About securing the Splunk platform
The Splunk platform provides frameworks that prevent unauthorized access to the platform and the data that you store in it. These frameworks include the following:
- Role-based access control (RBAC)
- Securement of configurations, data ingestion points, data storage, and internal and external communications using various certificates and encryption schemes
- Obfuscation of credential details as you log in
The Splunk platform secures and encrypts your configurations and data ingestion points using the latest in transport layer security (TLS) technology, and you can easily secure access to your apps and data by using RBAC to limit who can see what. Read this manual to learn how to configure this access.
You can further secure configurations and your data in Splunk Enterprise by setting up security certificates and encryption for both Splunk Web and internal Splunk communications. Performing these additional steps on your Splunk Enterprise installation reduces its attack surface and mitigates the risk and impact of most vulnerabilities.
Some hardening procedures are simple, such as confirming that your Splunk platform instances are physically secure and that your properly manage Splunk credentials and role-based access. Others, such as configuring encryption, are more complex, but are equally as important to the integrity of your data.
Read this manual to learn about the security concepts that you must consider with regard to the Splunk platform:
- How to manage role-based access control on Splunk Cloud Platform and Splunk Enterprise using various authentication schemes
- How to use certificates to secure indexers, forwarders, and Splunk Web on Splunk Enterprise, where data is most vulnerable
- How to securely install and configure your Splunk Enterprise installation
- How to use encryption to secure your configuration information on Splunk Enterprise
- How to use auditing to keep track of activity on your Splunk Enterprise instance
Get started with securing the Splunk platform
See the following topics to quickly learn how to secure your Splunk platform instance or deployment.
- How to secure and harden your Splunk software installation for a checklist and roadmap to make your Splunk configuration and data as secure as possible.
- Install Splunk Enterprise securely for instructions on how to install Splunk Enterprise securely.
- Use access control to secure Splunk data to learn about Splunk role-based access control and how to use it.
- About user authentication to learn about Splunk authentication schemes and how they work
- Password best practices for Splunk administrators and users
- Introduction to securing the Splunk platform with TLS to learn how to use TLS certificates to secure the connection points in your Splunk platform infrastructure
- Protect PII and PHI data with role-based field filtering to learn how to protect personal data that you have indexed into the Splunk platform
See the chapters to the left for additional opportunities to protect your Splunk platform instance and the data it houses.
How to secure and harden your Splunk platform instance |
This documentation applies to the following versions of Splunk Cloud Platform™: 8.2.2112, 8.2.2201, 8.2.2202, 8.2.2203, 9.0.2205, 9.0.2208, 9.0.2209, 9.0.2303, 9.0.2305, 9.1.2308, 9.1.2312, 9.2.2403, 9.2.2406 (latest FedRAMP release), 9.3.2408
Feedback submitted, thanks!