Security

how do i monitor my own system ?

rcon313
Explorer

So I am very new to Splunk and I have just started using it. What I want to do is be able to view my own laptops operating system file logs and performance data. What I have been doing is logging onto my splunk and then selecting the "add data" button. From there I select the "monitor" button. For example I have chosen to monitor  my local events log but for some reason when I try to search anything I get nothing so something is wrong and I dont know what.

 

Please help

0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @rcon313,

there are two videos that describe how to ingest Windows logs.

Anyway, I usually don't start from Add Data, but from Data Inputs, I Use Add-Data when I want to upload logs from a text or csv file.

So if you want to take the logs from the machine where Splunk is installed, you have to see in the menu choice [Settings -- Data Inputs] and choose the logs you want:

  • Local Eventlog Collection for Wineventlogs,
  • Files & Directories to read logs e.g. from IIS,
  • Local Performance Monitor to take the performance counters
  • and so on.

Please, let me know if my answer solved your need, in this case, please accept it for the other people of Community, otherwise, tell me how can I help you.

Ciao and happy splunking.

Giuseppe

P.S.: Karma Points are appreciated 😉

 

View solution in original post

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @rcon313,

probably you need to have a training before to start to work on Splunk.

You could follow the Splunk Fundamentals I course (https://www.splunk.com/en_us/training/free-courses/splunk-fundamentals-1.html) that's a free course and the Search Tutorial (https://docs.splunk.com/Documentation/Splunk/8.1.0/SearchTutorial/WelcometotheSearchTutorial) that help you to understand how Splunk searches work.

About the ingestion of windows logs, there's an interesting video in the download page of splunk that could help you to understand how Splunk ingests local logs.

Then these other videos on YouTube:

https://www.youtube.com/watch?v=3GKhCZfQqDM 

https://www.youtube.com/watch?v=1AyJaKxks-I

https://www.youtube.com/watch?v=rT-O80XfWuY

https://www.youtube.com/watch?v=sLMIEjgD6UY

maybe someone is late but this part is almost the same.

Ciao.

Giuseppe

0 Karma

rcon313
Explorer

Hi Gcusello,

I finished the fundamentals part 1 course yesterday. It was a good course but it only really covered how to upload data into splunk. Maybe its a wee bit different for when you monitor your own system. I will have a look at the videos you sent me as well. 

Thank you very much 

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @rcon313,

there are two videos that describe how to ingest Windows logs.

Anyway, I usually don't start from Add Data, but from Data Inputs, I Use Add-Data when I want to upload logs from a text or csv file.

So if you want to take the logs from the machine where Splunk is installed, you have to see in the menu choice [Settings -- Data Inputs] and choose the logs you want:

  • Local Eventlog Collection for Wineventlogs,
  • Files & Directories to read logs e.g. from IIS,
  • Local Performance Monitor to take the performance counters
  • and so on.

Please, let me know if my answer solved your need, in this case, please accept it for the other people of Community, otherwise, tell me how can I help you.

Ciao and happy splunking.

Giuseppe

P.S.: Karma Points are appreciated 😉

 

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Take Action Automatically on Splunk Alerts with Red Hat Ansible Automation Platform

 Are you ready to revolutionize your IT operations? As digital transformation accelerates, the demand for ...

Calling All Security Pros: Ready to Race Through Boston?

Hey Splunkers, .conf25 is heading to Boston and we’re kicking things off with something bold, competitive, and ...

Beyond Detection: How Splunk and Cisco Integrated Security Platforms Transform ...

Financial services organizations face an impossible equation: maintain 99.9% uptime for mission-critical ...