Splunk Enterprise Security

Should Splunk have Internet access

SamHTexas
Builder

Should Splunk be connected to internet , have internet access? What are the pluses & minuses ?

Labels (1)
Tags (2)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Whether Splunk should have an Internet connection is up to you.  There are many places where Splunk runs successfully without one.

Some of the features the won't work without Internet access:

  • Checking for new versions of Splunk
  • Installing or upgrading apps directly from splunkbase
  • The Manage Apps screen will not say which apps have upgrades available
  • Any "Learn more" links to sites outside the local enclave
  • The "Documentation" and "Tutorial" links on the Search & Reporting home page
  • Threat feeds from outside sources
  • Telemetry information cannot be sent to Splunk HQ.

I'm sure are others I'm forgetting, but you get the idea.  Splunk will work just fine, but with a few minor "inconveniences".

See also https://wiki.splunk.com/Community:ConfigureNoInternet

---
If this reply helps you, Karma would be appreciated.

isoutamo
SplunkTrust
SplunkTrust
There is no real need to have internet connection. In security point of view w/o it is better option. Of course then you must get all packages etc via jump servers or other way to those nodes before install.
There is also option to use proxy to connect nodes in internet (e.g. use splunk cloud gateway).
My personal proposal is not to use direct connection to internet unless it’s absolutely necessary (I cannot figure what this can be).
R. Ismo
0 Karma

SamHTexas
Builder

Thank u very much for your message. Is Splunk Cloud gateway an app or add-on ? Or are there apps or add-on that you'd recommend? Thank u again.

0 Karma

isoutamo
SplunkTrust
SplunkTrust
Since 8.1.x it’s part of core splunk, before that it’s an app.
I haven’t any recommendations for apps and TAs, that totally depends on your needs.
r. Ismo
0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...