Splunk Enterprise Security

Should Splunk have Internet access

SamHTexas
Builder

Should Splunk be connected to internet , have internet access? What are the pluses & minuses ?

Labels (1)
Tags (2)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Whether Splunk should have an Internet connection is up to you.  There are many places where Splunk runs successfully without one.

Some of the features the won't work without Internet access:

  • Checking for new versions of Splunk
  • Installing or upgrading apps directly from splunkbase
  • The Manage Apps screen will not say which apps have upgrades available
  • Any "Learn more" links to sites outside the local enclave
  • The "Documentation" and "Tutorial" links on the Search & Reporting home page
  • Threat feeds from outside sources
  • Telemetry information cannot be sent to Splunk HQ.

I'm sure are others I'm forgetting, but you get the idea.  Splunk will work just fine, but with a few minor "inconveniences".

See also https://wiki.splunk.com/Community:ConfigureNoInternet

---
If this reply helps you, Karma would be appreciated.

isoutamo
SplunkTrust
SplunkTrust
There is no real need to have internet connection. In security point of view w/o it is better option. Of course then you must get all packages etc via jump servers or other way to those nodes before install.
There is also option to use proxy to connect nodes in internet (e.g. use splunk cloud gateway).
My personal proposal is not to use direct connection to internet unless it’s absolutely necessary (I cannot figure what this can be).
R. Ismo
0 Karma

SamHTexas
Builder

Thank u very much for your message. Is Splunk Cloud gateway an app or add-on ? Or are there apps or add-on that you'd recommend? Thank u again.

0 Karma

isoutamo
SplunkTrust
SplunkTrust
Since 8.1.x it’s part of core splunk, before that it’s an app.
I haven’t any recommendations for apps and TAs, that totally depends on your needs.
r. Ismo
0 Karma
Get Updates on the Splunk Community!

Federated Search for Amazon S3 | Key Use Cases to Streamline Compliance Workflows

Modern business operations are supported by data compliance. As regulations evolve, organizations must ...

New Dates, New City: Save the Date for .conf25!

Wake up, babe! New .conf25 dates AND location just dropped!! That's right, this year, .conf25 is taking place ...

Introduction to Splunk Observability Cloud - Building a Resilient Hybrid Cloud

Introduction to Splunk Observability Cloud - Building a Resilient Hybrid Cloud  In today’s fast-paced digital ...