Installation

Starting from scratch of installing and uploading of data

crispbacon
Loves-to-Learn

Hi everyone, i am a new user, i am trying to install splunk and upload data into it, i am using my company's linux system, so it cannot access splunk site and download from it, any ideas what i need to do ?

Labels (1)
0 Karma

splunk219783
Path Finder

If you're able to access the Linux box it sounds like you have ssh access from your Windows box.  You should be able to download the Splunk RHEL rpm from the splunk download site.  Then PSCP, SCP, or WINSCP it over to the linux box.  You can then yum localinstall like you would any other package.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @crispbacon,

if you haven't any information about installation and data loading I hint to find some documentation and video to help you:

https://docs.splunk.com/Documentation/Splunk/8.2.0/Installation/Beforeyouinstall

https://docs.splunk.com/Documentation/Splunk/8.2.0/Installation/InstallonLinux

https://www.youtube.com/watch?v=kqzvjjz9Wws

About data loading you should see at:

https://docs.splunk.com/Documentation/Splunk/8.2.0/Data/WhatSplunkcanmonitor

https://www.splunk.com/en_us/training/videos/getting-data-in-with-forwarders.html

https://www.youtube.com/watch?v=1AyJaKxks-I

etc...

In addition I hint to see the Splunk Search Tutorial https://docs.splunk.com/Documentation/SplunkCloud/latest/SearchTutorial that gives you also sample data to start.

and the Splunk Fundamentals I training https://www.splunk.com/en_us/training/free-courses/splunk-fundamentals-1.html that gives you a starting view about Splunk.

Anyway installation is very easy, you have to:

Ciao.

Giuseppe

0 Karma

crispbacon
Loves-to-Learn

Hi thanks for the help, i've read through alot times, none of them work. i am also not sure whats going, there are too many things to do but none is working. i cant just download the file on my windows and drag and drop into my linux machine

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @crispbacon,

at first check if you downloaded the correct version (Linux 64 bit?).

Then follow instructions.

Which user are you using, root?

which Linux are you using?

Ciao.

Giuseppe

0 Karma

crispbacon
Loves-to-Learn

i am using linux redhat? , i am definetly not root

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @crispbacon,

could you use "su" or "sudo"?

Once installed, you can configure Splunk to run as not root user, but to install you need grants.

Then, which errors or messages yu have during installation? can you descrive installation steps you followed?

Ciao.

Giuseppe

 

0 Karma

crispbacon
Loves-to-Learn

could we do private message? will it be easier? 

i can SU but i am not root so i cant use SUDO. 

how do i download into linux? i tried your link but after i download i cannot bring the file from windows to into linux

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @crispbacon,

which scp tool are you using? winscp or mobaxterm?

the steps are:

  • download the installation file from the above site to you pc;
  • upload the installation file in Unix using winspc;
  • run rpf -i splunk ...rpf
  • run /opt/splunk/bin/splunk start --accept-license

If you have problems to upload the file I cannot help you.

Otherwise, if your linux server can access Internet, you could try the wget command

wget -O splunk-8.2.0-e053ef3c985f-linux-2.6-x86_64.rpm 'https://www.splunk.com/bin/splunk/DownloadActivityServlet?architecture=x86_64&platform=linux&version=8.2.0&product=splunk&filename=splunk-8.2.0-e053ef3c985f-linux-2.6-x86_64.rpm&wget=true'

If you like, you can write to me as private message, but I don't think that it could be better (except if you're italian!), anyway I'd prefer Community because some other people can help you and your experience can rich the others.

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...