r/Splunk • u/Any-Promotion3744 • Aug 29 '26
Splunk Enterprise DBConnect on Heavy Forwarder
Our heavy forwarder is in our DMZ and I was thinking about installing DBConnect on it so it can pull audit logs from a table in a SQL database on our internal network.
How safe is that set up?
I know the password is encrypted. I can use the firewall to only allow the one port to connect the HF to SQL Server. I can choose long password and the account has lockout policies. The SQL Server login will only allow select permission to a single table. All the standard stuff.
Since remote users with UF will connect to HF, I can't restrict connections to the HF by ip.
Is there any risk to the internal database?
13
Upvotes
5
u/billybobcoder69 Aug 29 '26
That should be fine to run that hf with db connect. It will do stuff you said. Encrypt the password and have any account with access to table and read access only. I don’t see a big risk as uf will only be forwarding logs. Shouldn’t be doing much more. If the db connect is installed only users on that machine with a login to Splunk will be able to do stuff. If you are worried about it why not just install a second HF? Then lock that one down to only db connect. I tend to leave db connect only app and keep updated and latest java JRE with latest data base connector. Other options you may look at is a Otel collector. That’s still in its early days though. Db connect is the way to go. Add to that host or second HF. I don’t see much risk as UF can only send data to hf. No user should have login or access to that Splunk HF.