https://github.com/divonisimon97/log-analysis-siem-integration-with-splunk-on-linux
In this project, I set up Splunk on Linux to collect, analyze, and monitor system logs (syslog, authentication logs, and system events) for IT support and security purposes.
https://github.com/divonisimon97/log-analysis-siem-integration-with-splunk-on-linux
Last synced: 4 months ago
JSON representation
In this project, I set up Splunk on Linux to collect, analyze, and monitor system logs (syslog, authentication logs, and system events) for IT support and security purposes.
- Host: GitHub
- URL: https://github.com/divonisimon97/log-analysis-siem-integration-with-splunk-on-linux
- Owner: divonisimon97
- Created: 2025-03-07T01:13:37.000Z (over 1 year ago)
- Default Branch: main
- Last Pushed: 2025-03-09T00:14:42.000Z (over 1 year ago)
- Last Synced: 2025-03-09T01:19:38.990Z (over 1 year ago)
- Size: 2.93 KB
- Stars: 0
- Watchers: 1
- Forks: 0
- Open Issues: 0
-
Metadata Files:
- Readme: README.md
Awesome Lists containing this project
README
# Log Analysis SIEM Integration with Splunk on Linux
Description
In this project, I set up Splunk on Linux to collect, analyze, and monitor system logs (syslog, authentication logs, and system events) for IT support and security purposes.
Languages and Utilities Used
- Terminal
Environments Used
- Linux (6.11.2)
Program walk-through:
Download & Install Splunk:
Receive Web Interface:
Log-In Web Interface:
Open the rsyslog configuration file:
Add a Forwarding Rule:
Add a Rule to Write to /var/log/syslog:
Create the Log File, Set Appropriate Permissions, then Restart:
Export Journal Logs to a File:
Check for Logs in the System Journal:
Test the Configuration:
Configure Splunk to Monitor /var/log/journal_export.log:
Select Source, Input Settings & Review:
Search & Analyze Logs in Splunk:
Filter Specific Events:
