Splunk Quick Userguide V2
Splunk Quick Userguide V2
cisco
Components Used:
The information in this document is based on Windows 2008 R2 server and Splunk version 4.3
Build 115073.
Document Audience:
This documentation is primarily for Customer support engineers, Sales Engineers and customers
who are engage in planning, deploying/implementing, and configuring Splunk in Windows or
Unix/Linux environment.
System Requirements:
Splunk Advanced Web Reporting runs on Windows and Red Hat Linux. There is no support for
virtualization for production instances of Splunk Advanced Web Reporting. Reference hardware
can be commodity-grade with the minimum specifications below.
• Intel x86 64-bit chip architecture with 2 CPUs, 4 cores per CPU, and 2.5 to 3 GHz per core.
• 16 GB RAM
• (4) 300-GB SAS hard disks at 10,000 rpm each in RAID 10 (800 IOPS or better)
• (1) Gigabit Ethernet network interface card (NIC). A second NIC for a management network is
recommended
Note: These hardware specifications are recommended for an organization with more than
25,000 users. Please talk to your account team to understand the hardware specifications you
will need to run Splunk Advanced Web Reporting at your organization.
Step 1:
Download Splunk from www.splunk.com
Step 2:
Install Splunk on the local host/server.
Step 3:
Once the installation is completed logon via Splunk GUI for the first time, and change admin
password.
Step 4:
Enter username: admin password changeme, and enter desired password for admin account for
subsequent logins.
This will bring you to the Splunk Welcome/Home/default Screen.
Step 5
Add Splunk permanent License via Splunk GUI: (default license is for 30 days 500 MB indexing
per day)
Manager » Licensing » Add new license > copy & paste the license XML directly...
Copy and paste license file and click on install
Following Screen appears:
Click on “restart now”, follow the screen:
Once the Splunk is up, log back in and verify the License status (indexing volume per day,
expiration etc...)
Manager » Licensing verify the expiration date (screen below show 500 MB per day expiration
Jan 18, 2038)
Step 6:
Upload “SplunkforCiscoIronportWSA” APP (APP file is available on Cisco Portal file
name “SFCIW_v1.0.37.tar (link below)):
http://www.cisco.com/cisco/software/release.html?mdfid=282803425&flowid=4951&software
id=283998384&release=Splunk%20Reporting%20SW&relind=AVAILABLE&rellifecycle=&reltype
=all
MUST check “Continuously index data from a file or directory this Splunk instance can access”,
provide path and check “More setting”
Once the logs are moved to appropriate logs directory, Execute step 2 from Splunk CLI,
When prompt point to “Splunk” directory under c:\ Program Files\Splunk and enter Splunk
admin credentials
Screen Similar to below will appear and let it run in the background, once this process is
completed. ALL historical logs will be imported in to Splunk database:
Please note it *may* take a while, and all depends how much historical logs data have to be
process by Splunk,
Once the Summary run completed we should start seeing current and historical data (see
below):
Other Resources:
http://docs.splunk.com/Documentation/Splunk/latest/Knowledge/WhatisSplunkknowledge >
Splunk knowledge base (KB)
http://answers.splunk.com > Splunk Blog, FAQ, Wiki Documentations, Splunk Community, post
questions etc.
http://splunk-base.splunk.com/answers/ > Find an Answer for common Splunk issues
http://splunk-base.splunk.com/ask/ > Post a questions to Splunk
http://www.splunk.com/support/list/forum > Splunk Forums
http://docs.splunk.com/Documentation/Splunk > Splunk version specific documentations
http://wiki.splunk.com/Community:TroubleshootingIndexedDataVolume > Troubleshooting
Indexed Data Volume
http://www.cisco.com/cisco/software/type.html?mdfid=282803424&flowid=4950