📜 ⬆️ ⬇️

Splunk - a general description of the platform, the basic features of the installation and architecture

As part of TS Solution's corporate blog, we are starting a series of educational articles on a product for analyzing machine data like Splunk . Most articles will be “how to tutorial”, a description of interesting cases and the solution of popular problems.

In this article we briefly describe the system itself and its purpose, as well as consider the options for installing it.


A few words about Splunk


Splunk is a platform for collecting, storing, processing and analyzing machine data, that is, logs. Today it is extremely popular in the USA and in Europe and gradually enters other markets, including Russia. One of the main features of the platform is that it can work with data from virtually any source, and therefore the list of possible applications of the system is very wide.


')
Splunk, in most cases, (automatically or using add-ons) parses the input data into fields and values ​​and subsequently processes them. Processing takes place through SPL queries (a special language from Splunk), with which you can build various samples and tables, sort, filter, aggregate, generate reports, create calculated fields, access both internal and external directories, create dashboards, with wide visualization spectrum and make alerts (for example, by the result of the request to send tickets to the Service Desk). All this can be packaged in your personal app.



The main differences or strengths Splunk



Where can I download?


The free version of Splunk with a 500 MB index per day is available on the company's official website , the only thing you need to do is register.

System requirements




Splunk supports both 32-bit and 64-bit bit architectures. Below are tables with available platforms for Splunk separately for Unix and Microsoft. The last column of the table contains information about Splunk Universal Forwarder. This is a separate distribution and a separate role in the Splunk platform, which acts as an agent and is solely responsible for collecting logs and sending them to the server.

Unix

A - version is available for download, but has no official support.
D - version is currently supported, but in future releases the company may remove it from official support

Windows

D - version is currently supported, but in future releases the company may remove it from official support
... - version is supported, but Splunk does not recommend using this architecture

Installation


After you have downloaded the installation file, simply run the installation and by default the system will rise in the base configuration. Detailed step-by-step installation instructions for Windows here , on a Unix system here .

After installing Splunk, the port 8000: localhost: 8000 should be accessible via the web interface and after changing the password and logging in, you will see the following interface.



This concludes the introductory review. In the next article we will explain how to load data into Splunk, how to use the SPL language, how to build graphs and dashboards.

Also, we recently did a general Web application about Splunk - you can see its recording on the link on Youtube . In this webinar, the basic functionality was shown and some case studies of the product were described.

Source: https://habr.com/ru/post/323814/


All Articles