Splunk Search

Best way to simulating or obtain an commonly data source into Splunk Enterprise for POCs.

thanh_on
Explorer

Hi All,

I don't have many resource to build an ideal network environment to forward logs to Splunk. So, I'm seeking a way to simulating or source to obtain many commonly data sources into Splunk (Like some SIEM solutions have scripts to forward syslog through port 514). Any answer will be highly appreciated.

Regard.

 

Labels (1)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @thanh_on,

have you access to Splunk Show (https://show.splunk.com/login/?redirect=/)?

here you can find a complete environment to test Enterprise Security with a relevant set of data.

Ciao.

Giuseppe

View solution in original post

gcusello
SplunkTrust
SplunkTrust

Hi @thanh_on,

have you access to Splunk Show (https://show.splunk.com/login/?redirect=/)?

here you can find a complete environment to test Enterprise Security with a relevant set of data.

Ciao.

Giuseppe

isoutamo
SplunkTrust
SplunkTrust
show.splunk.com is mainly targeted to Splunk partners which have fulfilled some additional requirements. It's not for customers (without help from those partners e.g. in sales case).
0 Karma

thanh_on
Explorer

Thank you for your information. Actually, my company is an Splunk Partner so I can login to demo sites. Moreover, I'm still seeking for a RAW commonly data source for customize and fully control to my own Splunk.

Regard.

0 Karma

isoutamo
SplunkTrust
SplunkTrust
0 Karma

thanh_on
Explorer

Thank you Giuseppe, I have found static Splunk enterprise security demo site. I appreciate your help. 

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...