<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Small Deployment Splunk for SOC in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/Small-Deployment-Splunk-for-SOC/m-p/452844#M21013</link>
    <description>&lt;P&gt;hello there,&lt;BR /&gt;
plenty of information is missing, examples:&lt;BR /&gt;
how much data (gp per day) do you plan to ingest?&lt;BR /&gt;
what are the indexer and search head specs? (CPU, Memory, Disk)&lt;BR /&gt;
how may concurrent users (searches) are you anticipating?&lt;BR /&gt;
do you plan to scale in the future?&lt;/P&gt;

&lt;P&gt;however, your overall topology makes sense and seems like a good start&lt;BR /&gt;
good luck, and please share your progress and challenges and we would love to assist on your journey&lt;/P&gt;

&lt;P&gt;hope it helps&lt;/P&gt;</description>
    <pubDate>Sun, 24 Mar 2019 01:15:21 GMT</pubDate>
    <dc:creator>adonio</dc:creator>
    <dc:date>2019-03-24T01:15:21Z</dc:date>
    <item>
      <title>Small Deployment Splunk for SOC</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Small-Deployment-Splunk-for-SOC/m-p/452843#M21012</link>
      <description>&lt;P&gt;Now I want to learn to make Splunk on a small scale for SOC, but before that, let me give you a picture of the topology that I will make at home.&lt;/P&gt;

&lt;P&gt;It's topology is right to build? and is this possible to run accordingly?&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://ibb.co/kyXjPC9"&gt;https://ibb.co/kyXjPC9&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;&lt;STRONG&gt;For Details:&lt;/STRONG&gt;&lt;BR /&gt;
SH   : 192.168.1.20&lt;BR /&gt;
IDX  : 192.168.1.21&lt;BR /&gt;
UF1 : 192.168.1.30 | UF2 : 192.168.1.31 | HF1 : 192.168.1.32&lt;/P&gt;

&lt;P&gt;Of all this, what I really need is to get data from snort.. I want to use Firegen for Snort App but that requires the help of the Splunk DB Connect App that I will install on HF. That way, later the DB Connect App will be connected toanyard2's MySQL in snort.&lt;/P&gt;

&lt;P&gt;Please.. teach me and give me advice.. I want to learn more about Splunk.&lt;BR /&gt;
Thank you&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Links:&lt;/STRONG&gt;&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;DB Connect App - &lt;A href="https://splunkbase.splunk.com/app/2686/"&gt;https://splunkbase.splunk.com/app/2686/&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;Firegen for Snort App - &lt;A href="https://splunkbase.splunk.com/app/4118/"&gt;https://splunkbase.splunk.com/app/4118/&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;Splunk Docs - &lt;A href="https://docs.splunk.com/Documentation/DBX/3.1.4/DeployDBX/HowSplunkDBConnectworks"&gt;https://docs.splunk.com/Documentation/DBX/3.1.4/DeployDBX/HowSplunkDBConnectworks&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;Firegen Readme File - &lt;A href="https://pastebin.com/VDXkR71n"&gt;https://pastebin.com/VDXkR71n&lt;/A&gt;&lt;/LI&gt;
&lt;/OL&gt;</description>
      <pubDate>Fri, 22 Mar 2019 07:52:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Small-Deployment-Splunk-for-SOC/m-p/452843#M21012</guid>
      <dc:creator>gibranduatiga</dc:creator>
      <dc:date>2019-03-22T07:52:07Z</dc:date>
    </item>
    <item>
      <title>Re: Small Deployment Splunk for SOC</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Small-Deployment-Splunk-for-SOC/m-p/452844#M21013</link>
      <description>&lt;P&gt;hello there,&lt;BR /&gt;
plenty of information is missing, examples:&lt;BR /&gt;
how much data (gp per day) do you plan to ingest?&lt;BR /&gt;
what are the indexer and search head specs? (CPU, Memory, Disk)&lt;BR /&gt;
how may concurrent users (searches) are you anticipating?&lt;BR /&gt;
do you plan to scale in the future?&lt;/P&gt;

&lt;P&gt;however, your overall topology makes sense and seems like a good start&lt;BR /&gt;
good luck, and please share your progress and challenges and we would love to assist on your journey&lt;/P&gt;

&lt;P&gt;hope it helps&lt;/P&gt;</description>
      <pubDate>Sun, 24 Mar 2019 01:15:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Small-Deployment-Splunk-for-SOC/m-p/452844#M21013</guid>
      <dc:creator>adonio</dc:creator>
      <dc:date>2019-03-24T01:15:21Z</dc:date>
    </item>
    <item>
      <title>Re: Small Deployment Splunk for SOC</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Small-Deployment-Splunk-for-SOC/m-p/452845#M21014</link>
      <description>&lt;P&gt;I am sorry for late reply..&lt;/P&gt;

&lt;P&gt;I want to process data as much as 20-50 GB per day.&lt;BR /&gt;
for IDX &amp;amp; SH specifications for example:&lt;BR /&gt;
Intel i7-5820K CPU 3.30GHz CPU&lt;BR /&gt;
32GB RAM with RAID&lt;/P&gt;

&lt;P&gt;for the future maybe I will add a scale to a larger one as the needs are needed.&lt;/P&gt;

&lt;P&gt;by the way, what about dns loadbalance? do I have to implement it too?&lt;/P&gt;

&lt;P&gt;thank you..... @adonio&lt;/P&gt;</description>
      <pubDate>Mon, 25 Mar 2019 00:33:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Small-Deployment-Splunk-for-SOC/m-p/452845#M21014</guid>
      <dc:creator>gibranduatiga</dc:creator>
      <dc:date>2019-03-25T00:33:10Z</dc:date>
    </item>
  </channel>
</rss>

