<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to check if DFS is enabled in Splunk Enterprise in regards to Log4J (CVE-2021-44228) in Splunk Data Fabric Search</title>
    <link>https://community.splunk.com/t5/Splunk-Data-Fabric-Search/How-to-check-if-DFS-is-enabled-in-Splunk-Enterprise-in-regards/m-p/578951#M6</link>
    <description>&lt;P&gt;You can also use this:&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://&amp;lt;splunk" target="_blank" rel="noopener"&gt;https://&amp;lt;&lt;/A&gt;myonpremsplunkurl.com:8089/services/server/info&lt;BR /&gt;&lt;BR /&gt;You will be prompted to login from the browser. Login. If DFS is enabled, it will dfs_enable 1, if not enabled, it will show dfs_enabled 0.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;STRONG&gt;dfs_enabled&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD&gt;&lt;STRONG&gt;0&lt;/STRONG&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;eai:acl&lt;/TD&gt;&lt;TD&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;app&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;can_list&lt;/TD&gt;&lt;TD&gt;1&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;can_write&lt;/TD&gt;&lt;TD&gt;1&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;modifiable&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;Cheers&lt;/P&gt;</description>
    <pubDate>Mon, 20 Dec 2021 17:26:08 GMT</pubDate>
    <dc:creator>Yemi_Splunk</dc:creator>
    <dc:date>2021-12-20T17:26:08Z</dc:date>
    <item>
      <title>How to check if DFS is enabled in Splunk Enterprise in regards to Log4J (CVE-2021-44228)</title>
      <link>https://community.splunk.com/t5/Splunk-Data-Fabric-Search/How-to-check-if-DFS-is-enabled-in-Splunk-Enterprise-in-regards/m-p/578272#M2</link>
      <description>&lt;P&gt;Hi Guys,&lt;BR /&gt;I am quite new to splunk. I was looking around to see any splunk documents pertaining to&amp;nbsp;&lt;SPAN&gt;Data Fabric Search (DFS) as there is an impact since it leverages Log4j. However, I can't seem to find how to check if my Splunk Enterprise is using it.&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;Is there a setting that I can check from SearchHead, Indexer, etc if DFS is enabled?&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Also, does it mean if I did not install DFS Manager App, I am not using the DFS functionality?&lt;BR /&gt;&lt;BR /&gt;Thank you,&lt;BR /&gt;Rafiuddin&lt;/P&gt;</description>
      <pubDate>Tue, 14 Dec 2021 01:59:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Data-Fabric-Search/How-to-check-if-DFS-is-enabled-in-Splunk-Enterprise-in-regards/m-p/578272#M2</guid>
      <dc:creator>Rafiuddin</dc:creator>
      <dc:date>2021-12-14T01:59:30Z</dc:date>
    </item>
    <item>
      <title>How to check if DFS is enabled in Splunk Enterprise in regards to Log4J (CVE-2021-44228)</title>
      <link>https://community.splunk.com/t5/Splunk-Data-Fabric-Search/How-to-check-if-DFS-is-enabled-in-Splunk-Enterprise-in-regards/m-p/578279#M3</link>
      <description>&lt;P&gt;hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/241446"&gt;@Rafiuddin&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;1. You can check disabled=false in server.conf.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[dfs]

disabled = &amp;lt;boolean&amp;gt;
* When set to 'false' for the [dfs] stanza, this setting enables data fabric
  search functionality for this instance.
* A 'false' setting causes the Splunk software to start the DFSMaster Java
  process in a separate process. This process is central to Data Fabric Search
  funtionality.
* Default: true&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2. To check if DFS is in use you can run the below query. If it returns results then DFS is enabled.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| history 
| search search=*dfsjob* 
|  rex field=search "(?P&amp;lt;dfs_cmd&amp;gt;\|\s*dfsjob)" 
| search dfs_cmd=* and search!=*eval* 
| where len(dfs_cmd) &amp;gt; 0&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Dec 2021 05:37:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Data-Fabric-Search/How-to-check-if-DFS-is-enabled-in-Splunk-Enterprise-in-regards/m-p/578279#M3</guid>
      <dc:creator>manjunathmeti</dc:creator>
      <dc:date>2021-12-14T05:37:48Z</dc:date>
    </item>
    <item>
      <title>Re: How to check if DFS is enabled in Splunk Enterprise in regards to Log4J (CVE-2021-44228)</title>
      <link>https://community.splunk.com/t5/Splunk-Data-Fabric-Search/How-to-check-if-DFS-is-enabled-in-Splunk-Enterprise-in-regards/m-p/578419#M4</link>
      <description>&lt;P&gt;Thank you&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/129090"&gt;@manjunathmeti&lt;/a&gt;&amp;nbsp;!&lt;/P&gt;</description>
      <pubDate>Wed, 15 Dec 2021 05:05:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Data-Fabric-Search/How-to-check-if-DFS-is-enabled-in-Splunk-Enterprise-in-regards/m-p/578419#M4</guid>
      <dc:creator>Rafiuddin</dc:creator>
      <dc:date>2021-12-15T05:05:56Z</dc:date>
    </item>
    <item>
      <title>Re: How to check if DFS is enabled in Splunk Enterprise in regards to Log4J (CVE-2021-44228)</title>
      <link>https://community.splunk.com/t5/Splunk-Data-Fabric-Search/How-to-check-if-DFS-is-enabled-in-Splunk-Enterprise-in-regards/m-p/578622#M5</link>
      <description>&lt;P&gt;Please use:&lt;/P&gt;&lt;P&gt;| rest /services/configs/conf-server/dfs | table title,disabled&lt;/P&gt;</description>
      <pubDate>Thu, 16 Dec 2021 11:15:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Data-Fabric-Search/How-to-check-if-DFS-is-enabled-in-Splunk-Enterprise-in-regards/m-p/578622#M5</guid>
      <dc:creator>sybilla</dc:creator>
      <dc:date>2021-12-16T11:15:13Z</dc:date>
    </item>
    <item>
      <title>Re: How to check if DFS is enabled in Splunk Enterprise in regards to Log4J (CVE-2021-44228)</title>
      <link>https://community.splunk.com/t5/Splunk-Data-Fabric-Search/How-to-check-if-DFS-is-enabled-in-Splunk-Enterprise-in-regards/m-p/578951#M6</link>
      <description>&lt;P&gt;You can also use this:&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://&amp;lt;splunk" target="_blank" rel="noopener"&gt;https://&amp;lt;&lt;/A&gt;myonpremsplunkurl.com:8089/services/server/info&lt;BR /&gt;&lt;BR /&gt;You will be prompted to login from the browser. Login. If DFS is enabled, it will dfs_enable 1, if not enabled, it will show dfs_enabled 0.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;STRONG&gt;dfs_enabled&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD&gt;&lt;STRONG&gt;0&lt;/STRONG&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;eai:acl&lt;/TD&gt;&lt;TD&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;app&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;can_list&lt;/TD&gt;&lt;TD&gt;1&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;can_write&lt;/TD&gt;&lt;TD&gt;1&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;modifiable&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;Cheers&lt;/P&gt;</description>
      <pubDate>Mon, 20 Dec 2021 17:26:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Data-Fabric-Search/How-to-check-if-DFS-is-enabled-in-Splunk-Enterprise-in-regards/m-p/578951#M6</guid>
      <dc:creator>Yemi_Splunk</dc:creator>
      <dc:date>2021-12-20T17:26:08Z</dc:date>
    </item>
  </channel>
</rss>

