Installation

Bare Bones Splunk

_JP
Contributor

This isn't a question, rather just a place to drop a PDF I put together that I titled "Bare Bones Splunk"

 

I've seen a lot of people try and get started with Splunk, but then get stuck right after getting Splunk Enterprise installed on their local machine. It can be daunting to log into Splunk for the first time and know what the heck you should do.  A person can get through the install to the What Happens Next page, and be pretty overwhelmed with what to do next:

  • Learn SPL and search? 
  • What should they search? 
  • How should they start getting their data in? 
  • What sort of data should I start getting in? 
  • What dashboard should I build?


They've started...but need that ah-ha example to see how this tool will fit into their existing environment and workflow.

The attached Bare_Bones_Splunk.pdf file guides the reader from the point of install to using the data already being indexed in index=_internal to replicate a few common use cases of Splunk:

  • Monitor a web server
  • Monitor an application server
  • Monitor security incidents

The examples are really simple, and the resulting dashboard created in the tutorial is a poor example of something your boss might want (or not...how observant is your boss - do they just want a few graphs with nice colors?).  But, this will give someone a really quick intro to Splunk without having to do anything other than install (and then maybe they will be ready to tackle a broader introduction, like the Search Tutorial)

Labels (1)

inventsekar
SplunkTrust
SplunkTrust

Nice document @_JP ... thanks for sharing. 

 

the trouble with newbies is that, they want one person to hold their hands and walk with them together.(literally). 

If we say "I can only show you the door, you only should decide and walk thru it(the great Morpheus)", still they want us to walk with them (holding their hands). !!!

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !
Get Updates on the Splunk Community!

Take Your Breath Away with Splunk Risk-Based Alerting (RBA)

WATCH NOW!The Splunk Guide to Risk-Based Alerting is here to empower your SOC like never before. Join Haylee ...

SignalFlow: What? Why? How?

What is SignalFlow? Splunk Observability Cloud’s analytics engine, SignalFlow, opens up a world of in-depth ...

Federated Search for Amazon S3 | Key Use Cases to Streamline Compliance Workflows

Modern business operations are supported by data compliance. As regulations evolve, organizations must ...