25th May 2022

What is Splunk? How to Install Splunk?

Splunk is a SIEM (Security Information and Event Management) solution that collects logs from various sources (server, network devices, applications, etc.), stores (indexes) the collected logs, and provides search, research, analysis and correlation on the stored logs. With its simple logic, Splunk works with the forwarderindexer and master structure. Splunk can be used for free up to a certain 500 MB value.

How to Download Splunk?

We will perform these installation processes in Ubuntu. Sign up and log in to the Splunk site.

Splunk site
Splunk site

 

Then, the packages according to the operating systems are seen as follows. You can choose the one that suits you. Since we will install on Ubuntu, we download the package with the .deb extension from the Linux tab.

Download Splunk Enterprise
Download Splunk Enterprise

 

We mark the “Save File” tab and click the “OK” button to save.

Save File
Save File

 

How to Install Splunk?

We will perform these installation processes in Ubuntu. After the download is finished, we install it with the following command.

dkpg -i splunk.dep
dkpg -i splunk.dep

 

We start the command “/opt/splunk/bin/splunk enable boot-start”. Some questions such as the usage agreement are asked on the screen. We pass the keyboard by pressing the Tab key or the enter key a few times.

splunk enable boot-start
splunk enable boot-start

 

When WebGUI asks for a username and password, we complete the installation quickly by entering this information.

WebGUI asks for a username and password
WebGUI asks for a username and password

 

We start the Splunk service with the following command.

LEARN MORE  Data Recovery with PhotoRec for Linux in Forensic Examinations

systemctl start splunk
systemctl start splunk

 

The installation ends here. We access the Splunk interface by pasting the address below into our browser. Enter the username and password we created.

Splunk interface
Splunk interface

 

On the incoming screen, “Got it!” we click the button.

Splunk Software
Splunk Software

 

As you can see, the Splunk page is in front of us.

Splunk page
Splunk page

 

Leave a Reply

Your email address will not be published. Required fields are marked *