Hi All,
I don't have many resource to build an ideal network environment to forward logs to Splunk. So, I'm seeking a way to simulating or source to obtain many commonly data sources into Splunk (Like some SIEM solutions have scripts to forward syslog through port 514). Any answer will be highly appreciated.
Regard.
Hi @thanh_on,
have you access to Splunk Show (https://show.splunk.com/login/?redirect=/)?
here you can find a complete environment to test Enterprise Security with a relevant set of data.
Ciao.
Giuseppe
Hi @thanh_on,
have you access to Splunk Show (https://show.splunk.com/login/?redirect=/)?
here you can find a complete environment to test Enterprise Security with a relevant set of data.
Ciao.
Giuseppe
Thank you for your information. Actually, my company is an Splunk Partner so I can login to demo sites. Moreover, I'm still seeking for a RAW commonly data source for customize and fully control to my own Splunk.
Regard.
Thank you Giuseppe, I have found static Splunk enterprise security demo site. I appreciate your help.