All Apps and Add-ons

Is there a way to configure the Forensic Investigator app to use a proxy for web calls?

xdp4
Explorer

Is there a way to get Forensic Investigator to use a proxy for the web calls, like Virustotal? When configuring other apps like the REST client for Splunk, when configuring a data input you can specify the proxy being used. I didn't see anything in the dashboard where that could be entered, but is there a .conf or app property sheet where this can be specified? It doesn't seem to be picking up the system proxy configured on the Splunk search head.

0 Karma

xdp4
Explorer

How does the submission to VT work from a technical perspective? Running a netcap from both the search head and my system doesn't show anything actually being submitted to VirusTotal. I changed the config to point to the proxy, and put in my own VT API key but I don't see anything destined for VT hitting the wire. Other functions work like WHOIS lookup (and big props for adding CyberChef btw) but the VT doesn't seem to do anything yet.

0 Karma

TonyLeeVT
Builder

Just released version 1.1.8 of the Forensic Investigator app. We added proxy support for VT Lookup. You enter the proxy settings via the setup page (Help -> Configure App). It doesn't support authenticated proxies, but let us know if it works otherwise. Authenticated proxy support will be added in the next release. Thanks for your patience.

0 Karma

TonyLeeVT
Builder

As of right now, there is no option to force the app to use a web proxy. We are now looking into potential solutions and the level of effort required.

I assume you tried something like this already?

1) http_proxy=:80 in splunk-launch.conf

As mentioned in the following thread:
https://answers.splunk.com/answers/59873/how-to-get-splunk-to-work-behind-a-proxy.html

Send me an email through the app and I can try to help you troubleshoot.

Lastly, I know it is not an ideal solution, however we have seen organizations create a whitelist proxy rule for certain URLs from specific hosts to get around such limitations.

Feel free to post below if you have other examples of apps that contain proxy configurations that work well.

0 Karma

Masa
Splunk Employee
Splunk Employee

I suggest to contact the author of the app. It all depends on how the app designed.

0 Karma
Get Updates on the Splunk Community!

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...