Knowledge Management

How can I create a rule to detect known RHEL vulnerabilities?

pm2012
Explorer

Hi SMEs,

Seeking advice on how i can create a rule/correlation search to detect some RHEL known vulnerabilities (CVEs)

Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Splunk is not a vulnerability scanner.  It can index and report on results produced by dedicated vulnerability tools, but doesn't detect vulnerabilities on its own.  That's not to say a Splunk query can't find anything with the right data (like, for instance, a running telnetd process) it's just typically not done that way.

If you have a specific vulnerability you need help detecting then post a new question and perhaps someone can help with it.

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...