Splunk Enterprise

log4j vulnerable files are getting recreated after removal(CVE-2021-44228. )

imsidrai
Explorer

we followed the steps provided on https://www.splunk.com/en_us/blog/bulletins/splunk-security-advisory-for-apache-log4j-cve-2021-44228... but it seems that files are being recreated , Can anyone please help on that ??,
Also i wanted to know if replacing just Apache version rather upgrading splunk could  help to mitigate ?
and what should be the steps if i replace?

Tags (1)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

Which files are you talking about?  Are they actually being recreated or is the deletion failing?  Are the files showing up in the splunk_archiver app?  If so, the blog says what to do about that.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

0 Karma

japonter
Explorer

did you just delete the 4 paths the documents say. i have been looking for more clarification into this. as i read it just indicates to delete those 4 paths and that should be it. is this true?

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Which files are you talking about?  Are they actually being recreated or is the deletion failing?  Are the files showing up in the splunk_archiver app?  If so, the blog says what to do about that.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...