Splunk App vs Add-On - Whats the Difference

Splunk App vs Add-On - What's the Difference?

A guide to understanding the difference between a Splunk App and a Splunk Add-On.

August 11, 2024 · 2 min · 275 words · Emlin
Bearlychilly - Detecting Typosquatting with Splunk and the URL Toolbox App

Bearlychilly - Detecting Typosquatting with Splunk and the URL Toolbox App

Splunk users can apply the ut_levenshtein macro from the URL Toolbox app to compare domain names against a reference domain, enabling the detection of potential typosquatting.

February 21, 2024 · 3 min · 543 words · Emlin
How to Make a Syslog-NG Config with Examples

How to Make a Syslog-NG Config with Examples

In this guide, we will walk you through the process of creating a Syslog-NG configuration that caches and organizes syslog data on disk. Additionally, we will delve deep into the structure of the config, examining each option we utilize. Finally, we will explore configuring ‘catch-all’ entries.

January 19, 2024 · 13 min · 2567 words · Emlin
How to Install Syslog-NG on Linux - Ubuntu and Debian

How to Install Syslog-NG on Linux - Ubuntu and Debian

In this guide, we’ll walk you through the process of installing Syslog-NG on your Ubuntu or any other Debian-based Linux distribution. Syslog-NG is a powerful logging and event management tool used widely in cybersecurity and system administration. Follow these steps to get it up and running on your system.

January 18, 2024 · 2 min · 372 words · Emlin
Finding and Replacing Encrypted Secrets in Splunk Configurations

Finding and Replacing Encrypted Secrets in Splunk Configurations

Have you ever needed to locate and replace encrypted secrets in your Splunk configurations? It’s a tricky task that requires careful handling. In this article, we’ll guide you through the process.

December 8, 2023 · 3 min · 453 words · Emlin
Demystifying Splunk Index Retention Settings

Demystifying Splunk Index Retention Settings

Splunk’s index retention settings might seem tricky because they involve various options. If you don’t fully understand these configuration options, you could encounter problems like data being deleted too early or not being removed as expected. Let’s explore some important index retention settings in indexes.conf.

October 4, 2023 · 6 min · 1231 words · Emlin
Basics of Network Connectivity Troubleshooting

Basics of Network Connectivity Troubleshooting

In this guide, we will explore network connectivity troubleshooting using a simple use case.

June 1, 2023 · 7 min · 1358 words · Emlin
Splunk Enterprise Backup Strategy - Secure Your Configuration Files

Splunk Enterprise Backup Strategy - Secure Your Configuration Files

Maintaining a reliable backup strategy is crucial when working with Splunk Enterprise, as it ensures the ability to revert back to a functional state in the event of an unrecoverable issue. In this article, we will explore a simple yet effective method of backing up Splunk’s /opt/splunk/etc directory.

May 26, 2023 · 5 min · 913 words · Emlin
How to Install Splunk

How to Install Splunk 9.x on Ubuntu

Lets take a look at the steps needed to install Splunk 9.x on a Ubuntu Linux server.

May 23, 2023 · 3 min · 556 words · Emlin
Installing Docker and Docker-Compose on Ubuntu 20.04

Installing Docker and Docker-Compose on Ubuntu 20.04

This is the process for installing Docker and Docker-Compose on Ubuntu 20.04

May 23, 2023 · 3 min · 506 words · Emlin