Splunk® App for PCI Compliance

Installation and Configuration Manual

Anomalous System Uptime

This report provides a list of servers that have not had been rebooted in 30 days or more. Use this report to identify systems that might be vulnerable to attack.

Systems often need to be rebooted after patches are applied. Systems that have not been rebooted might still be vulnerable to compromise. PCI DSS requires that high and/or critical patches be applied within 30 days.

Relevant data sources

Relevant data sources for this report include uptime data extracted through scripts from Windows, Unix, or other hosts.

How to configure this report

  1. Index uptime information captured through scripts from relevant hosts.
  2. Map the uptime data to the following Common Information Model fields: dest, uptime. CIM-compliant add-ons for these data sources perform this step for you.
  3. Tag the uptime data with "uptime", "performance", and "os".
  4. Set the should_timesync column to true for assets in the asset table that should synchronize their clocks.

Report description

The Anomalous System Update report is populated by the Performance data model and the asset table.

Useful searches for troubleshooting

Troubleshooting Task Search/Action Expected Result
Verify that uptime data is available in Splunk platform. tag=uptime tag=os tag=performance Returns uptime data.
Verify that fields are normalized and available as expected. tag=uptime tag=os tag=performance | fields dest, uptime
or `uptime`
Returns uptime data fields.
Last modified on 14 February, 2022
System Update Status   PCI Command History

This documentation applies to the following versions of Splunk® App for PCI Compliance: 5.0.1, 5.0.2, 5.1.0, 5.1.1, 5.1.2, 5.2.0, 5.3.0, 5.3.1, 5.3.2

Was this topic useful?

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters