Knowledge Management

How can I create a rule to detect known RHEL vulnerabilities?

pm2012
Explorer

Hi SMEs,

Seeking advice on how i can create a rule/correlation search to detect some RHEL known vulnerabilities (CVEs)

Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Splunk is not a vulnerability scanner.  It can index and report on results produced by dedicated vulnerability tools, but doesn't detect vulnerabilities on its own.  That's not to say a Splunk query can't find anything with the right data (like, for instance, a running telnetd process) it's just typically not done that way.

If you have a specific vulnerability you need help detecting then post a new question and perhaps someone can help with it.

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...