Skip to content


Logging and Learning

We recently deployed Splunk at work. I’ve only pointed a few servers (the core ones) and the networking gear towards it and it’s already making a HUGE impact by simplifying the tasks that rely on log review. Just by adding the domain controllers and core switches, we immediately gain visibility to Authentication and DHCP matters. As we move forward, we will continue to extend the flow to include in process operations logs from Enterprise Applications like SAP, Oracle eBusiness, and all of the other ERPs we have in house. So far the log flow is pretty light (only about 240MB/Day average) but once we start to ramp up the use of the system I expect this to grow dramatically.

So far I have been really happy with the way Splunk works. I am just now starting to hit some frustration as I start install some of the applications and actually go through their implementation. This is fairly typical of open source type software and the additions available from the splunkbase are not an exception to the rule. In particular, I am trying to get the CheckPoint OPSEC LEA Application installed and configured. The installation only hit one snag on the CentOS 5 box I have splunk running on and I noted the fix on the applications page.

So now I have the application installed and I have no idea what to do next to configure or verify if it’s working. It looks like I’ll have to drop back to the original source project to run my troubleshooting from… I’[ll post more on this as I move along in hopes it will be helpful to others.

Posted in Active Directory, CentOS, OpenSource, Security, Splunk, linux, msserver.

2 Responses

Stay in touch with the conversation, subscribe to the RSS feed for comments on this post.

  1. Thanks for the help on the OPSEC configuration page: http://www.splunk.com/doc/latest/admin/Opsec

    If you still need help, feel free to ping support or hop on the IRC channel on efnet: #splunk. The 4.0 release will have integrated application installation support, which should help address some of the issues you had with installing the CheckPoint application.

    If coding against Splunk interests you, more information is available for getting data out of Splunk programmatically on Splunk Labs pages on Google: http://code.google.com/p/splunk-labs

  2. hey man! we miss you back at the RBJ Community Forums. come drop by and say hello when you get a chance….

    peace and luv,
    randomguru

Some HTML is OK

(required)

(required, but never shared)

or, reply to this post via trackback.