Security

Regarding Log4j

abhi04d
Engager

Hello everyone, 

So according to the Splunk blog: Splunk Security Advisory for Apache Log4j (CVE-2021-44228 and CVE-2021-45046) | Splunk it says that the affected versions are: "All supported non-Windows versions of 8.1.x and 8.2.x only if DFS is used. " 

I'm using Splunk Enterprise Search Head & Indexer with version 7.3.1 and I can see various log4j-1.2.17.jar files under location "/bin/jars/vendors/spark/2.3.0/lib/", "/etc/apps/splunk_app_db_connect/bin/lib/", /etc/apps/splunk_archiver/java-bin/jars/vendors/spark/ and etc. 

Also, I am attaching the result I received from a search query to determine if DFS is enabled on my Splunk servers.dfs_splunk.png
Should I be concerned about this vulnerability? 
Also to remediate, do I just need to replace this log4j-1.2.17.jar with the latest files directly in the respective directories or do I need to make any changes in the conf files as well? 

Any help will be appreciated. 

Thank you!

 

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Since you're running an unsupported version of Splunk, the guidance in the blog doesn't apply.  We can make some reasonable conclusions from it, however.

You're not using DFS so you should be safe.

To be "safer", follow the remediation instructions and remove the vulnerable jar files.

The instructions say nothing about changing config files so no changes are necessary.

To be "safest", upgrade to a version of Splunk that fixes the vulnerability.

---
If this reply helps you, Karma would be appreciated.
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Design, Compete, Win: Submit Your Best Splunk Dashboards for a .conf26 Pass

Hello Splunkers,  We’re excited to kick off a Splunk Dashboard contest! We know that dashboards are a primary ...

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...

Network to App: Observability Unlocked [May & June Series]

In today’s digital landscape, your environment is no longer confined to the data center. It spans complex ...