Splunk Enterprise

Splunk Certificate 8089 Port

edgarsilva01
Path Finder

Hello

I'm trying to install a web certificate for port 8089, I don't know what I'm doing wrong.
There are already 3 scans and the vulnerability continues to appear.

Someone who has already solved it

This is the stanza I have in the web.conf file

[settings]
enableSplunkWebSSL = true
privKeyPath = /opt/splunk/etc/auth/mycerts/certificate.key
serverCert = /opt/splunk/etc/auth/mycerts/certificate.pem
 

Labels (2)
0 Karma

richgalloway
SplunkTrust
SplunkTrust
What problem are you trying to solve?
What "vulnerability" are you talking about?
Port 8089 is not "SplunkWeb". It's the Splunk management port used by Splunk instances to talk to each other. Change the security on that post and you could break your Splunk installation.
"SplunkWeb" is port 8000.
---
If this reply helps you, Karma would be appreciated.
0 Karma

edgarsilva01
Path Finder

Hi richgalloway

The problem I have is that a scan was performed to one of the servers where a universal forwarder is installed and a vulnerability in port 8089 of the splunk service was detected.

To solve this problem, a digital certificate was requested, upload it to the deployment server, in a second scan the vulnerability is still active

0 Karma

richgalloway
SplunkTrust
SplunkTrust
You don't say what vulnerability was reported, but perhaps this answer will solve your problem: https://community.splunk.com/t5/Security/Splunk-Enterprise-8089-Vulnerability-Scan-Results-Resolve-t...
It's not enough to put a certificate on the DS - it must be installed on the UF to protect the UF's management port.
---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

 (view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...