Deployment Architecture

will server hardening (CIS redhat 9 level 1) break Splunk functionality?

tdth
Explorer

Hi

I have splunk servers (full deployment with index cluster, sh cluster) running on redhat 9.

Now we want to harden the server following cis standard. Will this have any impact on Splunk application? Any exception need to be made? 

Thanks

Labels (2)
0 Karma

kiran_panchavat
SplunkTrust
SplunkTrust

@tdth 

Yes, implementing CIS benchmarks to harden your Red Hat 9 servers can potentially impact your Splunk deployment if not carefully managed. What specific hardening measures are you planning to apply? It's best to first implement CIS hardening in a UAT environment and thoroughly test its impact before deploying it in production.

 
Did this help? If yes, please consider giving kudos, marking it as the solution, or commenting for clarification — your feedback keeps the community going!
0 Karma

tdth
Explorer

Thanks, I guess we have no choice but to test it out.

In your experience, what could be the impact to Splunk application?

0 Karma

richgalloway
SplunkTrust
SplunkTrust

What specifically do you plan to do to harden the server?  Once we know that, we can tell what effect it will have.

---
If this reply helps you, Karma would be appreciated.
0 Karma

tdth
Explorer

As I mentioned, we want to harden the Linux server following CIS benchmark. There is long list of things to be done so it's hard to put down everything here... The goal is to make the server and the application more secured

0 Karma

richgalloway
SplunkTrust
SplunkTrust

There is a long list of things that potentially could go wrong depending on what you do to the server to harden it.  It's hard to be specific about the results if you can't be specific about the changes.  We're all volunteers here, so try to meet us halfway.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...