All Apps and Add-ons

Splunk setup with light forwarders and *nix App

bmorgenthaler
Path Finder

So I'm new to Splunk but loving it so far. My question is on system design/layout. I have the following systems:

FSM: Splunk Host (linux)
Mother: DNS/DHCP (linux)
Bastion: ssh/stunnel (linux)

Currently I have setup splunk listeners on 514 udp/tcp and have the syslogs of Mother & Bastion forwarding to it.

I'm interested in the light forwarders and the *nix App, from what I'm reading what would I install the light forwarders on Mother & Bastion along with *nix App to index /etc, /var/log, etc. and then have it all sent to FSM where I also would install the *nix App?

The same question goes for the Linux DNS and DHCP Apps, those would need to go on the server itself and not the Splunk system correct?

Side Question: Anyone have experience getting Sonicwalls to play nice with Splunk?

Thanks.

1 Solution

araitz
Splunk Employee
Splunk Employee

I would recommend that you install the Splunk for Unix and Linux technology add-on on Mother and Bastion, enable the inputs you want to gather, then set both hosts to forward their data to FSM. On FSM, you can install the Splunk for Unix and Linux app and configure Splunk to receive data from Mother and Bastion.

See this page in our docs for forwarding and receiving:

http://docs.splunk.com/Documentation/Splunk/latest/Deploy/Setupforwardingandreceiving

Regarding Sonicwall, I wrote some field extractions a long time ago, they might be adaptable to 4.x but it has been a while so not sure:

http://splunkbase.splunk.com/apps/Fields/3.x/Technologies/app:Sonicwall+Firewall

Also, see this answer from Dwaddle:

http://splunk-base.splunk.com/answers/2390/sonicwall-4060-logs

View solution in original post

0 Karma

araitz
Splunk Employee
Splunk Employee

I would recommend that you install the Splunk for Unix and Linux technology add-on on Mother and Bastion, enable the inputs you want to gather, then set both hosts to forward their data to FSM. On FSM, you can install the Splunk for Unix and Linux app and configure Splunk to receive data from Mother and Bastion.

See this page in our docs for forwarding and receiving:

http://docs.splunk.com/Documentation/Splunk/latest/Deploy/Setupforwardingandreceiving

Regarding Sonicwall, I wrote some field extractions a long time ago, they might be adaptable to 4.x but it has been a while so not sure:

http://splunkbase.splunk.com/apps/Fields/3.x/Technologies/app:Sonicwall+Firewall

Also, see this answer from Dwaddle:

http://splunk-base.splunk.com/answers/2390/sonicwall-4060-logs

0 Karma

bmorgenthaler
Path Finder

Thanks for info araitz, that is what I figured I needed to do, now to get that setup.

As for the sonicwall I have it setup and logging to splunk over syslog and I did see your post about field extractions on it for 3.x. I'll see if I can get it updated to 4.x and post back about it.

0 Karma
Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

REGISTER NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If ...

Observability | Use Synthetic Monitoring for Website Metadata Verification

If you are on Splunk Observability Cloud, you may already have Synthetic Monitoringin your observability ...

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...