Internet (and it sounds like you do) then leave it connected.

Pros: threat feeds arrive; alerts go out; update checking works; app updates work; less noise in the logs

Cons: "less secure"

---
If this reply helps you, Karma would be appreciated.

SamHTexas
Builder

Thank u again. As far as apps. I have about 80 apps & TAs that needs updating. My understanding is that I need to download the new ones & update the apps one at time. Am I right?

Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

You are correct.  There are a couple of ways to update apps, but all of them require tedious manual clicking.  If you update from the Manage Apps page then Splunk does most of the work for you.

If your REST and programming skills are high enough then you may be able to automate the work.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Splunk Search APIを使えば調査過程が残せます

このゲストブログは、JCOM株式会社の情報セキュリティ本部・専任部長である渡辺慎太郎氏によって執筆されました。 Note: This article is published in both Japanese and ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...