<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Can I delete /opt/splunk/var/run/searchpeers/&amp;lt;hostname&amp;gt;-1633305600/apps/splunk_archiver/* in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/Can-I-delete-opt-splunk-var-run-searchpeers-lt-hostname-gt/m-p/581057#M25187</link>
    <description>&lt;P&gt;check this out&amp;nbsp; it has all the details, i think there were some updated versions in that fixed the vulnerability.&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.splunk.com/en_us/blog/bulletins/splunk-security-advisory-for-apache-log4j-cve-2021-44228.html" target="_blank"&gt;https://www.splunk.com/en_us/blog/bulletins/splunk-security-advisory-for-apache-log4j-cve-2021-44228.html&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 14 Jan 2022 08:49:21 GMT</pubDate>
    <dc:creator>SinghK</dc:creator>
    <dc:date>2022-01-14T08:49:21Z</dc:date>
    <item>
      <title>Can I delete /opt/splunk/var/run/searchpeers/&lt;hostname&gt;-1633305600/apps/splunk_archiver/*?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Can-I-delete-opt-splunk-var-run-searchpeers-lt-hostname-gt/m-p/581055#M25186</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;I would like to know if it is safe to delete below on all of our Splunk hosts: /opt/splunk/var/run/searchpeers/&amp;lt;hostname&amp;gt;-1633305600/apps/splunk_archiver/java-bin/jars/vendors/spark/3.0.1/lib/&lt;BR /&gt;&lt;BR /&gt;Similar files exist on a lot of our Splunk hosts and we get notifications daily about them because of log4j. So is it safe to delete the above path and similar? It is just replications right?&lt;BR /&gt;&lt;BR /&gt;Thanks in advance!&lt;/P&gt;</description>
      <pubDate>Tue, 12 Jul 2022 16:22:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Can-I-delete-opt-splunk-var-run-searchpeers-lt-hostname-gt/m-p/581055#M25186</guid>
      <dc:creator>erw550</dc:creator>
      <dc:date>2022-07-12T16:22:24Z</dc:date>
    </item>
    <item>
      <title>Re: Can I delete /opt/splunk/var/run/searchpeers/&lt;hostname&gt;-1633305600/apps/splunk_archiver/*</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Can-I-delete-opt-splunk-var-run-searchpeers-lt-hostname-gt/m-p/581057#M25187</link>
      <description>&lt;P&gt;check this out&amp;nbsp; it has all the details, i think there were some updated versions in that fixed the vulnerability.&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.splunk.com/en_us/blog/bulletins/splunk-security-advisory-for-apache-log4j-cve-2021-44228.html" target="_blank"&gt;https://www.splunk.com/en_us/blog/bulletins/splunk-security-advisory-for-apache-log4j-cve-2021-44228.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Jan 2022 08:49:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Can-I-delete-opt-splunk-var-run-searchpeers-lt-hostname-gt/m-p/581057#M25187</guid>
      <dc:creator>SinghK</dc:creator>
      <dc:date>2022-01-14T08:49:21Z</dc:date>
    </item>
    <item>
      <title>Re: Can I delete /opt/splunk/var/run/searchpeers/&lt;hostname&gt;-1633305600/apps/splunk_archiver/*</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Can-I-delete-opt-splunk-var-run-searchpeers-lt-hostname-gt/m-p/581060#M25189</link>
      <description>&lt;P&gt;Yes, we have followed the instructions from the link you provided. But it does not mention if it is ok to the splunk_archiver app in&amp;nbsp;/opt/splunk/var/run/searchpeers/&amp;lt;host&amp;gt;-1633305600/*. Is it just replication under&amp;nbsp;/opt/splunk/var/run/searchpeers/&amp;lt;host&amp;gt;-1633305600/* and is it safe to delete it?&lt;/P&gt;</description>
      <pubDate>Fri, 14 Jan 2022 08:53:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Can-I-delete-opt-splunk-var-run-searchpeers-lt-hostname-gt/m-p/581060#M25189</guid>
      <dc:creator>erw550</dc:creator>
      <dc:date>2022-01-14T08:53:56Z</dc:date>
    </item>
    <item>
      <title>Re: Can I delete /opt/splunk/var/run/searchpeers/&lt;hostname&gt;-1633305600/apps/splunk_archiver/*</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Can-I-delete-opt-splunk-var-run-searchpeers-lt-hostname-gt/m-p/581335#M25192</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Our scan has too found log4j vulnerability under the path&amp;nbsp;&lt;SPAN&gt;/opt/splunk/var/run/searchpeers/&amp;lt;host&amp;gt;...&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Did you remove those files/folders from the location ?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;</description>
      <pubDate>Mon, 17 Jan 2022 14:05:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Can-I-delete-opt-splunk-var-run-searchpeers-lt-hostname-gt/m-p/581335#M25192</guid>
      <dc:creator>spodda01da</dc:creator>
      <dc:date>2022-01-17T14:05:15Z</dc:date>
    </item>
    <item>
      <title>Re: Can I delete /opt/splunk/var/run/searchpeers/&lt;hostname&gt;-1633305600/apps/splunk_archiver/*</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Can-I-delete-opt-splunk-var-run-searchpeers-lt-hostname-gt/m-p/581596#M25197</link>
      <description>&lt;P&gt;We have not removed them yet. Our Splunk environment is not effected since we do not have DFS enabled. But I am still trying to investigate whether we can delete those files so we don't get notified from the scan. Have you heard anything else?&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Jan 2022 08:04:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Can-I-delete-opt-splunk-var-run-searchpeers-lt-hostname-gt/m-p/581596#M25197</guid>
      <dc:creator>erw550</dc:creator>
      <dc:date>2022-01-19T08:04:39Z</dc:date>
    </item>
    <item>
      <title>Re: Can I delete /opt/splunk/var/run/searchpeers/&lt;hostname&gt;-1633305600/apps/splunk_archiver/*</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Can-I-delete-opt-splunk-var-run-searchpeers-lt-hostname-gt/m-p/581609#M25199</link>
      <description>&lt;P&gt;I went ahead and removed log4j files from the specified locations. Although I get a Splunk alert which is expected (As per Splunk, it can be ignored), but the scan is clean.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am planning to follow the same on other Splunk servers.&lt;/P&gt;&lt;P&gt;Here is the URL for reference:&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.splunk.com/en_us/blog/bulletins/splunk-security-advisory-for-apache-log4j-cve-2021-44228.html" target="_blank"&gt;https://www.splunk.com/en_us/blog/bulletins/splunk-security-advisory-for-apache-log4j-cve-2021-44228.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;"&lt;SPAN&gt;Upon removal of these jar files, an administrator may see errors at Splunk startup pertaining to file integrity, specific to these jar files. These are expected as you are removing these unused jar files as a workaround. These errors may be ignored.&amp;nbsp;&lt;/SPAN&gt;"&lt;/P&gt;</description>
      <pubDate>Wed, 19 Jan 2022 11:49:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Can-I-delete-opt-splunk-var-run-searchpeers-lt-hostname-gt/m-p/581609#M25199</guid>
      <dc:creator>spodda01da</dc:creator>
      <dc:date>2022-01-19T11:49:25Z</dc:date>
    </item>
    <item>
      <title>Re: Can I delete /opt/splunk/var/run/searchpeers/&lt;hostname&gt;-1633305600/apps/splunk_archiver/*</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Can-I-delete-opt-splunk-var-run-searchpeers-lt-hostname-gt/m-p/605311#M25855</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/240997"&gt;@erw550&lt;/a&gt;&amp;nbsp; Where you able to succesfully remove /opt/splunk/var/run/searchpeers/&amp;lt;hostname&amp;gt;/apps/splunk_archiver/* without any issue?&lt;/P&gt;</description>
      <pubDate>Tue, 12 Jul 2022 16:14:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Can-I-delete-opt-splunk-var-run-searchpeers-lt-hostname-gt/m-p/605311#M25855</guid>
      <dc:creator>bwoodward22</dc:creator>
      <dc:date>2022-07-12T16:14:36Z</dc:date>
    </item>
  </channel>
</rss>

