Getting Data In

How to implement Splunk on Linux Platform?

fazilhussain
Explorer

Hello. Friends am new to Splunk. I have Basic knowledge on Windows Platform and learning day by day.
Need Help for Implementation on Linux Platform.
Below are the Servers listed for implementation with Splunk.
I request you to please help me on the step how i can start Configuration with the listed Servers with Splunk, this implementation is on Linux Centos Platform. Please provide me some guidance on the Linux Platform

Device Details (Please specify quantities specifically):-
1) 10 of Windows Servers-
2) 10 of Linux Servers-
3) Firewalls- Palo Alto-2, Stonesoft-2
4) Web Security- Bluecoat
5) WAF-Citrix
6) Brocade Switches
7) Routers
8) Load Balancer- F5
9) MS Exchange
Waiting for your reply.
Regards,
Mir

0 Karma

skoelpin
SplunkTrust
SplunkTrust

Welcome to Spunk!

It looks like you have servers in different network tiers which will all generate machine data. You will also need to decide if you want a standalone system or distributed system (This all depends on how many users are searching concurrently and how much data your indexing per day). Assuming your using a standalone system with the basic components you provided, you will need to get a beefy server with atleast 32-64GB of RAM and a good CPU, more cores the better as each real time search will use 1 core.

After setting up your standalone indexer, you will need to then install forwarders on your remote servers and point them at your indexer. You can also send data over the wire which will be good for the WAF, routers, LB's and firewalls.

So step one is for you to obtain a *nix based server with enough beef to run your indexer on. Once obtained said server, you need to install Splunk, configure firewall rules so data can send via 9997/514 to the indexer, create your indexes, then install the forwarders on your remote machines, then configure tcp/udp traffic to go to your indexer. Once this is complete, data will start flowing into your indexer in real time and Splunk will come alive!!

This will get you started on step 1
http://docs.splunk.com/Documentation/Splunk/6.5.1/Installation/Whatsinthismanual

0 Karma
Get Updates on the Splunk Community!

The OpenTelemetry Certified Associate (OTCA) Exam

What’s this OTCA exam? The Linux Foundation offers the OpenTelemetry Certified Associate (OTCA) credential to ...

From Manual to Agentic: Level Up Your SOC at Cisco Live

Welcome to the Era of the Agentic SOC   Are you tired of being a manual alert responder? The security ...

Splunk Classroom Chronicles: Training Tales and Testimonials (Episode 4)

Welcome back to Splunk Classroom Chronicles, our ongoing series where we shine a light on what really happens ...