Configuration

Configuring Splunk

  1. Click here to go to Splunk.
  2. Click the User icon and select Sign Up.
  3. Complete the Create Your Splunk Account page.
  4. Click Create Your Account.
  5. Download the Splunk Enterprise setup.
  6. Install Splunk Enterprise.
  7. Click here to log into your Splunk Enterprise.

    The first time you log in, use the default username admin and the password you set during installation. You can then change the password and log in again with your new password.

Configuring Secret Server Settings

To configure Secret Server settings:

  1. Sign into Secret Server.

    alt

  2. The Home page displays.

    alt

  3. Click Administration > Actions > Configuration and the Configuration page displays.

    alt

  4. At the bottom of the page, click Edit

    alt

  5. The Application Setting page displays.

    alt

  6. Select Enable Webservices check box.

  7. Under the Syslog/CEF Logging Advanced Settings Information area, select Enable Syslog/CEF Logging check box and enter the syslog server.

    This should be the IP of the machine/server where Splunk Enterprise is configured.

    alt

  8. Click Save.

Configure Splunk Enterprise

  1. Go to Splunk enterprise > Settings > Add Data > click on Monitor.

  2. The Select Source page displays, click TCP/UDP.

  3. Select UDP and enter the port configured in Secret Server (for example TCP 6514).

    alt

  4. Click Next on Input Settings page and select the source type as syslog.

    alt

  5. In the Index list, select Default.

  6. Click Review and the Review page displays.

  7. Review the information and click Submit.

  8. The message, “,” displays.

    alt

  9. Click Start Searching and the New Search page displays.

  10. In the New Search field, enter the query and click the Search icon.

    alt