Splunk Enterprise

Enabling FIPS 140-2

kchongMITRE
Observer

GM!

We currently have Splunk 7.2.3 and there is a STIG requirement to turn on the FIPS setting. According to the STIG, the only way to turn it on is to reinstall or upgrade the software.  Is that correct?

If I choose to reinstall 7.2.3 without first uninstalling it, will that work?  What is the Windows command to query the FIPS status on the Splunk server?

Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

FIPS has to be enabled before starting Splunk for the first time.  Enable FIPS in the config files.  Furthermore, FIPS is only supported on Linux systems so there's no Windows command to query the FIPS setting.  See https://docs.splunk.com/Documentation/Splunk/8.0.4/Security/SecuringSplunkEnterprisewithFIPS

---
If this reply helps you, Karma would be appreciated.
0 Karma

kchongMITRE
Observer

Thanks for the quick response!

I am having some authentication issue.  When running Splunk command in the Command Prompt, I am able to logon as admin.  However, when I tried to logon using admin through the web UI, I am not able to log on at all.  Also, I am not able to logon using my AD account neither.  Any idea?

0 Karma

richgalloway
SplunkTrust
SplunkTrust
You should post a new question since this is not related to FIPS.
---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...

[Live Demo] Watch SOC transformation in action with the reimagined Splunk Enterprise ...

Overwhelmed SOC? Splunk ES Has Your Back Tool sprawl, alert fatigue, and endless context switching are making ...

What’s New & Next in Splunk SOAR

Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us on ...