Splunk Enterprise

Splunk Certificate 8089 Port

edgarsilva01
Path Finder

Hello

I'm trying to install a web certificate for port 8089, I don't know what I'm doing wrong.
There are already 3 scans and the vulnerability continues to appear.

Someone who has already solved it

This is the stanza I have in the web.conf file

[settings]
enableSplunkWebSSL = true
privKeyPath = /opt/splunk/etc/auth/mycerts/certificate.key
serverCert = /opt/splunk/etc/auth/mycerts/certificate.pem
 

Labels (2)
0 Karma

richgalloway
SplunkTrust
SplunkTrust
What problem are you trying to solve?
What "vulnerability" are you talking about?
Port 8089 is not "SplunkWeb". It's the Splunk management port used by Splunk instances to talk to each other. Change the security on that post and you could break your Splunk installation.
"SplunkWeb" is port 8000.
---
If this reply helps you, Karma would be appreciated.
0 Karma

edgarsilva01
Path Finder

Hi richgalloway

The problem I have is that a scan was performed to one of the servers where a universal forwarder is installed and a vulnerability in port 8089 of the splunk service was detected.

To solve this problem, a digital certificate was requested, upload it to the deployment server, in a second scan the vulnerability is still active

0 Karma

richgalloway
SplunkTrust
SplunkTrust
You don't say what vulnerability was reported, but perhaps this answer will solve your problem: https://community.splunk.com/t5/Security/Splunk-Enterprise-8089-Vulnerability-Scan-Results-Resolve-t...
It's not enough to put a certificate on the DS - it must be installed on the UF to protect the UF's management port.
---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to July and August Tech Talks, Office Hours, and Webinars!

Dive into our sizzling summer lineup for July and August Community Office Hours and Tech Talks. Scroll down to ...

Edge Processor Scaling, Energy & Manufacturing Use Cases, and More New Articles on ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Get More Out of Your Security Practice With a SIEM

Get More Out of Your Security Practice With a SIEMWednesday, July 31, 2024  |  11AM PT / 2PM ETREGISTER ...