One of the goals I have set myself is becoming core user certified for splunk. I’ve already begun taking the classes, but I found them a bit lacking and I’m someone who learns best by doing so I decided to install a Ubuntu VM and get Splunk up and running on it. It was simpler than I thought. Here is how I did it.
data:image/s3,"s3://crabby-images/12278/12278e67aefba9a848d50e07acfa161ee193e576" alt="Downloading Splunk"
I followed this great youtube video that is only 5 minutes long! I know! Insane. It really is not that difficult. The image above shows the download.
data:image/s3,"s3://crabby-images/cdb4b/cdb4b3af4718bb69311c111ac7621eab2a337429" alt="Successful Installation"
You set up the username and password for Splunk during the installation that happens in terminal.
data:image/s3,"s3://crabby-images/8a8db/8a8dbe90cd7484325a80f448592110eccf98552c" alt="Installing Data"
In order to actually do anything with Splunk you need data to query. So I followed these instructions on splunks site.
They were okay but I ran into an issue where the upload kept timing out, so I found this troubleshooting guide also on their support site. How to resolve error “Upload failed with ERROR : Read Timeout for the log file” when uploading a generated alert log to Splunk?
These instructions worked like a charm!
data:image/s3,"s3://crabby-images/7b9aa/7b9aa0d1e7280948c88bb08237ef3363d27208ff" alt="Querying Splunk"
And lastly, I was able to query Splunk successfully. Now, I can go back through the training on Splunk’s site and do the examples at the same time as the online instructors. I’m very happy this was easier than I thought.