
Configure universal forwarders on Linux and Windows to monitor files under the Volokh directory, set inputs.conf and outputs.conf, and add the indexer as a search peer.
Install the universal forwarder on a Linux system, create a Splunk user, set ownership under /opt, and start it via the CLI; no UI and no data forwarding yet.
Configure the universal forwarder to monitor /var/log/secure* with inputs.conf, use host segment three, forward to the indexer on port 9997 via outputs.conf, and ensure Splunk ownership with a dedicated app.
Configure the Splunk indexer to listen on 9997, forward logs from the universal forwarder, enable the index security index, and trigger re-ingestion by clearing the fish bucket.
Deploy the universal forwarder on Windows, forward logs to the Splunk indexer over port 9997, install the Windows add-on for parsing and field extraction, and enable search head access.
Configure and deploy a Windows index on the Splunk indexer, create and enable the Windows index, and install the Windows add-on from Splunk Base to enable log collection and parsing.
Learn to configure a distributed Splunk search head by adding an indexer as a search peer, deploying via settings, and enabling quarantine for underperforming peers.
The best hands-on labs crash course for learning Splunk, the leader in real-time monitoring, log management, and SIEM (security information and event management).
For a complete Course, please check out my other full deployment Admin certification Course!!
Your instructor is Saif Al-Shoker, a former SPLUNK Architect Employee and a Splunk Certified core Consultant and Architect with over 10 years of experience in the security domain, 5 years splunking and hold two master degrees.
This fast lab course, is a sample part which focuses on system administrator and data administrator learning content.
In this micro nugget course, we will go through deploying the Universal Forwarder on a Linux and Windows machines, configure the monitoring inputs, deploy windows app and forward the logs to the indexing tier, lastly I will discuss and configure the search head and add the search peer as part of the Splunk distributed architecture design.
Don't buy poor quality courses! This course is a free high quality that I will take you step by step to successfully deploy Splunk in a distributed architecture design, through engaging video tutorials and teach you everything you need to know to be a successful Splunk Administrator
I remember my first time when I started to learn Splunk, I didn’t know where to start and with all the information out there makes it even harder to grasp, so today I am putting my self in your shoes to help you conquer this complexity .so I have designed this free course specially for you to take you