SPLK-CL-000175 - Splunk Enterprise forwarders must be configured with Indexer Acknowledgement enabled.

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

To prevent the loss of data during transmission, a handshake acknowledgement between the sender and the recipient may need configured.

Solution

If the server is not a forwarder, this check is N/A.

In the Splunk installation folder, edit the following file in the $SPLUNK_HOME/etc/system/local folder:

outputs.conf

Locate the section similar to:

[tcpout:group1]

Note that group1 may be named differently depending on how tcpout was configured.

Add the following line under the group stanza above:

useACK=true

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Splunk_Enterprise_7-x_for_Windows_V2R3_STIG.zip

Item Details

References: CAT|III, CCI|CCI-000366, Rule-ID|SV-221936r508660_rule, STIG-ID|SPLK-CL-000175, STIG-Legacy|SV-111327, STIG-Legacy|V-102377, Vuln-ID|V-221936

Plugin: Windows

Control ID: 0ce5cdb87143c086c501a0f4004cde6e6a0856d631fda3717c7fbf0fe6059f86