Hi  first your splunk installation is quite old and out of support. You should plan to update it to supported versions as soon as possible. Oldest supported version is currently 8.1.x. Unfortunately you need some middle versions to reach this target level, which are not available from splunk.com any more. You must contact to Splunk support and ask if they could give those to you.  The current knowledge is the core splunk is used log4j only for DFS and if that is not in use then there shouldn't be an issue. BUT as your version is out of support, I'm not sure if Splunk has verified that for your version (probably not).   Here is Splunk's information about this vulnerability:   https://www.splunk.com/en_us/blog/bulletins/splunk-security-advisory-for-apache-log4j-cve-2021-44228.html  https://www.splunk.com/en_us/blog/security/log-jammin-log4j-2-rce.html  https://www.splunk.com/en_us/blog/security/log4shell-detecting-log4j-vulnerability-cve-2021-44228-continued.html   My personal proposal to you is: try to update your splunk to current one as soon as possible.  r. Ismo 
						
					
					... View more