Deployment Architecture

will server hardening (CIS redhat 9 level 1) break Splunk functionality?

tdth
Explorer

Hi

I have splunk servers (full deployment with index cluster, sh cluster) running on redhat 9.

Now we want to harden the server following cis standard. Will this have any impact on Splunk application? Any exception need to be made? 

Thanks

Labels (2)
0 Karma

kiran_panchavat
Influencer

@tdth 

Yes, implementing CIS benchmarks to harden your Red Hat 9 servers can potentially impact your Splunk deployment if not carefully managed. What specific hardening measures are you planning to apply? It's best to first implement CIS hardening in a UAT environment and thoroughly test its impact before deploying it in production.

 
Did this help? If yes, please consider giving kudos, marking it as the solution, or commenting for clarification — your feedback keeps the community going!
0 Karma

tdth
Explorer

Thanks, I guess we have no choice but to test it out.

In your experience, what could be the impact to Splunk application?

0 Karma

richgalloway
SplunkTrust
SplunkTrust

What specifically do you plan to do to harden the server?  Once we know that, we can tell what effect it will have.

---
If this reply helps you, Karma would be appreciated.
0 Karma

tdth
Explorer

As I mentioned, we want to harden the Linux server following CIS benchmark. There is long list of things to be done so it's hard to put down everything here... The goal is to make the server and the application more secured

0 Karma

richgalloway
SplunkTrust
SplunkTrust

There is a long list of things that potentially could go wrong depending on what you do to the server to harden it.  It's hard to be specific about the results if you can't be specific about the changes.  We're all volunteers here, so try to meet us halfway.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Detecting Brute Force Account Takeover Fraud with Splunk

This article is the second in a three-part series exploring advanced fraud detection techniques using Splunk. ...

Buttercup Games: Further Dashboarding Techniques (Part 9)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...

Buttercup Games: Further Dashboarding Techniques (Part 8)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...