STIGQter STIGQter: STIG Summary: Ivanti EPMM Server Security Technical Implementation Guide Version: 3 Release: 1 Benchmark Date: 24 Oct 2024:

The Ivanti EPMM server must, at a minimum, off-load audit logs of interconnected systems in real time and off-load standalone systems weekly.

DISA Rule

SV-251421r1004748_rule

Vulnerability Number

V-251421

Group Title

SRG-APP-000515-UEM-000390

Rule Version

IMIC-11-012500

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Complete the following activities to configure the transfer of MobileIron Core 11 server logs:

Configure Splunk for automated log export:

Step 1: Enable Core to turn on the Splunk Forwarder so it can push data to the Splunk Indexer.

To enable the Splunk Forwarder:
1. Log in to System Manager.
2. Go to Settings >> Services.
3. Select "Enable" next to Splunk Forwarder.
4. Click Apply >> OK to save the changes.

Step 2: Add a Splunk Indexer to configure which external Splunk Indexer will receive and manipulate the data from the Splunk Forwarder.

To add a Splunk Indexer:
1. Log in to System Manager.
2. Go to Settings >> Data Export >> Splunk Indexer.
3. Click "Add" to open the Add Splunk Indexer window.
4. Modify the fields, as necessary, in the "Add Splunk Indexer" window. The following fields and descriptions are in the Add Splunk Indexer window:
- Splunk Indexer - Add the IP address of your Splunk Enterprise Server.
- Port - Add port of your Splunk Enterprise Server.
- Enable SSL - Click this check box to enable SSL.
5. Click Apply >> OK to save the changes.

Step 3: Configure Splunk Data to configure which data Splunk Forwarder sends to the Splunk Indexer.

To configure Splunk Data:
1. Log in to System Manager.
2. Go to Settings >> Data Export >> Splunk Data to open the "Data to Index" window.
3. Modify the fields, as necessary.
- Click Show/Hide Advanced Options to further customize which data to send to Splunk.
- Check "Audit Log" at a minimum.
4. Click Apply >> OK.
5. Restart the Splunk Forwarder by disabling it, then enabling it again.
a. Go to Settings >> Services.
b. Select Disable next to Splunk Forwarder.
c. Click Apply >> OK.
d. Select Enable next to Splunk Forwarder.
6. Click Apply >> OK to save the changes.

Check Contents

Verify that Splunk is configured for automated log export.

Step 1: Verify that the Splunk Forwarder is enabled.
1. Log in to System Manager.
2. Go to Settings >> Services.
3. Verify that the "Enable" toggle is ON and "Running" is displayed.
If "Enable" toggle is not ON or "Running" is not displayed, this is a finding.

Step 2: Verify that Splunk Indexer is configured.
1. Log in to System Manager.
2. Go to Settings >> Data Export >> Splunk Indexer.
3. Verify that there is an entry and the Status is "Connected".
If there is no entry for Splunk Indexer or the Status is "Not Connected", this is a finding.

Step 3: Verify "Audit Log" is enabled in the Splunk "data to index".
1. Log in to System Manager.
2. Go to Settings >> Data Export >> Splunk Data to open the "Data to Index" window.
3. Verify "Audit Log" is included in the "Data To Index".
If "Audit Log" is not included in the "Data To Index", this is a finding.

Vulnerability Number

V-251421

Documentable

False

Rule Version

IMIC-11-012500

Severity Override Guidance

Verify that Splunk is configured for automated log export.

Step 1: Verify that the Splunk Forwarder is enabled.
1. Log in to System Manager.
2. Go to Settings >> Services.
3. Verify that the "Enable" toggle is ON and "Running" is displayed.
If "Enable" toggle is not ON or "Running" is not displayed, this is a finding.

Step 2: Verify that Splunk Indexer is configured.
1. Log in to System Manager.
2. Go to Settings >> Data Export >> Splunk Indexer.
3. Verify that there is an entry and the Status is "Connected".
If there is no entry for Splunk Indexer or the Status is "Not Connected", this is a finding.

Step 3: Verify "Audit Log" is enabled in the Splunk "data to index".
1. Log in to System Manager.
2. Go to Settings >> Data Export >> Splunk Data to open the "Data to Index" window.
3. Verify "Audit Log" is included in the "Data To Index".
If "Audit Log" is not included in the "Data To Index", this is a finding.

Check Content Reference

M

Target Key

5445