Splunk is a SIEM (Security Information and Event Management) solution that collects logs from various sources (server, network devices, applications, etc.), stores (indexes) the collected logs, and provides search, research, analysis and correlation on the stored logs. With its simple logic, Splunk works with the forwarder, indexer and master structure. Splunk can be used for free up to a certain 500 MB value.
How to Download Splunk?
We will perform these installation processes in Ubuntu. Sign up and log in to the Splunk site.
data:image/s3,"s3://crabby-images/1b48e/1b48e687fc325e357798a2e6022d3efd6573f3c1" alt="Splunk site"
Then, the packages according to the operating systems are seen as follows. You can choose the one that suits you. Since we will install on Ubuntu, we download the package with the .deb extension from the Linux tab.
data:image/s3,"s3://crabby-images/5fc9b/5fc9bee187581262085a1aa86f8c0e167c81d5cd" alt="Download Splunk Enterprise"
We mark the “Save File” tab and click the “OK” button to save.
data:image/s3,"s3://crabby-images/993d0/993d079d37042b36e05763e6fe1b87772be6a2fd" alt="Save File"
How to Install Splunk?
We will perform these installation processes in Ubuntu. After the download is finished, we install it with the following command.
sudo dkpg -i splunk-8.2.2.1-ae6821b7c64b-linux-2.6-amd64.deb
data:image/s3,"s3://crabby-images/75cd0/75cd072226c263c2d853e3055cf1b15d73d2b909" alt="dkpg -i splunk.dep"
We start the command “/opt/splunk/bin/splunk enable boot-start”. Some questions such as the usage agreement are asked on the screen. We pass the keyboard by pressing the Tab key or the enter key a few times.
sudo /opt/splunk/bin/splunk enable boot-start
data:image/s3,"s3://crabby-images/f381d/f381d0104985912c7f2c6842ab1c38bbc30d6f8c" alt="splunk enable boot-start"
When WebGUI asks for a username and password, we complete the installation quickly by entering this information.
data:image/s3,"s3://crabby-images/7a1c2/7a1c2ee6a34c3b9dc03ea75263131006a163a7f6" alt="WebGUI asks for a username and password"
We start the Splunk service with the following command.
sudo systemctl start splunk
data:image/s3,"s3://crabby-images/8c949/8c949d6342b63aaff8f15485810ea92c4762b979" alt="systemctl start splunk"
The installation ends here. We access the Splunk interface by pasting the address below into our browser. Enter the username and password we created.
http://server ip address:8000
data:image/s3,"s3://crabby-images/db1f8/db1f89c99e345e1829f40d1bee0ac30c8adb85b8" alt="Splunk interface"
On the incoming screen, “Got it!” we click the button.
data:image/s3,"s3://crabby-images/6605c/6605cd3191fd124e544ee346d1cc44b334730af5" alt="Splunk Software"
As you can see, the Splunk page is in front of us.
data:image/s3,"s3://crabby-images/834b0/834b0975116e5a0a26d181f2a07d5804c1fcfcb7" alt="Splunk page"