Перейти к содержимому

Splunk _project_10

Bon_ Voyage

0:00 / 0:00

Splunk _project_10

6 просмотров · 4 дня назад
Bon_ Voyage
1 подписчик
6 просмотров · 4 дня назад
The client wants to onboard Linux operating system and security logs into Splunk for centralized monitoring and future security use cases. The implementation must use the Splunk Add-on for Unix and Linux for collecting and interpreting the Linux data. The environment will consist of one Splunk All-in-One instance, one Intermediate Heavy Forwarder (IHF), and one Linux Server. The expected architecture and implementation requirements are: Infrastructure: 1 Splunk AIO, 1 Intermediate Heavy Forwarder (IHF), and 1 Linux Server. Install and configure the Splunk Universal Forwarder on the Linux Server. Deploy the Splunk Add-on for Unix and Linux on the appropriate Splunk components. Configure the Add-on to collect relevant system, authentication, security, performance, process, and network-related data from the Linux Server. Configure the data flow as Linux Server → IHF → Splunk AIO, ensuring the Linux Server does not directly forward data to the AIO. Create a dedicated index for the Linux data and ensure the correct host, source, sourcetype, and index values are assigned. Validate that the required fields and knowledge objects are correctly extracted from the onboarded Linux events. Identify the applicable Splunk CIM Data Models for the collected security events and map the required fields to achieve CIM compliance. Validate the CIM mapping using appropriate SPL searches and Data Model searches. Perform end-to-end validation and troubleshooting to confirm that the data is successfully collected, forwarded, indexed, searchable, and CIM compliant.