Hello,
I’m a Splunk admin supporting a government environment. We’ve historically used both the STIGs and the SRGs to help meet compliance requirements.
With Splunk STIGs 7.x and 8.x now sunset, I’m trying to understand whether Cisco plans to publish an updated set of STIGs for newer Splunk versions. At the moment, the SRG appears to reference a Centralized Log Server rather than Splunk specifically, which leaves some room for interpretation.
I’m interested in whether anyone has seen official guidance, an updated roadmap, or any discussion around compliance support for current Splunk Enterprise releases.
A few specific questions:
I second this - Any guidance or information surrounding this exact issue would be greatly appreciated!