Splunk Enterprise

Splunk Enterprise or Heavy Forwarder Internet Access

CarlosNoob
Engager

Good Day.

I've browsed for some time the official documentation and the forum, and I haven't found exactly the answer I need, so... this is my question (it applies to HF and Enterprise).

I would like to limit the internet access of my HF. Over the months, two possible connections come to my mind:

  • Updating Splunk
  • Updating Plugins from splunkbase

After some reseach, I haven't found what IP addresses or URL are the right ones to configure in the firewall.

Any help?

Labels (1)
0 Karma
1 Solution

livehybrid
Super Champion

Hi @CarlosNoob 

If you want to be able to update apps from within your Splunk server's apps list then you need to enable the server to access https://apps.splunk.com/  which is details in server.conf.

If you want the update notifications, *or to access docs* linked from various parts of Splunk then the server needs to be able to access http://quickdraw.splunk.com - this is detailed in web.conf here.

Note - Splunk HF/Enterprise does not have the ability to update itself, it can only notify you of an update. You would need to download the packages from https://splunk.com/download

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

View solution in original post

livehybrid
Super Champion

Hi @CarlosNoob 

If you want to be able to update apps from within your Splunk server's apps list then you need to enable the server to access https://apps.splunk.com/  which is details in server.conf.

If you want the update notifications, *or to access docs* linked from various parts of Splunk then the server needs to be able to access http://quickdraw.splunk.com - this is detailed in web.conf here.

Note - Splunk HF/Enterprise does not have the ability to update itself, it can only notify you of an update. You would need to download the packages from https://splunk.com/download

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

CarlosNoob
Engager

Good Day @livehybrid 

Yes, It helped.

Some research with Browser Dev Tools shows that all posibilities (login to splunk base, downloading, login to splunk) are inside the main domain:

*.splunk.com

So allowing by domain to splunk.com should be ok.

 

Kind Regards.

0 Karma

PickleRick
SplunkTrust
SplunkTrust

Splunk doesn't automatically update online - you have to manually download a new version and upload it to server(s).

The sources for app downloads are listed in

https://docs.splunk.com/Documentation/Splunk/latest/Admin/Serverconf#Remote_applications_configurati...

0 Karma
Get Updates on the Splunk Community!

Splunk at Cisco Live 2025: Learning, Innovation, and a Little Bit of Mr. Brightside

Pack your bags (and maybe your dancing shoes)—Cisco Live is heading to San Diego, June 8–12, 2025, and Splunk ...

Splunk App Dev Community Updates – What’s New and What’s Next

Welcome to your go-to roundup of everything happening in the Splunk App Dev Community! Whether you're building ...

The Latest Cisco Integrations With Splunk Platform!

Join us for an exciting tech talk where we’ll explore the latest integrations in Cisco + Splunk! We’ve ...