SV-221621r508660_rule
V-221621
SRG-APP-000086-AU-000020
SPLK-CL-000250
CAT III
10
Configure Splunk Enterprise to aggregate log records from organization-defined devices and hosts within its scope of coverage, as defined in the site security plan.
Examine the site documentation that lists the scope of coverage for the instance being reviewed.
Select Settings >> Data Inputs. Verify that data inputs are configured to support the scope of coverage documented for the site.
If Splunk enterprise is not configured to aggregate log records from organization-defined devices and hosts within its scope of coverage, this is a finding.
V-221621
False
SPLK-CL-000250
Examine the site documentation that lists the scope of coverage for the instance being reviewed.
Select Settings >> Data Inputs. Verify that data inputs are configured to support the scope of coverage documented for the site.
If Splunk enterprise is not configured to aggregate log records from organization-defined devices and hosts within its scope of coverage, this is a finding.
M
4082