<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: log4j vulnerable files are getting recreated after removal(CVE-2021-44228. ) in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/log4j-vulnerable-files-are-getting-recreated-after-removal-CVE/m-p/578966#M10979</link>
    <description>&lt;P&gt;Which files are you talking about?&amp;nbsp; Are they actually being recreated or is the deletion failing?&amp;nbsp; Are the files showing up in the splunk_archiver app?&amp;nbsp; If so, the blog says what to do about that.&lt;/P&gt;</description>
    <pubDate>Mon, 20 Dec 2021 18:45:00 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2021-12-20T18:45:00Z</dc:date>
    <item>
      <title>log4j vulnerable files are getting recreated after removal(CVE-2021-44228. )</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/log4j-vulnerable-files-are-getting-recreated-after-removal-CVE/m-p/578961#M10978</link>
      <description>&lt;P&gt;we followed the steps provided on&amp;nbsp;&lt;A href="https://www.splunk.com/en_us/blog/bulletins/splunk-security-advisory-for-apache-log4j-cve-2021-44228.html" target="_blank"&gt;https://www.splunk.com/en_us/blog/bulletins/splunk-security-advisory-for-apache-log4j-cve-2021-44228.html&lt;/A&gt;&amp;nbsp;but it seems that files are being recreated , Can anyone please help on that ??,&lt;BR /&gt;Also i wanted to know if replacing just Apache version rather upgrading splunk could&amp;nbsp; help to mitigate ?&lt;BR /&gt;and what should be the steps if i replace?&lt;/P&gt;</description>
      <pubDate>Mon, 20 Dec 2021 18:14:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/log4j-vulnerable-files-are-getting-recreated-after-removal-CVE/m-p/578961#M10978</guid>
      <dc:creator>imsidrai</dc:creator>
      <dc:date>2021-12-20T18:14:52Z</dc:date>
    </item>
    <item>
      <title>Re: log4j vulnerable files are getting recreated after removal(CVE-2021-44228. )</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/log4j-vulnerable-files-are-getting-recreated-after-removal-CVE/m-p/578966#M10979</link>
      <description>&lt;P&gt;Which files are you talking about?&amp;nbsp; Are they actually being recreated or is the deletion failing?&amp;nbsp; Are the files showing up in the splunk_archiver app?&amp;nbsp; If so, the blog says what to do about that.&lt;/P&gt;</description>
      <pubDate>Mon, 20 Dec 2021 18:45:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/log4j-vulnerable-files-are-getting-recreated-after-removal-CVE/m-p/578966#M10979</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-12-20T18:45:00Z</dc:date>
    </item>
    <item>
      <title>Re: log4j vulnerable files are getting recreated after removal(CVE-2021-44228. )</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/log4j-vulnerable-files-are-getting-recreated-after-removal-CVE/m-p/579523#M11021</link>
      <description>&lt;P&gt;did you just delete the 4 paths the documents say. i have been looking for more clarification into this. as i read it just indicates to delete those 4 paths and that should be it. is this true?&lt;/P&gt;</description>
      <pubDate>Wed, 29 Dec 2021 21:34:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/log4j-vulnerable-files-are-getting-recreated-after-removal-CVE/m-p/579523#M11021</guid>
      <dc:creator>japonter</dc:creator>
      <dc:date>2021-12-29T21:34:08Z</dc:date>
    </item>
  </channel>
</rss>

