Splunk Enterprise

Splunk Certificate 8089 Port

edgarsilva01
Path Finder

Hello

I'm trying to install a web certificate for port 8089, I don't know what I'm doing wrong.
There are already 3 scans and the vulnerability continues to appear.

Someone who has already solved it

This is the stanza I have in the web.conf file

[settings]
enableSplunkWebSSL = true
privKeyPath = /opt/splunk/etc/auth/mycerts/certificate.key
serverCert = /opt/splunk/etc/auth/mycerts/certificate.pem
 

Labels (2)
0 Karma

richgalloway
SplunkTrust
SplunkTrust
What problem are you trying to solve?
What "vulnerability" are you talking about?
Port 8089 is not "SplunkWeb". It's the Splunk management port used by Splunk instances to talk to each other. Change the security on that post and you could break your Splunk installation.
"SplunkWeb" is port 8000.
---
If this reply helps you, Karma would be appreciated.
0 Karma

edgarsilva01
Path Finder

Hi richgalloway

The problem I have is that a scan was performed to one of the servers where a universal forwarder is installed and a vulnerability in port 8089 of the splunk service was detected.

To solve this problem, a digital certificate was requested, upload it to the deployment server, in a second scan the vulnerability is still active

0 Karma

richgalloway
SplunkTrust
SplunkTrust
You don't say what vulnerability was reported, but perhaps this answer will solve your problem: https://community.splunk.com/t5/Security/Splunk-Enterprise-8089-Vulnerability-Scan-Results-Resolve-t...
It's not enough to put a certificate on the DS - it must be installed on the UF to protect the UF's management port.
---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Aligning Observability Costs with Business Value: Practical Strategies

 Join us for an engaging Tech Talk on Aligning Observability Costs with Business Value: Practical ...

Mastering Data Pipelines: Unlocking Value with Splunk

 In today's AI-driven world, organizations must balance the challenges of managing the explosion of data with ...

Splunk Up Your Game: Why It's Time to Embrace Python 3.9+ and OpenSSL 3.0

Did you know that for Splunk Enterprise 9.4, Python 3.9 is the default interpreter? This shift is not just a ...