SV-221614r508660_rule
V-221614
SRG-APP-000516-AU-000340
SPLK-CL-000170
CAT II
10
Select Settings >> Data Inputs, and verify there are zero inputs configured under UDP. Remove any that exist and recreate using TCP.
It is recommended to set these settings before disabling the web UI of the instance in a distributed environment.
Select Settings >> Data Inputs, and verify there are zero inputs configured under UDP. Splunk supports UDP, but it is not permissible to use.
If any exist, this is a finding.
If the Web UI is disabled, open an OS command prompt and type:
netstat -a -p UDP
If a UDP connection is displayed for 0.0.0.0:514, the instance is listening for Syslog port 514 in UDP, and this is a finding.
V-221614
False
SPLK-CL-000170
Select Settings >> Data Inputs, and verify there are zero inputs configured under UDP. Splunk supports UDP, but it is not permissible to use.
If any exist, this is a finding.
If the Web UI is disabled, open an OS command prompt and type:
netstat -a -p UDP
If a UDP connection is displayed for 0.0.0.0:514, the instance is listening for Syslog port 514 in UDP, and this is a finding.
M
4082