Splunk Enterprise

log4j vulnerable files are getting recreated after removal(CVE-2021-44228. )

imsidrai
Explorer

we followed the steps provided on https://www.splunk.com/en_us/blog/bulletins/splunk-security-advisory-for-apache-log4j-cve-2021-44228... but it seems that files are being recreated , Can anyone please help on that ??,
Also i wanted to know if replacing just Apache version rather upgrading splunk could  help to mitigate ?
and what should be the steps if i replace?

Tags (1)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

Which files are you talking about?  Are they actually being recreated or is the deletion failing?  Are the files showing up in the splunk_archiver app?  If so, the blog says what to do about that.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

0 Karma

japonter
Explorer

did you just delete the 4 paths the documents say. i have been looking for more clarification into this. as i read it just indicates to delete those 4 paths and that should be it. is this true?

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Which files are you talking about?  Are they actually being recreated or is the deletion failing?  Are the files showing up in the splunk_archiver app?  If so, the blog says what to do about that.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

What's New in Splunk Enterprise 9.4: Features to Power Your Digital Resilience

Hey Splunky People! We are excited to share the latest updates in Splunk Enterprise 9.4. In this release we ...

Take Your Breath Away with Splunk Risk-Based Alerting (RBA)

WATCH NOW!The Splunk Guide to Risk-Based Alerting is here to empower your SOC like never before. Join Haylee ...

SignalFlow: What? Why? How?

What is SignalFlow? Splunk Observability Cloud’s analytics engine, SignalFlow, opens up a world of in-depth ...