Security

In Splunk 6.4, I noticed server.conf.spec has reference to Common Criteria mode. Does Splunk support that yet?

Ellen
Splunk Employee
Splunk Employee

Splunk Enterprise 6.4 release shows some .conf.spec files (eg. server.conf, authentication.conf ...) that has references to Common Criteria mode for some of the attributes.

Is Splunk 6.4 NIAP certified yet and supported?

1 Solution

Ellen
Splunk Employee
Splunk Employee

Splunk has submitted Splunk Enterprise 6.4.0 for Common Criteria evaluation.

Until we are common criteria certified we do not recommend nor support configuring Splunk Enterprise in common criteria mode.

This can also be referenced in the Splunk documentation: About securing Splunk Enterprise

View solution in original post

tchimento_splun
Splunk Employee
Splunk Employee

I am happy to say that the Splunk Enterprise 6.4.5 evaluation has been posted on NIAP’s Product Compliant List (PCL).

The posting can be found at the following URL:
https://www.niap-ccevs.org/Product/Compliant.cfm?pid=10807

0 Karma

tchimento_splun
Splunk Employee
Splunk Employee

When we are officially accepted by NIAP to start the CC certification evaluation, it will be posted to the NIAP website: https://www.niap-ccevs.org/Product/PINE.cfm

dchoi_splunk
Splunk Employee
Splunk Employee

Has there been any progress for the CC certification since then

0 Karma

dchoi_splunk
Splunk Employee
Splunk Employee

How CC certification evaluation goes? Has Splunk Enterprise 6.4.0 got the certification?
It's gone away from NIAP website

0 Karma

tchimento_splun
Splunk Employee
Splunk Employee

We have submitted to NIAP and are awaiting their response. Once accepted we will schedule the testing.

0 Karma

Ellen
Splunk Employee
Splunk Employee

Splunk has submitted Splunk Enterprise 6.4.0 for Common Criteria evaluation.

Until we are common criteria certified we do not recommend nor support configuring Splunk Enterprise in common criteria mode.

This can also be referenced in the Splunk documentation: About securing Splunk Enterprise

doksu
Contributor

Is the Protection Profile report available?

0 Karma
Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...