Monitoring Splunk

Demande d'aide pour fichier d'audit afin de contrôler SPLUNK | Need help for audit files to control SPLUNK

fulbert
New Member

[English version below dashes ]

Bonjour à tous,

Nous utilisons Nessus dans le cadre de contrôles de conformité et souhaitons contrôler SPLUNK, mais aucun fichier d’audit basé sur les CIS Benchmark n’est fourni par Tenable.

Quelqu’un disposerait-il d’un fichier audit forgé d’après les recommandation CIS, ou de ressources permettant de créer le fichier audit en corrélation avec les recommandations CIS ?

Vous remerciant par avance.


Good morning, everyone,

We use Nessus for compliance checks and want to control SPLUNK, but no audit file based on CIS Benchmark is provided by Tenable.

Does anyone have an audit file forged based on CIS recommendations, or resources to create the audit file in correlation with CIS recommendations?

Thank you in advance.

Labels (1)
0 Karma

nickhills
Ultra Champion

CIS do not publish a benchmark specifically for Splunk
https://www.cisecurity.org/cis-benchmarks/

In the past we have applied the standard benchmarks for the OS (which nessus does support) and combined this with operational best practices for splunk such as:

-limited local users & bastion host access
-custom SSL certs & enforced TLS
- not running splunk as root
- etc.

If my comment helps, please give it a thumbs up!
0 Karma

fulbert
New Member

Hello,

Thanks for you answer.

0 Karma
Get Updates on the Splunk Community!

.conf25 Community Recap

Hello Splunkers, And just like that, .conf25 is in the books! What an incredible few days — full of learning, ...

Splunk App Developers | .conf25 Recap & What’s Next

If you stopped by the Builder Bar at .conf25 this year, thank you! The retro tech beer garden vibes were ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...