Splunk Enterprise Security

How to view expired server certificates in the Splunk App for Enterprise Security 3.3?

eljaybee
Engager

I'm trying to view my server certificates via the Splunk Enterprise Security App 3.3. I asked to set it up in the app to monitor the expiration of certs. I have several servers forwarding data via the universal forwarder. How can I accomplish this?

mdessus_splunk
Splunk Employee
Splunk Employee

You might either index your certificates and add a command to check the expiration date or run a command on the fwd (may be with openssl) that will check once a day (for ex.) what is your certificate expiration date.

You might also have a look to the dashboard SSL Activity (in Protocol intelligence), to look what is done there, but the source is the SSL flows collected by Stream.

Does it makes sense ?

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.


Introducing Unified TDIR with the New Enterprise Security 8.2

Read the blog

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...