Getting Data In

How to implement Splunk on Linux Platform?

fazilhussain
Explorer

Hello. Friends am new to Splunk. I have Basic knowledge on Windows Platform and learning day by day.
Need Help for Implementation on Linux Platform.
Below are the Servers listed for implementation with Splunk.
I request you to please help me on the step how i can start Configuration with the listed Servers with Splunk, this implementation is on Linux Centos Platform. Please provide me some guidance on the Linux Platform

Device Details (Please specify quantities specifically):-
1) 10 of Windows Servers-
2) 10 of Linux Servers-
3) Firewalls- Palo Alto-2, Stonesoft-2
4) Web Security- Bluecoat
5) WAF-Citrix
6) Brocade Switches
7) Routers
8) Load Balancer- F5
9) MS Exchange
Waiting for your reply.
Regards,
Mir

0 Karma

skoelpin
SplunkTrust
SplunkTrust

Welcome to Spunk!

It looks like you have servers in different network tiers which will all generate machine data. You will also need to decide if you want a standalone system or distributed system (This all depends on how many users are searching concurrently and how much data your indexing per day). Assuming your using a standalone system with the basic components you provided, you will need to get a beefy server with atleast 32-64GB of RAM and a good CPU, more cores the better as each real time search will use 1 core.

After setting up your standalone indexer, you will need to then install forwarders on your remote servers and point them at your indexer. You can also send data over the wire which will be good for the WAF, routers, LB's and firewalls.

So step one is for you to obtain a *nix based server with enough beef to run your indexer on. Once obtained said server, you need to install Splunk, configure firewall rules so data can send via 9997/514 to the indexer, create your indexes, then install the forwarders on your remote machines, then configure tcp/udp traffic to go to your indexer. Once this is complete, data will start flowing into your indexer in real time and Splunk will come alive!!

This will get you started on step 1
http://docs.splunk.com/Documentation/Splunk/6.5.1/Installation/Whatsinthismanual

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...