Security

How do I tell if we are using Splunk Web?

mpwhite
New Member

I am using Splunk Enterprise 6.6.1 and there is a security vulnerability that exploits Splunk Web that is resolved in 6.6.3. I go to my services running and there is a "splunkweb (for legacy purposes only)" service that is not running, so it appears that we do not use splunk web, although I can still access splunk from the web interface. How can I find out for sure if I am exposed to this vulnerability?

0 Karma

tmarlette
Motivator

if you're accessing splunk on port 8000, you are running splunkweb on port 8000. unless you deliberately turn it off in web.conf, splunkweb starts with Splunk.

in order to find out for sure, you would have to run intrusion tests on splunkweb, following the criteria of your specific vulnerability.

Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...

Updated Data Management and AWS GDI Inventory in Splunk Observability

We’re making some changes to Data Management and Infrastructure Inventory for AWS. The Data Management page, ...