Splunk Enterprise Security

How to install the Splunk App for Enterprise Security on Linux with indexer clustering?

brent_weaver
Builder

Hello!

I am about to embark on an install of the Splunk App for Enterprise Security on a set of shiny new CentOS Linux servers. Here is the config:

4 Clustered Indexer Servers
2 Search Heads
1 Deployment server with License manager running on it

Some of my questions are as follows:

  1. I have chosen to use xfs as the filesystem for indexes. I will be striping the lv across 16 LUN's, which cluster size should I use for optimal perf? Is xfs the correct fs for this in the first place? Should I break out the hot and cold areas into multiple mount points? I expext about 5k iops per sec on each disk.

  2. Given that this env has clustered indexers, what considerations should I make?

  3. I understand that ES relies heavily on sourcetype, what are the implications in ES if I create my own sourcetypes?

ANY advice to spare me future pain is more than welcome. Thanks!

0 Karma

miront
Explorer

Just follow best practices with the common information model and reference the dashboard requirement matrix and you will be in good shape.

http://docs.splunk.com/Documentation/CIM/4.2.0/User/Overview
http://docs.splunk.com/Documentation/ES/3.3.0/Install/Dashboards

0 Karma

tskinnerivsec
Contributor

ES relies a lot more on tags then it does sourcetypes. If you are creating your own sourcetypes, take a look through the common information model documentation and the ES dashboard matrix. You'll need your custom sourcetypes to map into the datamodels that ship with ES and have the proper field extractions. If you can map your data to sourcetypes from the technology add-ons that ship with ES, you will save yourself a ton of work. By the way, an entire book could be written on this set of questions.

Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...