Splunk Enterprise

Enabling FIPS 140-2

kchongMITRE
Observer

GM!

We currently have Splunk 7.2.3 and there is a STIG requirement to turn on the FIPS setting. According to the STIG, the only way to turn it on is to reinstall or upgrade the software.  Is that correct?

If I choose to reinstall 7.2.3 without first uninstalling it, will that work?  What is the Windows command to query the FIPS status on the Splunk server?

Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

FIPS has to be enabled before starting Splunk for the first time.  Enable FIPS in the config files.  Furthermore, FIPS is only supported on Linux systems so there's no Windows command to query the FIPS setting.  See https://docs.splunk.com/Documentation/Splunk/8.0.4/Security/SecuringSplunkEnterprisewithFIPS

---
If this reply helps you, Karma would be appreciated.
0 Karma

kchongMITRE
Observer

Thanks for the quick response!

I am having some authentication issue.  When running Splunk command in the Command Prompt, I am able to logon as admin.  However, when I tried to logon using admin through the web UI, I am not able to log on at all.  Also, I am not able to logon using my AD account neither.  Any idea?

0 Karma

richgalloway
SplunkTrust
SplunkTrust
You should post a new question since this is not related to FIPS.
---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Fall Into Learning with New Splunk Education Courses

Every month, Splunk Education releases new courses to help you branch out, strengthen your data science roots, ...

Super Optimize your Splunk Stats Searches: Unlocking the Power of tstats, TERM, and ...

By Martin Hettervik, Senior Consultant and Team Leader at Accelerate at Iver, Splunk MVPThe stats command is ...

How Splunk Observability Cloud Prevented a Major Payment Crisis in Minutes

Your bank's payment processing system is humming along during a busy afternoon, handling millions in hourly ...