Skip to content

In this project, I set up Splunk on Linux to collect, analyze, and monitor system logs (syslog, authentication logs, and system events) for IT support and security purposes.

Notifications You must be signed in to change notification settings

divonisimon97/Log-Analysis-SIEM-Integration-with-Splunk-on-Linux

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

10 Commits
 
 

Repository files navigation

Log Analysis SIEM Integration with Splunk on Linux

Description

In this project, I set up Splunk on Linux to collect, analyze, and monitor system logs (syslog, authentication logs, and system events) for IT support and security purposes.

Languages and Utilities Used

  • Terminal

Environments Used

  • Linux (6.11.2)

Program walk-through:

Download & Install Splunk:
Creating a MD5-crypt hash Creating a MD5-crypt hash Creating a MD5-crypt hash

Receive Web Interface:
Creating a MD5-crypt hash

Log-In Web Interface:
Creating a MD5-crypt hash

Open the rsyslog configuration file:
Creating a MD5-crypt hash

Add a Forwarding Rule:
Creating a MD5-crypt hash

Add a Rule to Write to /var/log/syslog:
Creating a MD5-crypt hash

Create the Log File, Set Appropriate Permissions, then Restart:
Creating a MD5-crypt hash

Export Journal Logs to a File:
Creating a MD5-crypt hash

Check for Logs in the System Journal:
Creating a MD5-crypt hash

Test the Configuration:
Creating a MD5-crypt hash Creating a MD5-crypt hash

Configure Splunk to Monitor /var/log/journal_export.log:
Creating a MD5-crypt hash

Select Source, Input Settings & Review:
Creating a MD5-crypt hash Creating a MD5-crypt hash Creating a MD5-crypt hash

Search & Analyze Logs in Splunk:
Creating a MD5-crypt hash Creating a MD5-crypt hash

Filter Specific Events:
Creating a MD5-crypt hash Creating a MD5-crypt hash

About

In this project, I set up Splunk on Linux to collect, analyze, and monitor system logs (syslog, authentication logs, and system events) for IT support and security purposes.

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published