Network Monitoring Using Splunk
Network Monitoring Using Splunk
SPLUNK
Network monitoring using splunk 2
Table of Contents
1.1 Description
They tend to check the activity and health of internal systems via the network by sending
a signal, called a ping, to various system ports. The testing system uses a huge variety of
check intervals, which is basically the time between pings.
STEP 1:
Download and Install splunk free enterprise on your local system, from the splunk
website.
Login to the splunk account using the credentials.
STEP 2:
Move into the root directory, and create a directory named ‘pings’. Within the directory,
create another directory called ‘targets’
STEP 3:
Move into the directory created, and using nano editor, create a file called ’monitor.sh’
STEP 4:
Within the file, type of the content as follows which takes in the logs
STEP 5:
STEP 6:
We the use the tail command which allows us to continuously update and see the last 10
lines of the output file, here the output file being, ‘googledns.txt’. Click on ‘control c’ to exit
STEP 7:
Click on Select, leaving the rest of the settings default, and it will lead to the page where
the logs are displayed
STEP 8:
Do a search query that describes all the ping results from one host to the timechart
function, from which we can view the average of the timechart values.
STEP 9:
Once the dashboard is saved, click on ‘view dashboard’ to view the dashboard created.
https://www.youtube.com/watch?v=1wkmEvsUe68
https://www.youtube.com/watch?v=HPVlHQjnxYs