Installed splunk app for FISMA on my splunk version 6.2.2
Steps i followed:
1) installed fisma app and deployed it in search head.
2) then deployed the same FISMA app folder to all indexers.
3) But Account Management Trends & Account Management Signatures doesn't show up any data in the dashboard
4) Other dashboards also doesn't collect any data like Audit, Logins, Malware, Network, Updates, Vulnerabilities.
Please let me know if i have to do any further configuration.
I need documentation on what specific piece of the FISMA app will do say AU-8. Is there something out there that describes that?
I believe the Splunk FISMA app was designed at this time to pass baseline requirements meaning they validate in the low categories of the FISMA scale of each of the controls. I know if you go to any of the controls... example >> investigate a control > PS personal security > PS-4 Personnel Termination > go down to the bottom of the page and select arrow next to Control Details. The FISMA explanation comes up that the auditor or the IA officer can read to understand the details of the metrics for the displayed or printed report. Hope this helps out and that I understood your question ok.
I need documentation on what specific piece of the FISMA app will do say AU-8. Is there something out there that describes that?