2 hours 29 minutes
Hi. We're on module four. And in this video will be getting familiar with the Splunk Web interface.
To start off,
I'm logged into Time Machine, where we previously installed *** Enterprise. I've got a browser open to the *** Web interface and is unable to connect.
Since I didn't enable boots start and have since shut down this machine *** isn't currently running. I can check that by a
going opt Splunk
bins. Blunk stat status.
It's plenty is not running.
So if you want to start the *** software to run automatically when you turn on your machine,
you could enter the following command ops plunk
to start it up, I'm gonna go ops Plunk, been Splunk.
checking that everything that been running and what that's done
should be able to log in
for starters, really go to one of the most commonly used places the search and reporting out.
Since we haven't got data yet 40 in this point, you'll only be able to get someone's own logs about how it and its host are doing.
I'm going to type in in next equals
internal, just so we have something to see here
from this green. We have a few options.
We could save this as a new alert report or dashboard,
and we can go through some different options to visualize the data.
The screen I
is another good place to know about.
It's a quick overview of the health status of ***. Since everything screen there is anything we need to investigate here.
Messages can be another good place to check for possible errors and issues.
He's just told me there's a newer version available.
Another place you can get.
A more thorough overview of the health and status of *** is by going to settings.
Mother during console.
This page gives us a nice overview of Harlem looking this far a CPU disk, memory and license usage.
If I click on health check,
I can run a report for possible issues.
We're gonna go in depth with this, but you want to know what the different pieces are. If you plan to have administrative duties and ***,
I mean, click back on the settings button here and go do searches, reports and alerts.
You immediately notice
that there are already some items here.
These air alerts designed to let you know
when there's a problem with splints. Health, such as if you're at your life since quota. Or if you're running out of this space,
he's all pertained to the monitoring consul app.
If I click here, I can select all.
You'll notice that we have several pages of
save searches, reports or alerts.
If I want, I can look at the ones that I've just built,
which is none right now.
I mean, take a look at users by going to settings,
either in authentication and access controls.
I click on users.
There's just me right now. But if I wanted to get out of new user by clicking here
and if I go back
and click on rolls,
you can see the difference
default roles that are available
You should be set at an admin right now. But if you want to create more limited roles, which is a good idea to only give people is much access is they need. You have the ability of *** in your price to limit users toe only access, sir, indeed, A and limit their access in other ways.
You can also tie accounts to external indication methods such as Al DAP
going back to settings. We also restart Splunk from the Web consul by going to settings
And then we can just click this restart button if we wanted to.
And then under activity, there are two useful options. Jobs and triggered alerts.
Treated alerts are just what you think alerts have recently triggered. If we want to open up jobs,
ah, it will show you which jobs have recently completed or currently running such a CZ searches.
If I wanted to go back into the search and reporting AP and run a search,
we can see it pop up in there
while data is stored for a while, which is determined by your retention policies, Specific searches typically aren't kept for very long.
So in this job's area, if you knew that you wanted to a store specific results for a while and maybe share it,
um, that you could extend the life in here
by clicking on that button.
You could also delete the job, such as if you're in a situation where too many searchers were run at once and it was, um,
You could go through and try and delete the unneeded ones. Or if you forgot about what that perfect search was that you were in just a minute, going had closed out the window. It was still show up here
in future. Videos will get to a lot of these other items, so just looking at data inputs,
indexes and lookups.
Now we'll just hop back to my slides for a quiz.
True or false,
you can restart Splunk fromthe Web interface.
Is this true?
You can restart Splunk
by going to studies and server controls
in the next video. We'll look at different ways to get data in this punk. Thanks for watching.
Splunk online test helps to assess knowledge of Splunk which is an advanced, scalable and ...
Event Log Collection
In this lab you will use Splunk Enterprise to ingest logs from a local host ...