Getting Data In

How to implement Splunk on Linux Platform?

fazilhussain
Explorer

Hello. Friends am new to Splunk. I have Basic knowledge on Windows Platform and learning day by day.
Need Help for Implementation on Linux Platform.
Below are the Servers listed for implementation with Splunk.
I request you to please help me on the step how i can start Configuration with the listed Servers with Splunk, this implementation is on Linux Centos Platform. Please provide me some guidance on the Linux Platform

Device Details (Please specify quantities specifically):-
1) 10 of Windows Servers-
2) 10 of Linux Servers-
3) Firewalls- Palo Alto-2, Stonesoft-2
4) Web Security- Bluecoat
5) WAF-Citrix
6) Brocade Switches
7) Routers
8) Load Balancer- F5
9) MS Exchange
Waiting for your reply.
Regards,
Mir

0 Karma

skoelpin
SplunkTrust
SplunkTrust

Welcome to Spunk!

It looks like you have servers in different network tiers which will all generate machine data. You will also need to decide if you want a standalone system or distributed system (This all depends on how many users are searching concurrently and how much data your indexing per day). Assuming your using a standalone system with the basic components you provided, you will need to get a beefy server with atleast 32-64GB of RAM and a good CPU, more cores the better as each real time search will use 1 core.

After setting up your standalone indexer, you will need to then install forwarders on your remote servers and point them at your indexer. You can also send data over the wire which will be good for the WAF, routers, LB's and firewalls.

So step one is for you to obtain a *nix based server with enough beef to run your indexer on. Once obtained said server, you need to install Splunk, configure firewall rules so data can send via 9997/514 to the indexer, create your indexes, then install the forwarders on your remote machines, then configure tcp/udp traffic to go to your indexer. Once this is complete, data will start flowing into your indexer in real time and Splunk will come alive!!

This will get you started on step 1
http://docs.splunk.com/Documentation/Splunk/6.5.1/Installation/Whatsinthismanual

0 Karma
Get Updates on the Splunk Community!

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...