1) Navigate to the /opt directory (the default for most Splunk installs… don’t ask me why) 2) Grab Splunk from the offical repositories with the wget command 3) Unpack the downloaded .tgz file using tar 4) Run the script to install/start Splunk
Here is the link for 4.2.2
Accept the E.U.L.A. and your install is complete. The pretty web UI is now waiting for you at http://your.server.ip.address:8000 Simple, no?
UPGRADING SPLUNK Stop the old version, download the new version and extract it in the same folder. Start Splunk back up and it will recognize the upgrade.
CONFIGURING SPLUNK This step will vary, depending on your needs. I still recommend a few settings for everyone:
Listen for logs on port 514: Most devices and many apps (including syslog) use port 514 for sending log info. You’ll want Splunk to be listening. navigate to your Splunk web UI (http://your.server.ip.address:8000) click “Admin” click “Data Inputs” click “Network Ports” “New Input” button. choose “UDP” and the port number will automagically change to 514. click the “Submit” button to save the configuration change
Start upon bootup: Pretty self-explanatory. When the machine boots up, so does Splunk.
SEND MAC/LINUX LOGS TO SPLUNK:
This is a two step process where you add your Slunk server to the list of known hosts on the client machine and then tell the syslog process to forward logs to Splunk.
Add the following line to /etc/hosts (NOTE: Use tabs, spaces won’t work.)
Where splunkserver is the name of your Splunk server. Now, add the following lines to /etc/syslog.conf:
@splunkseverWhere *.info is the level of detail you desire to be sent.
SEND WINDOWS LOGS TO SPLUNK
Download and Install Snare here: http://www.intersectalliance.com/dow…-MultiArch.exe
Open the Snare interface to configure its log management: Click on “Network Configuration” Set the “Destination Snare Server Address” to Splunk’s IP Change “Destination Port” to 514 Click the checkbox to “Enable SYSLOG header” Select your desired “Syslog Priority” level from the drop down menu. Click the “Change Configuration” button
You might need to add an exception for Snare in the Windows Firewall. (tested in XP) Navigate to the Windows Firwall settings (Start > Control Panel > Windows Firewall) Click on the Exceptions Tab Click the “Add Program” button Browse to C:\Program Files\Snare\SnareCore (or wherever you installed Snare)