SPLK-CL-000270 - Splunk Enterprise must use TCP for data transmission.

Information

If the UDP protocol is used for communication, then data packets that do not reach the server are not detected as a data loss. The use of TCP to transport data improves delivery reliability, adds data integrity, and gives the option to encrypt the traffic.

Solution

This configuration is performed on the machine used as an indexer, which may be a separate machine in a distributed environment.

Navigate to $SPLUNK_HOME/etc/system/local/

Modify the inputs.conf file to replace any input that is using a UDP port with a TCP port.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Splunk_Enterprise_8-x_for-Linux_V1R5_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|II, CCI|CCI-000366, Rule-ID|SV-251675r879887_rule, STIG-ID|SPLK-CL-000270, Vuln-ID|V-251675

Plugin: Splunk

Control ID: b571f06e9a0bd728a380fd75d2a3e41a3db2b842d1fb8e312c9708f36fd47d02