UCF STIG Viewer Logo

Splunk Enterprise must be configured to retain the identity of the original source host or device where the event occurred as part of the log record.


Overview

Finding ID Version Rule ID IA Controls Severity
V-251674 SPLK-CL-000260 SV-251674r808258_rule Medium
Description
In this case the information producer is the device based on IP address or some other identifier of the device producing the information. The source of the record must be bound to the record using cryptographic means. Some events servers allow the administrator to retain only portions of the record sent by devices and hosts. This requirement applies to log aggregation servers with the role of fulfilling the DoD requirement for a central log repository. The syslog, SIEM, or other event servers must retain this information with each log record to support incident investigations.
STIG Date
Splunk Enterprise 8.x for Linux Security Technical Implementation Guide 2022-06-07

Details

Check Text ( C-55112r808256_chk )
Review the log records in Splunk Enterprise and verify that the log records retain the identity of the original source host or device where the event occurred.

If the log files do not retain the identity of the original source host or device where the event occurred, this is a finding.
Fix Text (F-55066r808257_fix)
Configure Splunk Enterprise to retain the identity of the original source host or device where the event occurred.

Use Splunk Enterprise to modify the props.conf file to include the identity of the original source host or device where the event occurred.