Monitoring Splunk

Disabling CBC mode ciphers

lal37
Explorer

Hi Team,

SSLv3.0/TLSv1.0 Protocol Weak CBC Mode vulnerability have been identified on Splunk during internal scan.
The internal PA team asked us to upgrade to TLSv1.1 or TLSv1.2,if not possible to upgrade they asked us to disable CBC mode ciphers.
It could be better if you could guide us to fix the issue.strong text

Regards,
Shiva

Tags (1)

hsesterhenn_spl
Splunk Employee
Splunk Employee

Just an update to make sure people use the current options: (v7.3+)

https://docs.splunk.com/Documentation/Splunk/latest/Security/Ciphersuites

HTH,

Holger

0 Karma

dwaddle
SplunkTrust
SplunkTrust

For Splunkd (port 8089 by default) - the proper setting of cipher suites is in server.conf under the sslConfig stanza, set the cipherSuite option using a valid OpenSSL cipher suite specification. See http://docs.splunk.com/Documentation/Splunk/latest/Admin/Serverconf

For splunkweb, there are similar settings in web.conf.

lal37
Explorer

Hi dawadle,

I would like to know how we can replace SSL version to TLS version.
I guess by default splunk is using SSL encryption.
Please advice.

Thanks and Regards,
Shiva

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...