ไม่สามารถเล่นวิดีโอนี้
ขออภัยในความไม่สะดวก

Splunk CIM (PART-1) : Installation and data setup

แชร์
ฝัง
  • เผยแพร่เมื่อ 5 ก.ค. 2020
  • If you want to avail the membership please follow the below link,
    / @splunk_ml
    In this video I have discussed about the splunk CIM installation and OSSEC data setup.
    OSSEC setup step : blog.rapid7.co....
    Setup Syslog for OSSEC : www.ossec.net/d...
    Docs can be downloaded from the below repo:
    github.com/sid...

ความคิดเห็น • 26

  • @RM-gm7lu
    @RM-gm7lu ปีที่แล้ว +1

    Great video!! your channel is the best on splunk ! Thank you for your efforts in sharing the KNOWLEDGE!

  • @sandipanpaul7482
    @sandipanpaul7482 3 ปีที่แล้ว +3

    Your videos are really helpful. I recently passed the power user exam. Now going for the admin user.

    • @splunk_ml
      @splunk_ml  3 ปีที่แล้ว

      Best of luck!

    • @bhanuayikam6064
      @bhanuayikam6064 3 ปีที่แล้ว

      Hi @Sandipan paul, Can you please tell me what are all the videos or pdf's you have followed for power user exam? it would be really helpful for me as I have exam in dec

    • @sandipanpaul7482
      @sandipanpaul7482 3 ปีที่แล้ว

      @@bhanuayikam6064 th-cam.com/video/gsV3ukSztHc/w-d-xo.html
      This video will help you alongwith fundamental 2 document.

    • @bhanuayikam6064
      @bhanuayikam6064 3 ปีที่แล้ว

      @@sandipanpaul7482 Thanks a ton :)

  • @__sagar_shah__591
    @__sagar_shah__591 2 ปีที่แล้ว

    should also include the link to the playlist in every video will increase your number of views

  • @__goyal__
    @__goyal__ 2 ปีที่แล้ว

    Thanks Sid!

  • @valishaik9209
    @valishaik9209 4 ปีที่แล้ว

    Amazing video, thank you.

  • @rocking1833
    @rocking1833 ปีที่แล้ว

    Thanks!

  • @dudishosh
    @dudishosh 4 ปีที่แล้ว +1

    Thank you for this video, Where should the CIM application should be installed? is it on the search head or the Indexer?

    • @splunk_ml
      @splunk_ml  4 ปีที่แล้ว +1

      It is the SH only app.
      docs.splunk.com/Documentation/CIM/4.16.0/User/Install

    • @dudishosh
      @dudishosh 4 ปีที่แล้ว

      @@splunk_ml Sorry, but what is the SH? tnx

    • @sandipanpaul7482
      @sandipanpaul7482 3 ปีที่แล้ว

      @@dudishosh SH means search head

  • @karanmulchandani5424
    @karanmulchandani5424 4 ปีที่แล้ว

    I am not able to see ossec web ui after restarting. Is there a firewall setting which we have to allow for ossec separately? Fyi I have allowed 514 and 8000. So, I can see splunk UI but not ossec UI. Please advice

    • @splunk_ml
      @splunk_ml  4 ปีที่แล้ว

      not really....did you followed the same instructions to install OSSEC ui?

  • @amirnenihemanthkumar8254
    @amirnenihemanthkumar8254 3 ปีที่แล้ว

    Thank you!! ... The video is really helpful. But at the Syslog IP address configuration step, we need to provide the IP address of the Splunk server instead of localhost(127.0.0.1).

    • @splunk_ml
      @splunk_ml  3 ปีที่แล้ว +1

      As I was using the same server as receiver localhost also works.

  • @AI-AF-70
    @AI-AF-70 2 ปีที่แล้ว

    Great video !! thank you! But I believe you have two copies of this posted to TH-cam. your # 25 and #26 of this playlist are the same. So are #27 and #28, they are duplicates also. Great videos though, thanks

    • @splunk_ml
      @splunk_ml  2 ปีที่แล้ว +1

      Actually when I added to youtube playlist its displaying like that, I have raised a ticket to youtube support but still they didnt fixed it.

    • @AI-AF-70
      @AI-AF-70 2 ปีที่แล้ว

      @@splunk_ml Ah ! i should have known how well done your videos are that you wouldn't have missed something like that. Talk about slow support on youtube's part !!!

  • @Sandeep223358
    @Sandeep223358 4 ปีที่แล้ว

    What if I have data which is not CIM compatible? I have kafka logs how can normalize the data here?

    • @splunk_ml
      @splunk_ml  4 ปีที่แล้ว

      Please check out the second part I posted on 9th July. I hope that will answer your question.

  • @ajaykapoor40
    @ajaykapoor40 4 ปีที่แล้ว

    CIM Part 2 is missing in the playlist. The next video of CIM is the duplicate of this one. Can you update with the right one.

    • @splunk_ml
      @splunk_ml  4 ปีที่แล้ว +1

      I still not posted the part 2. I will do it tomorrow.

  • @hamiltonian4698
    @hamiltonian4698 3 ปีที่แล้ว

    If you're running Splunk as non-root user (best practice), then you will not have access to port 514. Just use 5514 instead.