SV-221602r508660_rule
V-221602
SRG-APP-000148-AU-002270
SPLK-CL-000030
CAT I
10
Select Settings >> Access Controls >> Users.
Delete any user account with Authentication system set to Splunk, with the exception of one emergency account of last resort. Splunk will prevent the user from deleting an LDAP account.
Select Settings >> Access Controls >> Users.
Verify that no user accounts exist with Authentication system set to Splunk except an account of last resort. They should all be set to LDAP or SAML.
If any user accounts have Authentication system set to Splunk, with the exception of one emergency account of last resort, this is a finding.
V-221602
False
SPLK-CL-000030
Select Settings >> Access Controls >> Users.
Verify that no user accounts exist with Authentication system set to Splunk except an account of last resort. They should all be set to LDAP or SAML.
If any user accounts have Authentication system set to Splunk, with the exception of one emergency account of last resort, this is a finding.
M
4082