All Apps and Add-ons

admin's beware: 6.5.1 causes clients to directly reach to splunk

w531t4
Path Finder

FYI, discovered that in 6.5.1 Splunk is now placing the burden of checking whether it is up to date on the client rather than the server. So, since most client machines have access to the internet, lots of interesting information gets passed back to Splunk.. including:

Any associated Splunk Answers user/cookie information
All Splunk role's on the server
GUID's of Splunk Licenses on the server

We are observing the request go to https://quickdraw.splunk.com, and we have 'updateCheckerBaseURL = 0' in web.conf. The request to quickdraw.splunk.com only occurs after a successful login.

If anyone knows how to turn off this behavior, it would be greatly appreciated.

0 Karma

ChrisG
Splunk Employee
Splunk Employee

The information that Splunk collects if you opt in to share performance data is documented in Share performance data in the Admin Manual. This topic also explains what data is not collected, which node in your deployment runs the searches to collect the data, and how to opt in or out.

0 Karma

w531t4
Path Finder

As stated in my original post, this still occurs while both

  • Anonymized Usage Data
  • License Usage Data

are set to disabled.

Additionally, the page says nothing about the inclusion of reporting the names of configured roles to splunk.

0 Karma

ChrisG
Splunk Employee
Splunk Employee

Indeed. We are doing some research here to get the details.

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...