Deployment Architecture

will server hardening (CIS redhat 9 level 1) break Splunk functionality?

tdth
Explorer

Hi

I have splunk servers (full deployment with index cluster, sh cluster) running on redhat 9.

Now we want to harden the server following cis standard. Will this have any impact on Splunk application? Any exception need to be made? 

Thanks

Labels (2)
0 Karma

kiran_panchavat
SplunkTrust
SplunkTrust

@tdth 

Yes, implementing CIS benchmarks to harden your Red Hat 9 servers can potentially impact your Splunk deployment if not carefully managed. What specific hardening measures are you planning to apply? It's best to first implement CIS hardening in a UAT environment and thoroughly test its impact before deploying it in production.

 
Did this help? If yes, please consider giving kudos, marking it as the solution, or commenting for clarification — your feedback keeps the community going!
0 Karma

tdth
Explorer

Thanks, I guess we have no choice but to test it out.

In your experience, what could be the impact to Splunk application?

0 Karma

richgalloway
SplunkTrust
SplunkTrust

What specifically do you plan to do to harden the server?  Once we know that, we can tell what effect it will have.

---
If this reply helps you, Karma would be appreciated.
0 Karma

tdth
Explorer

As I mentioned, we want to harden the Linux server following CIS benchmark. There is long list of things to be done so it's hard to put down everything here... The goal is to make the server and the application more secured

0 Karma

richgalloway
SplunkTrust
SplunkTrust

There is a long list of things that potentially could go wrong depending on what you do to the server to harden it.  It's hard to be specific about the results if you can't be specific about the changes.  We're all volunteers here, so try to meet us halfway.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Observability Unlocked: Kubernetes Monitoring with Splunk Observability Cloud

 Ready to master Kubernetes and cloud monitoring like the pros? Join Splunk’s Growth Engineering team for an ...

Update Your SOAR Apps for Python 3.13: What Community Developers Need to Know

To Community SOAR App Developers - we're reaching out with an important update regarding Python 3.9's ...

October Community Champions: A Shoutout to Our Contributors!

As October comes to a close, we want to take a moment to celebrate the people who make the Splunk Community ...