Item Search

NameAudit NamePluginCategory
DISA_STIG_Docker_Enterprise_2.x_Linux_Unix_DTR_v2r2.audit from DISA Docker Enterprise 2.x Linux/UNIX v2r2 STIGDISA STIG Docker Enterprise 2.x Linux/Unix DTR v2r2Unix
DISA_STIG_Docker_Enterprise_2.x_Linux_Unix_UCP_v2r2.audit from DISA Docker Enterprise 2.x Linux/UNIX v2r2 STIGDISA STIG Docker Enterprise 2.x Linux/Unix UCP v2r2Unix
DISA_STIG_Docker_Enterprise_2.x_Linux_Unix_v2r2.audit from DISA Docker Enterprise 2.x Linux/UNIX v2r2 STIGDISA STIG Docker Enterprise 2.x Linux/Unix v2r2Unix
DISA_STIG_MongoDB_Enterprise_Advanced_8.x_v1r1_Unix.audit from DISA MongoDB Enterprise Advanced 8.x STIG v1r1DISA MongoDB Enterprise Advanced 8.x STIG v1r1 UnixUnix
DISA_STIG_Oracle_Database_19c_v1r5_Unix.audit from DISA Oracle Database 19c STIG v1r5DISA Oracle Database 19c STIG v1r5 UnixUnix
DISA_STIG_Oracle_Database_19c_v1r5_Windows.audit from DISA Oracle Database 19c STIG v1r5DISA Oracle Database 19c STIG v1r5 WindowsWindows
DISA_STIG_Oracle_Linux_9_v1r5.audit from DISA Oracle Linux 9 STIG v1r5DISA Oracle Linux 9 STIG v1r5Unix
DISA_STIG_Red_Hat_Enterprise_Linux_8_v2r7.audit from DISA Red Hat Enterprise Linux 8 STIG v2r7DISA Red Hat Enterprise Linux 8 STIG v2r7Unix
DISA_STIG_Splunk_Enterprise_7.x_for_Windows_OS_v3r2.audit from DISA Splunk Enterprise 7.x for Windows v3r2 STIGDISA STIG Splunk Enterprise 7.x for Windows v3r2 OSWindows
DISA_STIG_Splunk_Enterprise_7.x_for_Windows_REST_API_v3r2.audit from DISA Splunk Enterprise 7.x for Windows v3r2 STIGDISA STIG Splunk Enterprise 7.x for Windows v3r2 REST APISplunk
DISA_STIG_Splunk_Enterprise_8.x_for_Linux_OS_v2r3.audit from DISA Splunk Enterprise 8.x for Linux v2r3 STIGDISA STIG Splunk Enterprise 8.x for Linux v2r3 STIG OSUnix
DISA_STIG_Splunk_Enterprise_8.x_for_Linux_REST_API_v2r3.audit from DISA Splunk Enterprise 8.x for Linux v2r3 STIGDISA STIG Splunk Enterprise 8.x for Linux v2r3 STIG REST APISplunk
SPLK-CL-000020 - Splunk Enterprise must notify the system administrator (SA) and information system security officer (ISSO) when account events are received (creation, deletion, modification, or disabling) - creation, deletion, modification, or disabling.DISA STIG Splunk Enterprise 8.x for Linux v2r3 STIG REST APISplunk

ACCESS CONTROL

SPLK-CL-000030 - Splunk Enterprise must have all local user accounts removed after implementing organizational level user management system, except for one emergency account of last resort.DISA STIG Splunk Enterprise 7.x for Windows v3r2 REST APISplunk

IDENTIFICATION AND AUTHENTICATION

SPLK-CL-000040 - Splunk Enterprise must only allow the use of DOD-approved certificate authorities for cryptographic functions.DISA STIG Splunk Enterprise 7.x for Windows v3r2 REST APISplunk

SYSTEM AND COMMUNICATIONS PROTECTION

SPLK-CL-000050 - Splunk Enterprise must use TLS 1.2 and SHA-2 or higher cryptographic algorithms.DISA STIG Splunk Enterprise 7.x for Windows v3r2 REST APISplunk

IDENTIFICATION AND AUTHENTICATION

SPLK-CL-000060 - Splunk Enterprise must use HTTPS/SSL for access to the user interface.DISA STIG Splunk Enterprise 7.x for Windows v3r2 REST APISplunk

IDENTIFICATION AND AUTHENTICATION

SPLK-CL-000070 - Splunk Enterprise must use SSL to protect the confidentiality and integrity of transmitted information.DISA STIG Splunk Enterprise 7.x for Windows v3r2 REST APISplunk

SYSTEM AND COMMUNICATIONS PROTECTION

SPLK-CL-000080 - Splunk Enterprise must display the Standard Mandatory DOD Notice and Consent Banner before granting access to the server.DISA STIG Splunk Enterprise 8.x for Linux v2r3 STIG REST APISplunk

ACCESS CONTROL

SPLK-CL-000090 - When Splunk Enterprise is distributed over multiple servers, each server must be configured to disable non-essential capabilities.DISA STIG Splunk Enterprise 7.x for Windows v3r2 REST APISplunk

CONFIGURATION MANAGEMENT

SPLK-CL-000100 - Splunk Enterprise must be configured to aggregate log records from organization-defined devices and hosts within its scope of coverage.DISA STIG Splunk Enterprise 8.x for Linux v2r3 STIG REST APISplunk

AUDIT AND ACCOUNTABILITY

SPLK-CL-000110 - In a distributed environment, Splunk Enterprise indexers must be configured to ingest log records from its forwarders.DISA STIG Splunk Enterprise 8.x for Linux v2r3 STIG REST APISplunk

AUDIT AND ACCOUNTABILITY

SPLK-CL-000130 - Splunk Enterprise must be configured to retain the DoD-defined attributes of the log records sent by the devices and hosts.DISA STIG Splunk Enterprise 8.x for Linux v2r3 STIG REST APISplunk

AUDIT AND ACCOUNTABILITY

SPLK-CL-000140 - Splunk Enterprise must allow only the individuals appointed by the information system security manager (ISSM) to have full admin rights to the system - ISSM to have full admin rights to the system.DISA STIG Splunk Enterprise 8.x for Linux v2r3 STIG REST APISplunk

AUDIT AND ACCOUNTABILITY

SPLK-CL-000150 - Splunk Enterprise must be configured to offload log records onto a different system or media than the system being audited.DISA STIG Splunk Enterprise 8.x for Linux v2r3 STIG REST APISplunk

AUDIT AND ACCOUNTABILITY

SPLK-CL-000160 - Splunk Enterprise must be configured to protect the log data stored in the indexes from alteration.DISA STIG Splunk Enterprise 7.x for Windows v3r2 REST APISplunk

AUDIT AND ACCOUNTABILITY

SPLK-CL-000160 - Splunk Enterprise must be configured to send an immediate alert to the system administrator (SA) and information system security officer (ISSO) (at a minimum) when allocated log record storage volume reaches 75 percent of the repository maximum log record storage capacity - at a minimum when allocated log record storage volume reaches 75 percent of the repository maximum log record storage capacity.DISA STIG Splunk Enterprise 8.x for Linux v2r3 STIG REST APISplunk

AUDIT AND ACCOUNTABILITY

SPLK-CL-000170 - Splunk Enterprise must notify the System Administrator (SA) and Information System Security Officer (ISSO) (at a minimum) of all audit failure events, such as loss of communications with hosts and devices, or if log records are no longer being received.DISA STIG Splunk Enterprise 8.x for Linux v2r3 STIG REST APISplunk

AUDIT AND ACCOUNTABILITY

SPLK-CL-000170 - Splunk Enterprise must use TCP for data transmission.DISA STIG Splunk Enterprise 7.x for Windows v3r2 REST APISplunk

CONFIGURATION MANAGEMENT

SPLK-CL-000180 - Splunk Enterprise must notify the System Administrator (SA) or Information System Security Officer (ISSO) if communication with the host and devices within its scope of coverage is lost.DISA STIG Splunk Enterprise 8.x for Linux v2r3 STIG REST APISplunk

AUDIT AND ACCOUNTABILITY

SPLK-CL-000250 - Splunk Enterprise must be configured to aggregate log records from organization-defined devices and hosts within its scope of coverage.DISA STIG Splunk Enterprise 7.x for Windows v3r2 REST APISplunk

AUDIT AND ACCOUNTABILITY

SPLK-CL-000250 - Splunk Enterprise must be configured to back up the log records repository at least every seven days onto a different system or system component other than the system or component being audited.DISA STIG Splunk Enterprise 8.x for Linux v2r3 STIG REST APISplunk

AUDIT AND ACCOUNTABILITY

SPLK-CL-000260 - Splunk Enterprise must be configured to retain the identity of the original source host or device where the event occurred as part of the log record.DISA STIG Splunk Enterprise 8.x for Linux v2r3 STIG REST APISplunk

CONFIGURATION MANAGEMENT

SPLK-CL-000270 - Splunk Enterprise must use TCP for data transmission.DISA STIG Splunk Enterprise 8.x for Linux v2r3 STIG REST APISplunk

CONFIGURATION MANAGEMENT

SPLK-CL-000280 - Splunk Enterprise must be configured with a report to notify the System Administrator (SA) and Information System Security Officer (ISSO), at a minimum, when an attack is detected on multiple devices and hosts within its scope of coverage.DISA STIG Splunk Enterprise 8.x for Linux v2r3 STIG REST APISplunk

CONFIGURATION MANAGEMENT

SPLK-CL-000280 - Splunk Enterprise must be configured with a successful/unsuccessful logon attempts report.DISA STIG Splunk Enterprise 7.x for Windows v3r2 REST APISplunk

AUDIT AND ACCOUNTABILITY

SPLK-CL-000290 - Analysis, viewing, and indexing functions, services, and applications used as part of Splunk Enterprise must be configured to comply with DoD-trusted path and access requirements.DISA STIG Splunk Enterprise 8.x for Linux v2r3 STIG REST APISplunk

CONFIGURATION MANAGEMENT

SPLK-CL-000300 - Splunk Enterprise must notify the System Administrator (SA) and Information System Security Officer (ISSO) (at a minimum) of all audit failure events, such as loss of communications with hosts and devices, or if log records are no longer being received.DISA STIG Splunk Enterprise 7.x for Windows v3r2 REST APISplunk

AUDIT AND ACCOUNTABILITY

SPLK-CL-000300 - When Splunk Enterprise is distributed over multiple servers, each server must be configured to disable non-essential capabilities.DISA STIG Splunk Enterprise 8.x for Linux v2r3 STIG REST APISplunk

CONFIGURATION MANAGEMENT

SPLK-CL-000310 - Splunk Enterprise must notify the System Administrator (SA) or Information System Security Officer (ISSO) if communication with the host and devices within its scope of coverage is lost.DISA STIG Splunk Enterprise 7.x for Windows v3r2 REST APISplunk

AUDIT AND ACCOUNTABILITY

SPLK-CL-000320 - Splunk Enterprise must be configured to notify the System Administrator (SA) and Information System Security Officer (ISSO), at a minimum, when an attack is detected on multiple devices and hosts within its scope of coverage.DISA STIG Splunk Enterprise 7.x for Windows v3r2 REST APISplunk

CONFIGURATION MANAGEMENT

SPLK-CL-000320 - Splunk Enterprise must use organization-level authentication to uniquely identify and authenticate users.DISA STIG Splunk Enterprise 8.x for Linux v2r3 STIG REST APISplunk

IDENTIFICATION AND AUTHENTICATION

SPLK-CL-000330 - Splunk Enterprise must enforce password complexity for the account of last resort by requiring that at least one uppercase character be used.DISA STIG Splunk Enterprise 7.x for Windows v3r2 REST APISplunk

IDENTIFICATION AND AUTHENTICATION

SPLK-CL-000330 - Splunk Enterprise must use HTTPS/SSL for access to the user interface.DISA STIG Splunk Enterprise 8.x for Linux v2r3 STIG REST APISplunk

IDENTIFICATION AND AUTHENTICATION

SPLK-CL-000340 - Splunk Enterprise must enforce password complexity for the account of last resort by requiring that at least one lowercase character be used.DISA STIG Splunk Enterprise 7.x for Windows v3r2 REST APISplunk

IDENTIFICATION AND AUTHENTICATION

SPLK-CL-000350 - Splunk Enterprise must enforce password complexity for the account of last resort by requiring that at least one numeric character be used.DISA STIG Splunk Enterprise 7.x for Windows v3r2 REST APISplunk

IDENTIFICATION AND AUTHENTICATION

SPLK-CL-000390 - Splunk Enterprise must be installed in FIPS mode to implement NIST FIPS-approved cryptography for all cryptographic functions.DISA STIG Splunk Enterprise 8.x for Linux v2r3 STIG REST APISplunk

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

SPLK-CL-000450 - Splunk Enterprise must only allow the use of DOD-approved certificate authorities for cryptographic functions.DISA STIG Splunk Enterprise 8.x for Linux v2r3 STIG REST APISplunk

SYSTEM AND COMMUNICATIONS PROTECTION

SPLK-CL-000460 - Splunk Enterprise must be configured to protect the confidentiality and integrity of transmitted information.DISA STIG Splunk Enterprise 8.x for Linux v2r3 STIG REST APISplunk

SYSTEM AND COMMUNICATIONS PROTECTION

SPLK-CL-000490 - Splunk Enterprise must accept the DOD CAC or other PKI credential for identity management and personal authentication.DISA STIG Splunk Enterprise 8.x for Linux v2r3 STIG REST APISplunk

IDENTIFICATION AND AUTHENTICATION