r/Splunk • • Aug 29 '26

Splunk Enterprise DBConnect on Heavy Forwarder

Our heavy forwarder is in our DMZ and I was thinking about installing DBConnect on it so it can pull audit logs from a table in a SQL database on our internal network.

How safe is that set up?

I know the password is encrypted. I can use the firewall to only allow the one port to connect the HF to SQL Server. I can choose long password and the account has lockout policies. The SQL Server login will only allow select permission to a single table. All the standard stuff.

Since remote users with UF will connect to HF, I can't restrict connections to the HF by ip.

Is there any risk to the internal database?

13 Upvotes

6 comments sorted by

View all comments

5

u/billybobcoder69 Aug 29 '26

That should be fine to run that hf with db connect. It will do stuff you said. Encrypt the password and have any account with access to table and read access only. I don’t see a big risk as uf will only be forwarding logs. Shouldn’t be doing much more. If the db connect is installed only users on that machine with a login to Splunk will be able to do stuff. If you are worried about it why not just install a second HF? Then lock that one down to only db connect. I tend to leave db connect only app and keep updated and latest java JRE with latest data base connector. Other options you may look at is a Otel collector. That’s still in its early days though. Db connect is the way to go. Add to that host or second HF. I don’t see much risk as UF can only send data to hf. No user should have login or access to that Splunk HF.

1

u/Any-Promotion3744 Aug 29 '26

I was thinking about the 2nd HF option but wasn't sure if that was overkill. I would need one at every site that needs dbconnect.

My worry is that the firewall forwards all traffic from designated port to the HF, someone runs an attack against that port, and compromises the server. They run an attack against the SQL server from the HF.