Security

Splunk Heavy Forwarder and Java

nbrazier21
Engager

I have a request that the version of Java on the HFs need to be updated, or have Java removed.

Is Java needed to the functional operation of the Heavy Forwarders?

 

[xxxxxxxxxxxx ~]$ java -version
openjdk version "1.8.0_302"
OpenJDK Runtime Environment (build 1.8.0_302-b08)
OpenJDK 64-Bit Server VM (build 25.302-b08, mixed mode)

 

[xxxxxxxxxx ~]$ which java
/usr/bin/java

 

 

Labels (1)
0 Karma
1 Solution

isoutamo
SplunkTrust
SplunkTrust

Hi

Heavy forwarder itself is not needing java, BUT you may have some inputs (e.g. Splunk DB Connect) there where Java is used. You need to go trough all your TAs on this node and check if it's needed or not. You could found those from /opt/splunk/etc/apps/xxx if your splunk is installed on standard place.

r. Ismo

View solution in original post

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

Heavy forwarder itself is not needing java, BUT you may have some inputs (e.g. Splunk DB Connect) there where Java is used. You need to go trough all your TAs on this node and check if it's needed or not. You could found those from /opt/splunk/etc/apps/xxx if your splunk is installed on standard place.

r. Ismo

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...