Splunk Enterprise

Splunk Certificate 8089 Port

edgarsilva01
Path Finder

Hello

I'm trying to install a web certificate for port 8089, I don't know what I'm doing wrong.
There are already 3 scans and the vulnerability continues to appear.

Someone who has already solved it

This is the stanza I have in the web.conf file

[settings]
enableSplunkWebSSL = true
privKeyPath = /opt/splunk/etc/auth/mycerts/certificate.key
serverCert = /opt/splunk/etc/auth/mycerts/certificate.pem
 

Labels (2)
0 Karma

richgalloway
SplunkTrust
SplunkTrust
What problem are you trying to solve?
What "vulnerability" are you talking about?
Port 8089 is not "SplunkWeb". It's the Splunk management port used by Splunk instances to talk to each other. Change the security on that post and you could break your Splunk installation.
"SplunkWeb" is port 8000.
---
If this reply helps you, Karma would be appreciated.
0 Karma

edgarsilva01
Path Finder

Hi richgalloway

The problem I have is that a scan was performed to one of the servers where a universal forwarder is installed and a vulnerability in port 8089 of the splunk service was detected.

To solve this problem, a digital certificate was requested, upload it to the deployment server, in a second scan the vulnerability is still active

0 Karma

richgalloway
SplunkTrust
SplunkTrust
You don't say what vulnerability was reported, but perhaps this answer will solve your problem: https://community.splunk.com/t5/Security/Splunk-Enterprise-8089-Vulnerability-Scan-Results-Resolve-t...
It's not enough to put a certificate on the DS - it must be installed on the UF to protect the UF's management port.
---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Splunk Observability Cloud's AI Assistant in Action Series: Auditing Compliance and ...

This is the third post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how to ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

What You Read The Most: Splunk Lantern’s Most Popular Articles!

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...