Splunk

From CSLLabWiki
Jump to navigation Jump to search

What is Splunk?

"Splunk is a search engine for IT data. It's software that lets you search and analyze all the data your IT infrastructure generates from a single location in real time. We call this IT Search. No need for databases, connectors, custom parsers or proprietary consoles. Just your imagination and a web browser! Now you can troubleshoot IT problems and investigate security incidents in minutes, not hours or days. Monitor all your applications, servers and network devices from one place. Report on all your compliance controls in a fraction of the time." --Splunk.com

Installation

  • Download the appropriate installation file from Splunk's website
    • Login as: transycs
  • rpm -ivh ./splunk-4.0.3-65638-linux-2.6-x86_64.rpm