SV-221600r508660_rule
V-221600
SRG-APP-000514-AU-002890
SPLK-CL-000010
CAT I
10
FIPS 140-2 mode MUST be enabled during installation. If not enabled, it requires a reinstall or upgrade of the application.
The installer must be executed from the command line so that it can be passed the LAUNCHSPLUNK=0 parameter.
This allows Splunk to install and not automatically start up after install.
Example: msiexec /i <splunkinstaller.msi> LAUNCHSPLUNK=0
Using a text editor, edit $SPLUNK_HOME/etc/splunk-launch.conf file, add the line SPLUNK_FIPS=1 to it, restart the server, and then recheck this requirement.
Select the Search and Reporting App.
Execute a search query using the following:
| rest splunk_server=local /services/server/info | fields fips_mode
Verify that the report returns fips_mode = 1.
If the query returns 0, this is a finding.
V-221600
False
SPLK-CL-000010
Select the Search and Reporting App.
Execute a search query using the following:
| rest splunk_server=local /services/server/info | fields fips_mode
Verify that the report returns fips_mode = 1.
If the query returns 0, this is a finding.
M
4082