Search This Blog

Tuesday, March 12, 2024

01_PS_Splunk 9_Installation and Configuration

 Table of Contents

1 Course Overview 1

1.1 Course Overview 1

2 What Is Splunk? 1

2.1 Overview 1

2.2 What Is Machine Data? 3

2.3 Past, Present, and Future of Splunk 5

2.4 Splunk Architecture and Licenses 6

2.5 Splunk Documentation and Community Tour 7

2.6 Summary 8

3 Installing Splunk Enterprise 8

3.1 Overview 8

3.2 Building Splunk Environments 9

3.3 Setting Up Splunk 9

3.4 Demo: Installing in Windows Environment 10

3.5 Demo: Installing in Linux Environment 10

3.6 Splunk in the Cloud 12

3.7 Demo: Splunk Cloud Options 13

3.8 Summary 14

4 Navigating and Configuring the Splunk Enterprise 15

4.1 Overview 15

4.2 Getting Data into Splunk 15

4.3 Demo: Getting Data into Splunk – web log file 15

4.4 Navigating Splunk Search 16

4.4.1 How to Search in Splunk 16

4.4.2 Basic Splunk Search 17

4.5 Demo: Adding More Data into Splunk 17

4.6 Demo: Installing Splunk Apps 17

4.7 Splunk Roles in Search 18

4.8 Demo: Splunk User Roles 18

4.9 Summary 21

5 Wrapping up Splunk Enterprise Installation and Configuration 21

5.1 Splunk Learning Path 21


  1. Course Overview

    1. Course Overview

  • Splunk for Analysing and Processing data and Data Anaytics

  • Different Roles

  • Different Environemnt – Linux, Mac, Windows


  1. What Is Splunk?

    1. Overview

A close up of a logo

Description automatically generated

A screenshot of a phone

Description automatically generated


What is Machine Data?

A white background with black text

Description automatically generated

  1. What Is Machine Data?

A close up of a text

Description automatically generated

IIS Log, Windows Event Log

https://www.idc.com/

A screenshot of a computer

Description automatically generated


A blue and red robot

Description automatically generated with medium confidence



  1. Past, Present, and Future of Splunk

A close-up of a white background

Description automatically generated

A computer and cloud icons

Description automatically generated


Splunkbase

A group of words on a white background

Description automatically generated

  1. Splunk Architecture and Licenses

  • 3 Architectural Building Blocks

    • Index  (3 types of indexes) 

    • Search Head 

    • Forwarder

A screenshot of a white background

Description automatically generated



  1. Splunk Documentation and Community Tour

WWW.SPLUNK.COM / sigin in Resources >  Platform > Splunk Enterprises – we can choose the Product / Version to get the appropriate help

  1. Summary

A white background with black text

Description automatically generated

  1. Installing Splunk Enterprise

    1. Overview

A white background with black text

Description automatically generated


  1. Building Splunk Environments

A close-up of a white background

Description automatically generated

  1. Setting Up Splunk

  • Get Free Licensing 

    • Register 

    • Request

    • Download

    • Cloud Trial

  • Search Heaed > Indexes > Environments 

  • A computer icons with different colors

Description automatically generated with medium confidence

  • In this course all going into one location (Indexer / Search Head / Forwarder)

  • Data ingest Limitations based on the licenses – for free 500 MB / day

  • Ports

    • 8000 default to login with Username and password http://localhost:8000/

    • 8090 – Management Port


  1. Demo: Installing in Windows Environment

  • Login Splunk  - go to Dashboard -  Free trials and downloads – documentation link available to check prerequisites – Download and install

  1. Demo: Installing in Linux Environment

  • Login to Dashboard – Free Trials and Downloads – Choose Splunk Enterprise – Choose Linux – Check System Requirements in documentation Link -  Choose .rpm  - Download Now – Click Download via Command Line (wget)

  • A orange and white background with white text

Description automatically generated

  • A screenshot of a computer

Description automatically generated

  • Copy the content – Login to Linux Server – 

    • Sudo yum install wget --- check we can use wget

    • Sestatus  --- check linux status

    • A computer screen with white text

Description automatically generated

    • Enforcing to Permissive – 

    • Sudo setenforce 0

    • A computer screen shot of a computer program

Description automatically generated 

    • Paste the wget code – it will download the splunk

A computer screen shot of a blue screen

Description automatically generated

  • If not loading check the firewall

  1. Splunk in the Cloud

A cartoon of a person with headphones and money

Description automatically generated



A white background with black text

Description automatically generated

A white background with black text

Description automatically generated

  1. Demo: Splunk Cloud Options

  • No need to download 

  • Login to Dashboard – Free Trials and Downloads –  Choose Splunk Cloud – directly goest to our URL – takes 10 minutes to configure and set up – this is valid only 15 days

  • If we are AWS customer, we can login EC2 Dashboard – AMI Catelog search splunk – we can get splunk enterprise – download and install

A screenshot of a computer

Description automatically generated


  1. Summary

A white background with black text

Description automatically generated

  1. Navigating and Configuring the Splunk Enterprise

    1. Overview

A white background with black text

Description automatically generated

  1. Getting Data into Splunk

A black text on a white background

Description automatically generated

  1. Demo: Getting Data into Splunk – web log file

A screenshot of a computer

Description automatically generated


  1. Navigating Splunk Search 

    1. How to Search in Splunk

  • Basic Search

  • SPL – Splunk Processing Language

  • Splunkbase

  • APIs

  1. Basic Splunk Search

A close-up of a white background

Description automatically generated


A screenshot of a phone

Description automatically generated



  1. Demo: Adding More Data into Splunk

  • Add Data – Monitoring – Local Event Logs - Select all fiedls 

  1. Demo: Installing Splunk Apps

  • Splunkbase – search  Dell PowerScale App for Splunk

  • OR In splunk Dashboard – Find more Apps link – this will connect splunkbase with all api or applications – we can install by using splunk account



  1. Splunk Roles in Search

A close up of a text

Description automatically generated

A screenshot of a search engine

Description automatically generated



  1. Demo: Splunk User Roles

  • Settings – USERS AND AUTHENTICATIONS – Roles

A screenshot of a computer

Description automatically generated

A screenshot of a computer

Description automatically generated


  1. Summary

A screenshot of a computer

Description automatically generated

  1. Wrapping up Splunk Enterprise Installation and Configuration

    1. Splunk Learning Path


No comments:

Post a Comment