2.2 Splunk Website

Video Activity
Join over 3 million cybersecurity professionals advancing their career
Sign up with
Required fields are marked with an *
or

Already have an account? Sign In »

Time
1 hour 59 minutes
Difficulty
Beginner
CEU/CPE
2
Video Transcription
00:00
>> Welcome to Video 2 of Module 2.
00:00
Today we're talking about the Splunk website,
00:00
which is obviously a really simple topic,
00:00
but I think it's important to know
00:00
what resources you have available,
00:00
especially when you're scrambling
00:00
to find a solution for something.
00:00
This is just my recommendation of
00:00
things that already have bookmarked.
00:00
If we pull up the Splunk website,
00:00
we're just on splunk.com here.
00:00
And it's a little bit easy to get lost
00:00
into all the information that they've got available.
00:00
If we were to just look at resources, for example,
00:00
they've got eBooks you could read,
00:00
they've got tech briefs,
00:00
videos, webinars, white papers.
00:00
There's tons of stuff here.
00:00
I think some of the critical things to know exist
00:00
are Splunk docs.
00:00
Splunk actually has amazing documentation.
00:00
If you wanted to just
00:00
select your product here, you can search.
00:00
If you're looking for something specifically a bit,
00:00
let's just look at Splunk Enterprise.
00:00
They've even got it broken down in different categories.
00:00
Here's your installation manual,
00:00
and I guarantee you that's going to pretty
00:00
much tell you everything you would need to know,
00:00
barring unusual circumstances, how to install it.
00:00
Then we can look at adding data.
00:00
Learn how to configure the Splunk add-on for
00:00
Palo Alto Networks on
00:00
a single instance of Splunk Enterprise.
00:00
It's cool. They have really in-depth documentation.
00:00
Let's just click on one of these here, the typical page.
00:00
You can go down along the side here.
00:00
It tells you how to install system log server,
00:00
all the other things.
00:00
Something to pay attention
00:00
to is this version up in the corner here.
00:00
If you don't have the latest release,
00:00
you should go back a little bit.
00:00
Let's go back really far.
00:00
Let's see if this even exists
00:00
four version that might not even be compatible.
00:00
We can see the documentation
00:00
relevant for this particular version here.
00:00
Another place that's extremely helpful is Splunk Answers.
00:00
Chances are if you have a question for something,
00:00
somebody else has already asked
00:00
it and there are answers to it.
00:00
This is an extremely active community.
00:00
As we can see, somebody
00:00
last modified a question an hour ago,
00:00
three hours ago, two hours ago.
00:00
People are regularly answering
00:00
and asking questions on here.
00:00
Whenever you run into an issue,
00:00
one of the first things you might do is just try and
00:00
see if there's already a really good solution for it.
00:00
Splunk base is another place to look at.
00:00
If you're trying to even decide
00:00
if Splunk is going to work for you,
00:00
this might be a good place to start.
00:00
You can look for what kinds of apps that they have.
00:00
The most major products actually,
00:00
if they make sense to integrate with Splunk,
00:00
they've got something pre-built to do that.
00:00
You can check on here,
00:00
see what kinds of apps they have.
00:00
Then in later videos
00:00
we're going to talk about how to use apps.
00:00
But you can see here they've even got
00:00
slack notifications that you can add to Splunk,
00:00
all kinds of stuff.
00:00
That's a good place to be aware of.
00:00
Additionally, if we go back to splunk.com,
00:00
I said I was going to touch again on
00:00
certifications just to make sure you understand.
00:00
If we go to training,
00:00
there are lots of
00:00
learning materials available from Splunk directly.
00:00
This is the course.
00:00
I really recommend that you take.
00:00
This introduction to Splunk
00:00
is actually a little more basic than this.
00:00
For a fundamentals one
00:00
course you would think that that would be really simple,
00:00
but it goes a lot more in-depth than you would expect.
00:00
After completing this course,
00:00
I recommend going into that if you're interested in
00:00
Splunk and then taking the exam that comes with it.
00:00
You can be a certified course blink user.
00:00
Along here, we have different learning paths.
00:00
If you have a particular interest in mind,
00:00
or you just want to browse what they have available,
00:00
check these out, and they
00:00
do update this pretty regularly.
00:00
I like to come back here every
00:00
now and again and see what they've added,
00:00
see what they've changed.
00:00
Anyways, that's pretty much the Splunk site.
00:00
Go ahead and make your bookmarks.
00:00
I think that'll help you out and
00:00
we'll be onto the next topic. Thanks for watching.
Up Next