Rule ID
SV-221938r1043182_rule
Version
V3R2
CCIs
Automatic session termination after a period of inactivity addresses the potential for a malicious actor to exploit the unattended session. Closing any unattended sessions reduces the attack surface to the application.
Select Settings >> Server Settings >> General Settings and verify that Session timeout is set to 15 minutes or less. If Splunk is not configured to 15 minutes or less, this is a finding.
Select Settings >> Server Settings >> General Settings and set Session timeout to 15 minutes or less.