SPLK-CL-000170 - Splunk Enterprise must use TCP for data transmission.

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

If the UDP protocol is used for communication, then data packets that do not reach the server are not detected as a data loss. The use of TCP to transport data improves delivery reliability, adds data integrity, and gives the option to encrypt the traffic.

Solution

Select Settings >> Data Inputs, and verify there are zero inputs configured under UDP. Remove any that exist and recreate using TCP.

It is recommended to set these settings before disabling the web UI of the instance in a distributed environment.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Splunk_Enterprise_7-x_for_Windows_V2R3_STIG.zip

Item Details

References: CAT|II, CCI|CCI-000366, Rule-ID|SV-221614r508660_rule, STIG-ID|SPLK-CL-000170, STIG-Legacy|SV-111325, STIG-Legacy|V-102375, Vuln-ID|V-221614

Plugin: Splunk

Control ID: bdc28c0e54dedbaa97c85574c0758c4b60e226b31351596e1e393f49eeea27a2