CIS Splunk Enterprise Benchmark
Secure configuration guidelines for Splunk Enterprise SIEM platform
v1.1.0 November 2024Overview
▶This CIS Benchmark provides prescriptive guidance for establishing a secure configuration posture for Splunk Enterprise. Recommendations cover installation hardening, authentication and access control, data security, search and indexing security, network and transport security, and audit logging.
| Section | Area | Focus |
|---|---|---|
| 1 | Installation | Deployment, ports |
| 2 | Authentication | LDAP/SAML, RBAC |
| 3 | Data Security | Inputs, storage, encryption |
| 4 | Search | Quotas, knowledge objects |
| 5 | Network | TLS, listener hardening |
| 6 | Audit | Logging, health monitoring |
Profile Definitions
▶| Profile | Description | Intended Use |
|---|---|---|
| L1 | Level 1 — Standard | Essential security for all Splunk Enterprise deployments; minimal performance impact. |
| L2 | Level 2 — Hardened | Advanced hardening for PCI-DSS, HIPAA, or high-security environments. |
1 — Installation & Deployment
▶1.1 General Settings
▶This recommendation verifies that Splunk Is Running the Latest Stable Version on the Splunk Enterprise SIEM platform. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to implement this control may leave the Splunk Enterprise SIEM platform vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Review the Splunk Enterprise Splunk configuration and verify that Splunk Is Running the Latest Stable Version. Check the configuration files or use the CLI/API to confirm.
Update the Splunk Enterprise Splunk configuration to ensure Splunk Is Running the Latest Stable Version. Apply changes via configuration files or the management CLI/API and restart the service if required.
This recommendation verifies that Splunk Runs Under a Dedicated Non-Root User on the Splunk Enterprise SIEM platform. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to implement this control may leave the Splunk Enterprise SIEM platform vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Review the Splunk Enterprise Splunk configuration and verify that Splunk Runs Under a Dedicated Non-Root User. Check the configuration files or use the CLI/API to confirm.
Update the Splunk Enterprise Splunk configuration to ensure Splunk Runs Under a Dedicated Non-Root User. Apply changes via configuration files or the management CLI/API and restart the service if required.
This setting ensures that Splunk Home Directory Permissions Are Restricted on the Splunk Enterprise SIEM platform. Restricting this capability limits potential abuse and enforces the principle of least privilege across the environment.
Unrestricted access to this capability could allow unauthorized users or processes to perform actions beyond their intended scope. Applying least-privilege principles to the Splunk Enterprise SIEM platform is essential for defense in depth.
Review the Splunk Enterprise Splunk configuration and verify that Splunk Home Directory Permissions Are Restricted. Check the configuration files or use the CLI/API to confirm.
Update the Splunk Enterprise Splunk configuration to ensure Splunk Home Directory Permissions Are Restricted. Apply changes via configuration files or the management CLI/API and restart the service if required.
This recommendation verifies that Default Splunk Ports Are Changed on the Splunk Enterprise SIEM platform. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to implement this control may leave the Splunk Enterprise SIEM platform vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Review the Splunk Enterprise Splunk configuration and verify that Default Splunk Ports Are Changed. Check the configuration files or use the CLI/API to confirm.
Update the Splunk Enterprise Splunk configuration to ensure Default Splunk Ports Are Changed. Apply changes via configuration files or the management CLI/API and restart the service if required.
1.2 Deployment Configuration
▶This setting ensures that Management Port Is Restricted on the Splunk Enterprise SIEM platform. Restricting this capability limits potential abuse and enforces the principle of least privilege across the environment.
Unrestricted access to this capability could allow unauthorized users or processes to perform actions beyond their intended scope. Applying least-privilege principles to the Splunk Enterprise SIEM platform is essential for defense in depth.
Review the Splunk Enterprise Splunk configuration and verify that Management Port Is Restricted. Check the configuration files or use the CLI/API to confirm.
Update the Splunk Enterprise Splunk configuration to ensure Management Port Is Restricted. Apply changes via configuration files or the management CLI/API and restart the service if required.
This setting ensures that Deployment Server Client Access Is Controlled on the Splunk Enterprise SIEM platform. Restricting this capability limits potential abuse and enforces the principle of least privilege across the environment.
Unrestricted access to this capability could allow unauthorized users or processes to perform actions beyond their intended scope. Applying least-privilege principles to the Splunk Enterprise SIEM platform is essential for defense in depth.
Review the Splunk Enterprise Splunk configuration and verify that Deployment Server Client Access Is Controlled. Check the configuration files or use the CLI/API to confirm.
Update the Splunk Enterprise Splunk configuration to ensure Deployment Server Client Access Is Controlled. Apply changes via configuration files or the management CLI/API and restart the service if required.
This recommendation verifies that License Manager Communication Is Encrypted on the Splunk Enterprise SIEM platform. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to implement this control may leave the Splunk Enterprise SIEM platform vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Review the Splunk Enterprise Splunk configuration and verify that License Manager Communication Is Encrypted. Check the configuration files or use the CLI/API to confirm.
Update the Splunk Enterprise Splunk configuration to ensure License Manager Communication Is Encrypted. Apply changes via configuration files or the management CLI/API and restart the service if required.
2 — Authentication & Access Control
▶2.1 Authentication
▶This recommendation verifies that Default Admin Password Is Changed on the Splunk Enterprise SIEM platform. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to implement this control may leave the Splunk Enterprise SIEM platform vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Review the Splunk Enterprise Splunk configuration and verify that Default Admin Password Is Changed. Check the configuration files or use the CLI/API to confirm.
Update the Splunk Enterprise Splunk configuration to ensure Default Admin Password Is Changed. Apply changes via configuration files or the management CLI/API and restart the service if required.
This recommendation verifies that LDAP or SAML Authentication Is Configured on the Splunk Enterprise SIEM platform. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Splunk Enterprise SIEM platform vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Review the Splunk Enterprise Splunk configuration and verify that LDAP or SAML Authentication Is Configured. Check the configuration files or use the CLI/API to confirm.
Update the Splunk Enterprise Splunk configuration to ensure LDAP or SAML Authentication Is Configured. Apply changes via configuration files or the management CLI/API and restart the service if required.
This recommendation verifies that Password Complexity Requirements Are Set on the Splunk Enterprise SIEM platform. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Splunk Enterprise SIEM platform vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Review the Splunk Enterprise Splunk configuration and verify that Password Complexity Requirements Are Set. Check the configuration files or use the CLI/API to confirm.
Update the Splunk Enterprise Splunk configuration to ensure Password Complexity Requirements Are Set. Apply changes via configuration files or the management CLI/API and restart the service if required.
This recommendation verifies that Account Lockout Policy Is Configured on the Splunk Enterprise SIEM platform. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Splunk Enterprise SIEM platform vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Review the Splunk Enterprise Splunk configuration and verify that Account Lockout Policy Is Configured. Check the configuration files or use the CLI/API to confirm.
Update the Splunk Enterprise Splunk configuration to ensure Account Lockout Policy Is Configured. Apply changes via configuration files or the management CLI/API and restart the service if required.
2.2 Role-Based Access
▶This recommendation verifies that Custom Roles Are Used Instead of Default Admin on the Splunk Enterprise SIEM platform. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to implement this control may leave the Splunk Enterprise SIEM platform vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Review the Splunk Enterprise Splunk configuration and verify that Custom Roles Are Used Instead of Default Admin. Check the configuration files or use the CLI/API to confirm.
Update the Splunk Enterprise Splunk configuration to ensure Custom Roles Are Used Instead of Default Admin. Apply changes via configuration files or the management CLI/API and restart the service if required.
This setting ensures that Search Capabilities Are Role-Restricted on the Splunk Enterprise SIEM platform. Restricting this capability limits potential abuse and enforces the principle of least privilege across the environment.
Unrestricted access to this capability could allow unauthorized users or processes to perform actions beyond their intended scope. Applying least-privilege principles to the Splunk Enterprise SIEM platform is essential for defense in depth.
Review the Splunk Enterprise Splunk configuration and verify that Search Capabilities Are Role-Restricted. Check the configuration files or use the CLI/API to confirm.
Update the Splunk Enterprise Splunk configuration to ensure Search Capabilities Are Role-Restricted. Apply changes via configuration files or the management CLI/API and restart the service if required.
This setting ensures that Index Access Is Role-Restricted on the Splunk Enterprise SIEM platform. Restricting this capability limits potential abuse and enforces the principle of least privilege across the environment.
Unrestricted access to this capability could allow unauthorized users or processes to perform actions beyond their intended scope. Applying least-privilege principles to the Splunk Enterprise SIEM platform is essential for defense in depth.
Review the Splunk Enterprise Splunk configuration and verify that Index Access Is Role-Restricted. Check the configuration files or use the CLI/API to confirm.
Update the Splunk Enterprise Splunk configuration to ensure Index Access Is Role-Restricted. Apply changes via configuration files or the management CLI/API and restart the service if required.
This recommendation verifies that Token Authentication Is Properly Managed on the Splunk Enterprise SIEM platform. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to implement this control may leave the Splunk Enterprise SIEM platform vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Review the Splunk Enterprise Splunk configuration and verify that Token Authentication Is Properly Managed. Check the configuration files or use the CLI/API to confirm.
Update the Splunk Enterprise Splunk configuration to ensure Token Authentication Is Properly Managed. Apply changes via configuration files or the management CLI/API and restart the service if required.
3 — Data Security
▶3.1 Data Input Security
▶This recommendation verifies that Data Inputs Are Authenticated on the Splunk Enterprise SIEM platform. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to implement this control may leave the Splunk Enterprise SIEM platform vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Review the Splunk Enterprise Splunk configuration and verify that Data Inputs Are Authenticated. Check the configuration files or use the CLI/API to confirm.
Update the Splunk Enterprise Splunk configuration to ensure Data Inputs Are Authenticated. Apply changes via configuration files or the management CLI/API and restart the service if required.
This recommendation verifies that HEC Tokens Are Properly Scoped on the Splunk Enterprise SIEM platform. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to implement this control may leave the Splunk Enterprise SIEM platform vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Review the Splunk Enterprise Splunk configuration and verify that HEC Tokens Are Properly Scoped. Check the configuration files or use the CLI/API to confirm.
Update the Splunk Enterprise Splunk configuration to ensure HEC Tokens Are Properly Scoped. Apply changes via configuration files or the management CLI/API and restart the service if required.
This recommendation verifies that Scripted Inputs Run with Least Privilege on the Splunk Enterprise SIEM platform. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to implement this control may leave the Splunk Enterprise SIEM platform vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Review the Splunk Enterprise Splunk configuration and verify that Scripted Inputs Run with Least Privilege. Check the configuration files or use the CLI/API to confirm.
Update the Splunk Enterprise Splunk configuration to ensure Scripted Inputs Run with Least Privilege. Apply changes via configuration files or the management CLI/API and restart the service if required.
3.2 Data Storage
▶This recommendation verifies that Indexes Have Retention Policies Configured on the Splunk Enterprise SIEM platform. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to implement this control may leave the Splunk Enterprise SIEM platform vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Review the Splunk Enterprise Splunk configuration and verify that Indexes Have Retention Policies Configured. Check the configuration files or use the CLI/API to confirm.
Update the Splunk Enterprise Splunk configuration to ensure Indexes Have Retention Policies Configured. Apply changes via configuration files or the management CLI/API and restart the service if required.
This recommendation verifies that Sensitive Data Is Masked or Anonymized on the Splunk Enterprise SIEM platform. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to implement this control may leave the Splunk Enterprise SIEM platform vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Review the Splunk Enterprise Splunk configuration and verify that Sensitive Data Is Masked or Anonymized. Check the configuration files or use the CLI/API to confirm.
Update the Splunk Enterprise Splunk configuration to ensure Sensitive Data Is Masked or Anonymized. Apply changes via configuration files or the management CLI/API and restart the service if required.
This recommendation verifies that Index Bucket Encryption Is Enabled on the Splunk Enterprise SIEM platform. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Splunk Enterprise SIEM platform vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Review the Splunk Enterprise Splunk configuration and verify that Index Bucket Encryption Is Enabled. Check the configuration files or use the CLI/API to confirm.
Update the Splunk Enterprise Splunk configuration to ensure Index Bucket Encryption Is Enabled. Apply changes via configuration files or the management CLI/API and restart the service if required.
4 — Search & Knowledge Objects
▶4.1 Search Configuration
▶This recommendation verifies that Search Quotas Are Configured on the Splunk Enterprise SIEM platform. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Splunk Enterprise SIEM platform vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Review the Splunk Enterprise Splunk configuration and verify that Search Quotas Are Configured. Check the configuration files or use the CLI/API to confirm.
Update the Splunk Enterprise Splunk configuration to ensure Search Quotas Are Configured. Apply changes via configuration files or the management CLI/API and restart the service if required.
This setting ensures that Real-Time Searches Are Restricted on the Splunk Enterprise SIEM platform. Restricting this capability limits potential abuse and enforces the principle of least privilege across the environment.
Unrestricted access to this capability could allow unauthorized users or processes to perform actions beyond their intended scope. Applying least-privilege principles to the Splunk Enterprise SIEM platform is essential for defense in depth.
Review the Splunk Enterprise Splunk configuration and verify that Real-Time Searches Are Restricted. Check the configuration files or use the CLI/API to confirm.
Update the Splunk Enterprise Splunk configuration to ensure Real-Time Searches Are Restricted. Apply changes via configuration files or the management CLI/API and restart the service if required.
This recommendation verifies that Search Job TTL Is Configured on the Splunk Enterprise SIEM platform. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Splunk Enterprise SIEM platform vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Review the Splunk Enterprise Splunk configuration and verify that Search Job TTL Is Configured. Check the configuration files or use the CLI/API to confirm.
Update the Splunk Enterprise Splunk configuration to ensure Search Job TTL Is Configured. Apply changes via configuration files or the management CLI/API and restart the service if required.
4.2 Knowledge Objects
▶This setting ensures that App Installation Is Restricted to Admins on the Splunk Enterprise SIEM platform. Restricting this capability limits potential abuse and enforces the principle of least privilege across the environment.
Unrestricted access to this capability could allow unauthorized users or processes to perform actions beyond their intended scope. Applying least-privilege principles to the Splunk Enterprise SIEM platform is essential for defense in depth.
Review the Splunk Enterprise Splunk configuration and verify that App Installation Is Restricted to Admins. Check the configuration files or use the CLI/API to confirm.
Update the Splunk Enterprise Splunk configuration to ensure App Installation Is Restricted to Admins. Apply changes via configuration files or the management CLI/API and restart the service if required.
This recommendation verifies that Shared Knowledge Objects Have Proper Permissions on the Splunk Enterprise SIEM platform. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to implement this control may leave the Splunk Enterprise SIEM platform vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Review the Splunk Enterprise Splunk configuration and verify that Shared Knowledge Objects Have Proper Permissions. Check the configuration files or use the CLI/API to confirm.
Update the Splunk Enterprise Splunk configuration to ensure Shared Knowledge Objects Have Proper Permissions. Apply changes via configuration files or the management CLI/API and restart the service if required.
This recommendation verifies that Custom Commands Are Reviewed for Security on the Splunk Enterprise SIEM platform. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to implement this control may leave the Splunk Enterprise SIEM platform vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Review the Splunk Enterprise Splunk configuration and verify that Custom Commands Are Reviewed for Security. Check the configuration files or use the CLI/API to confirm.
Update the Splunk Enterprise Splunk configuration to ensure Custom Commands Are Reviewed for Security. Apply changes via configuration files or the management CLI/API and restart the service if required.
5 — Network & Transport Security
▶5.1 TLS Configuration
▶This recommendation verifies that TLS Is Enabled for Web Interface on the Splunk Enterprise SIEM platform. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Splunk Enterprise SIEM platform vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Review the Splunk Enterprise Splunk configuration and verify that TLS Is Enabled for Web Interface. Check the configuration files or use the CLI/API to confirm.
Update the Splunk Enterprise Splunk configuration to ensure TLS Is Enabled for Web Interface. Apply changes via configuration files or the management CLI/API and restart the service if required.
This recommendation verifies that TLS Is Enabled for Splunk-to-Splunk Communication on the Splunk Enterprise SIEM platform. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Splunk Enterprise SIEM platform vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Review the Splunk Enterprise Splunk configuration and verify that TLS Is Enabled for Splunk-to-Splunk Communication. Check the configuration files or use the CLI/API to confirm.
Update the Splunk Enterprise Splunk configuration to ensure TLS Is Enabled for Splunk-to-Splunk Communication. Apply changes via configuration files or the management CLI/API and restart the service if required.
This recommendation verifies that TLS 1.2 Is the Minimum Version on the Splunk Enterprise SIEM platform. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to implement this control may leave the Splunk Enterprise SIEM platform vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Review the Splunk Enterprise Splunk configuration and verify that TLS 1.2 Is the Minimum Version. Check the configuration files or use the CLI/API to confirm.
Update the Splunk Enterprise Splunk configuration to ensure TLS 1.2 Is the Minimum Version. Apply changes via configuration files or the management CLI/API and restart the service if required.
This recommendation verifies that Certificate Verification Is Enabled on the Splunk Enterprise SIEM platform. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Splunk Enterprise SIEM platform vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Review the Splunk Enterprise Splunk configuration and verify that Certificate Verification Is Enabled. Check the configuration files or use the CLI/API to confirm.
Update the Splunk Enterprise Splunk configuration to ensure Certificate Verification Is Enabled. Apply changes via configuration files or the management CLI/API and restart the service if required.
5.2 Network Hardening
▶This recommendation verifies that Splunk Web Is Bound to Specific Interfaces on the Splunk Enterprise SIEM platform. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to implement this control may leave the Splunk Enterprise SIEM platform vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Review the Splunk Enterprise Splunk configuration and verify that Splunk Web Is Bound to Specific Interfaces. Check the configuration files or use the CLI/API to confirm.
Update the Splunk Enterprise Splunk configuration to ensure Splunk Web Is Bound to Specific Interfaces. Apply changes via configuration files or the management CLI/API and restart the service if required.
This recommendation verifies that Unnecessary Listeners Are Disabled on the Splunk Enterprise SIEM platform. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to implement this control may leave the Splunk Enterprise SIEM platform vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Review the Splunk Enterprise Splunk configuration and verify that Unnecessary Listeners Are Disabled. Check the configuration files or use the CLI/API to confirm.
Update the Splunk Enterprise Splunk configuration to ensure Unnecessary Listeners Are Disabled. Apply changes via configuration files or the management CLI/API and restart the service if required.
This recommendation verifies that CORS Settings Are Restrictive on the Splunk Enterprise SIEM platform. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to implement this control may leave the Splunk Enterprise SIEM platform vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Review the Splunk Enterprise Splunk configuration and verify that CORS Settings Are Restrictive. Check the configuration files or use the CLI/API to confirm.
Update the Splunk Enterprise Splunk configuration to ensure CORS Settings Are Restrictive. Apply changes via configuration files or the management CLI/API and restart the service if required.
6 — Audit & Monitoring
▶6.1 Audit Logging
▶This recommendation verifies that Audit Logging Is Enabled on the Splunk Enterprise SIEM platform. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Splunk Enterprise SIEM platform vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Review the Splunk Enterprise Splunk configuration and verify that Audit Logging Is Enabled. Check the configuration files or use the CLI/API to confirm.
Update the Splunk Enterprise Splunk configuration to ensure Audit Logging Is Enabled. Apply changes via configuration files or the management CLI/API and restart the service if required.
This recommendation verifies that Login Activity Is Logged on the Splunk Enterprise SIEM platform. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to implement this control may leave the Splunk Enterprise SIEM platform vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Review the Splunk Enterprise Splunk configuration and verify that Login Activity Is Logged. Check the configuration files or use the CLI/API to confirm.
Update the Splunk Enterprise Splunk configuration to ensure Login Activity Is Logged. Apply changes via configuration files or the management CLI/API and restart the service if required.
This recommendation verifies that Configuration Changes Are Logged on the Splunk Enterprise SIEM platform. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to implement this control may leave the Splunk Enterprise SIEM platform vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Review the Splunk Enterprise Splunk configuration and verify that Configuration Changes Are Logged. Check the configuration files or use the CLI/API to confirm.
Update the Splunk Enterprise Splunk configuration to ensure Configuration Changes Are Logged. Apply changes via configuration files or the management CLI/API and restart the service if required.
6.2 Health Monitoring
▶This recommendation verifies that Monitoring Console Is Configured on the Splunk Enterprise SIEM platform. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Splunk Enterprise SIEM platform vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Review the Splunk Enterprise Splunk configuration and verify that Monitoring Console Is Configured. Check the configuration files or use the CLI/API to confirm.
Update the Splunk Enterprise Splunk configuration to ensure Monitoring Console Is Configured. Apply changes via configuration files or the management CLI/API and restart the service if required.
This recommendation verifies that Indexer Clustering Health Is Monitored on the Splunk Enterprise SIEM platform. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to implement this control may leave the Splunk Enterprise SIEM platform vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Review the Splunk Enterprise Splunk configuration and verify that Indexer Clustering Health Is Monitored. Check the configuration files or use the CLI/API to confirm.
Update the Splunk Enterprise Splunk configuration to ensure Indexer Clustering Health Is Monitored. Apply changes via configuration files or the management CLI/API and restart the service if required.
This recommendation verifies that Forwarder Connectivity Is Monitored on the Splunk Enterprise SIEM platform. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to implement this control may leave the Splunk Enterprise SIEM platform vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Review the Splunk Enterprise Splunk configuration and verify that Forwarder Connectivity Is Monitored. Check the configuration files or use the CLI/API to confirm.
Update the Splunk Enterprise Splunk configuration to ensure Forwarder Connectivity Is Monitored. Apply changes via configuration files or the management CLI/API and restart the service if required.