Getting Data In

How to implement Splunk on Linux Platform?

fazilhussain
Explorer

Hello. Friends am new to Splunk. I have Basic knowledge on Windows Platform and learning day by day.
Need Help for Implementation on Linux Platform.
Below are the Servers listed for implementation with Splunk.
I request you to please help me on the step how i can start Configuration with the listed Servers with Splunk, this implementation is on Linux Centos Platform. Please provide me some guidance on the Linux Platform

Device Details (Please specify quantities specifically):-
1) 10 of Windows Servers-
2) 10 of Linux Servers-
3) Firewalls- Palo Alto-2, Stonesoft-2
4) Web Security- Bluecoat
5) WAF-Citrix
6) Brocade Switches
7) Routers
8) Load Balancer- F5
9) MS Exchange
Waiting for your reply.
Regards,
Mir

0 Karma

skoelpin
SplunkTrust
SplunkTrust

Welcome to Spunk!

It looks like you have servers in different network tiers which will all generate machine data. You will also need to decide if you want a standalone system or distributed system (This all depends on how many users are searching concurrently and how much data your indexing per day). Assuming your using a standalone system with the basic components you provided, you will need to get a beefy server with atleast 32-64GB of RAM and a good CPU, more cores the better as each real time search will use 1 core.

After setting up your standalone indexer, you will need to then install forwarders on your remote servers and point them at your indexer. You can also send data over the wire which will be good for the WAF, routers, LB's and firewalls.

So step one is for you to obtain a *nix based server with enough beef to run your indexer on. Once obtained said server, you need to install Splunk, configure firewall rules so data can send via 9997/514 to the indexer, create your indexes, then install the forwarders on your remote machines, then configure tcp/udp traffic to go to your indexer. Once this is complete, data will start flowing into your indexer in real time and Splunk will come alive!!

This will get you started on step 1
http://docs.splunk.com/Documentation/Splunk/6.5.1/Installation/Whatsinthismanual

0 Karma
Get Updates on the Splunk Community!

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...

Updated Team Landing Page in Splunk Observability

We’re making some changes to the team landing page in Splunk Observability, based on your feedback. The ...