3.3 Installing Splunk on Linux

Video Activity
Join over 3 million cybersecurity professionals advancing their career
Sign up with
Required fields are marked with an *
or

Already have an account? Sign In »

Time
2 hours 29 minutes
Difficulty
Beginner
CEU/CPE
2
Video Transcription
00:00
>> Hi. In this video,
00:00
we'll walk through installing Splunk
00:00
on Linux via the command line.
00:00
The next video covers a Windows installation.
00:00
If you want any other options or if you'd
00:00
like to follow written instructions for these videos,
00:00
please check out the supplemental
00:00
materials for this course.
00:00
To start off, we'll go to the Splunk website.
00:00
You will need to be signed in to download Splunk.
00:00
After that, go to products,
00:00
and then free trials and downloads.
00:00
From here, you can pick if
00:00
you want to download Splunk Enterprise or Splunk free.
00:00
Now, when I click on Splunk free,
00:00
something you might notice is that it
00:00
takes me to the site for a Splunk Enterprise.
00:00
What happens here is that you
00:00
get a free trial of Splunk Enterprise,
00:00
and if you don't make a purchase,
00:00
it turns into Splunk free,
00:00
which has some limitations we talked
00:00
about in an earlier video,
00:00
such as restricted user options and some other things.
00:00
From here, we'll select our download.
00:00
For this video, we'll pick
00:00
the Linux 64 bit tar installation package.
00:00
That's something you can do.
00:00
If you look down on the bottom here,
00:00
there are options for older and other downloads.
00:00
If you don't see what you want up here,
00:00
there are lots of other options.
00:00
Once you click on "Download
00:00
Now," you should get a pop-up to download the file.
00:00
You also see that this page has a lot of
00:00
useful documentations and even instructional videos here.
00:00
If you want to just download this file and
00:00
run through the installation, that's fine.
00:00
But I'm going to hit "Cancel" and
00:00
do something a little bit different.
00:00
If you only want to work from the command line,
00:00
this page gives you an easy option for the W.
00:00
Get you to enter right up here.
00:00
You can just copy and paste this into the command line.
00:00
This seems a little bit of a roundabout way to do it.
00:00
But if, for example,
00:00
you're just SSH into the machine,
00:00
it might come in handy.
00:00
I'm going to do this, and then jump
00:00
into the terminal here and just paste that in.
00:00
Now I've already downloaded,
00:00
so I'm going to skip it here.
00:00
But we've got this installation package now.
00:00
The next step is to unharmed this file.
00:00
Something you'll thank yourself later for,
00:00
is using the default directory for Splunk,
00:00
which is the app directory.
00:00
It makes your life so much easier for following
00:00
instructions and keeping track of
00:00
where you're at when you do this.
00:00
In order to do this,
00:00
I'm going to type in tar xvzf,
00:00
and then copy and paste this package name,
00:00
and then do C and opt.
00:00
Then after we're done explaining the file here,
00:00
the next thing we need to do is just start it.
00:00
Spoon commands are located in
00:00
the bin folder under opt Splunk bin,
00:00
if you do it like we just did.
00:00
To start up,
00:00
we'll just go opt,
00:00
splunk, bin, splunk, start.
00:00
Now you can just enter that,
00:00
but I'm going to add in
00:00
another step and hit n-type and accept the license.
00:00
Just to save myself some scrolling.
00:00
Now I'll need to put in
00:00
a username and come up with a password.
00:00
Confirm the password,
00:00
and then we should be good to go.
00:00
One thing you'll notice is right here it
00:00
says the splunk web interface is
00:00
at http vacay 8,000.
00:00
That's fine machine name.
00:00
If we were to open up a browser,
00:00
we can just type that in.
00:00
Here we have our live Splunk,
00:00
we can log into, and you started with.
00:00
Perfect. Another step that could be in
00:00
the instructions is setting Splunk to start at boot time.
00:00
I'm going to leave this out, but
00:00
the instructions are in the supplemental materials.
00:00
If you don't set it the next time you log in,
00:00
you'll just run the same command
00:00
minus the except license part to get us started.
00:00
In further videos, we'll be spending most of our time in
00:00
the web console and go more in depth
00:00
with searches and navigating that.
00:00
But thanks for watching.
00:00
In the next video,
00:00
we'll do this installation on a Windows machine.
Up Next