Hi @jeffery_steiner
Here are a few steps you could follow:
1.) Install Splunk.
On the download page, you'll see there is an option for linux, and in the top right, a link to use wget to download the tar.gz file. You can script the installation if you want. Once you've installed Splunk, you'll have access to the web interface (by default on port 8000) .
2.) Get the data into Splunk
You could log the data to files, then monitor and index those using Splunk. You could also send the information over TCP/UDP/HTTP, install a forwarder to forward the data, or utilize the scripted input or modular inputs to get the data. Basically the data has to be in Splunk one way or another, and how exactly you do that is up to you. Which approach you take will likely be dependent on how much data you have, how fast its being created, and the process that is generating the data. Thankfully, we have lots of documentation on the various ways you can get data in. Here is a good starting point, the Getting Data In manual. You can set all this up on the CLI if you don't want to use the web interface to add inputs.
3.) Write the searches
It sounds you are interested in a few different things, e.g. historical averages, deviations from the norm, etc. You'll need to write a number of searches using Splunk's Processing Language (SPL). Once you have the queries written, you can quickly save those as reports and turn those into dashboard panels and schedule them to run on regular intervals. If you haven't written any searches with SPL before, the Search Manual has a lot of good information. I doubt that you'll be doing this part on CLI, but, hypothetically, you could, although you wouldn't get any of our awesome visualizations 😞
If this is all a bit much, I'd suggest taking some training from Splunk Education - Instructors (including myself) cover this content in the Using Splunk, Searching and Reporting, and Administration classes. Best of luck !
... View more