Skip to content

daily-ops/splunk-in-3-minutes

Repository files navigation

Splunk in 3 minutes

Setting up an environment may take some of your time. This repository aims to get a local playground environment up quickly. It will require internet access at the start then everything can go offline and disconnected once setup. The 5 forwarders come built-in to simulate multiple h9sts and sources, where references for queries are scattered around internet, for example, https://www.stationx.net/splunk-cheat-sheet/.

What does this repo do?

  • Create Splunk Enterprise trial container (This should allow us to play with Alert)
  • Create 5 Splunk forwarder containers with log generator script (Credit the generator script to Josh Samuelson from the Learning Splunk course).

Pre-requisites

  • Internet connection
  • Docker

The two scripts

  • splunk.sh : Setup environment by creating a bridge network for Splunk and 5 nodes with Splunk Forwarders
  • cleanup.sh : Clean up all the containers and network bridge

5 Hosts

Screenshot_2025-03-11_20-48-06

Queries

Screenshot_2025-03-11_11-30-17 Screenshot_2025-03-11_16-21-42 Screenshot_2025-03-11_12-08-41 Screenshot_2025-03-11_11-45-53 Screenshot_2025-03-11_11-36-49 Screenshot_2025-03-11_11-35-20

About

No description, website, or topics provided.

Resources

License

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published