Splunk Enterprise

log4j vulnerable files are getting recreated after removal(CVE-2021-44228. )

imsidrai
Explorer

we followed the steps provided on https://www.splunk.com/en_us/blog/bulletins/splunk-security-advisory-for-apache-log4j-cve-2021-44228... but it seems that files are being recreated , Can anyone please help on that ??,
Also i wanted to know if replacing just Apache version rather upgrading splunk could  help to mitigate ?
and what should be the steps if i replace?

Tags (1)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

Which files are you talking about?  Are they actually being recreated or is the deletion failing?  Are the files showing up in the splunk_archiver app?  If so, the blog says what to do about that.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

0 Karma

japonter
Explorer

did you just delete the 4 paths the documents say. i have been looking for more clarification into this. as i read it just indicates to delete those 4 paths and that should be it. is this true?

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Which files are you talking about?  Are they actually being recreated or is the deletion failing?  Are the files showing up in the splunk_archiver app?  If so, the blog says what to do about that.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...