SIEM Setup- Splunk & Security Onion Install

แชร์
ฝัง
  • เผยแพร่เมื่อ 9 ก.พ. 2025
  • If you still need to install Security Onion: • Intrusion Detection Sy...
    In this video I install Splunk Enterprise on our Security Onion server to ingest and correlate logs across multiple sources. Splunk Apps provide additional investigation capabilities, which you can leverage to configure Splunk as a SIEM.
    Links for this video:
    Splunk Enterprise Trial
    www.splunk.com...
    Security Onion App
    splunkbase.spl...
    Sideview utils
    splunkbase.spl...
    Splunk for OSSEC
    splunkbase.spl...
    Maxmind geolocation
    splunkbase.spl...
    Google Maps
    splunkbase.spl...
    Splunk Visualization
    splunkbase.spl...
    Zeek IDS (Bro)
    splunkbase.spl...
    Commands/Notes:
    Ensure splunk owns all apps by executing "sudo chown -R splunk:splunk *" within the /opt/splunk/etc/apps directory
    Open Splunk port 8000 to Host system. On HomeIDS:
    sudo ufw allow 8000
    Change "Debug 1" to "Debug 2" in /etc/nsm/securityonion/sguild.conf
    Restart nsm services with: sudo nsm_server_ps-restart
    Didn't cover it in the video, but you should enable SSL access to Splunk:
    Under Settings - System - Server settings, click General Settings
    Under Splunk Web, for Enable SSL (HTTPS) in Splunk Web, select the Yes radio button

ความคิดเห็น • 19

  • @HishanShouketh
    @HishanShouketh 6 ปีที่แล้ว +2

    This is awesome, hope to see more from you.

  • @dragonslayer3650-b4n
    @dragonslayer3650-b4n 5 ปีที่แล้ว

    This is great stuff, thanks for posting this videos. Keep up the good work!

  • @chromefinch
    @chromefinch 5 ปีที่แล้ว

    YES! dude this is great! thanks so much.

  • @sulthansk6444
    @sulthansk6444 4 ปีที่แล้ว

    Thanks for the video...

  • @ksboi29
    @ksboi29 5 ปีที่แล้ว

    Great information!!!

  • @unknowx0026
    @unknowx0026 6 ปีที่แล้ว

    great work bro

  • @ravenhurst00
    @ravenhurst00 5 ปีที่แล้ว

    Great video. Thank you.

  • @d3blogger
    @d3blogger 5 ปีที่แล้ว

    Great video! Where is the next vid?

  • @Katsumato0
    @Katsumato0 4 ปีที่แล้ว +2

    WARNING: some apps don't work anymore. Due to advanced XML being deprecated by Splunk.

  • @nelsonrodriguez8190
    @nelsonrodriguez8190 4 ปีที่แล้ว

    Is they a new updated Security Onion app now it does not work on Splunk any longer?

  • @sobagos
    @sobagos 4 ปีที่แล้ว

    Thanks for the video, really aswesome. I'm having issues setting this up on a distributed install, can you help?

  • @aklutse
    @aklutse 5 ปีที่แล้ว

    Bro:
    I was trying to enable the SSL as per your above instruction but couldn't my hand around it.
    I checked on both the Windows 10 settings and my Oracle VM settings but couldn't go beyond server Settings which brings up the Proxy setting

  • @pyrophreak2600
    @pyrophreak2600 5 ปีที่แล้ว

    The splunk start command did not work for the latest version 7.3.2

  • @DLANM57
    @DLANM57 6 ปีที่แล้ว

    After about 4 days my search quit working as the index reached the limit. I tried using the clean "clean eventdata" command and and even reinstalled Splunk, but neither worked. Do you have any advice on this?

  • @aklutse
    @aklutse 5 ปีที่แล้ว

    Any help from your end...?

  • @greenwithNV
    @greenwithNV 6 ปีที่แล้ว

    Can I run Splunk without a license?

    • @sqearlsalazar11
      @sqearlsalazar11  6 ปีที่แล้ว

      You can run a trial license for 30 days, then you have to convert to a free license. Something you could run internally for lab/testing, but not enterprise.

  • @SuperChelseaSW6
    @SuperChelseaSW6 5 ปีที่แล้ว

    Hello sir. Why u installing the apps in the windows host mashine instead of security onion?

    • @slopedoff
      @slopedoff 5 ปีที่แล้ว

      that's his test enviroment and where it's supposed to work. (Splunk & Security Onion)
      so it's installed in Ubuntu (with xfce graphic enviroment) = Security Onion with ready to go tools.
      Also he's installing Splunk for log analysis (still trying to figure out what splunk really does on top of others (or not)...