Wednesday, July 2, 2014

splunk is happiness

 let's install splunk on ubuntu 12 lts. yes?  
# wget -O splunk-6.0-182037-linux-2.6-amd64.deb ''  
# dpkg -i splunk-6.0-182037-linux-2.6-amd64.deb  
# cd /opt/splunk/bin  
# ./splunk start  
# ./splunk boot-start  
Connect to http://localhost:8000  

Create Syslog Receiver  
      Settings > Data > Data inputs  
      Under "TCP" click "Add New"  
      Splunk Data Inputs TCP Add New  
      TCP Port = 514  
      Accept Connections from all hosts? = yes  
      Set sourcetype = From List  
      Select source type from list = syslog  
      Do the same for UDP  
Voila happiness.  
