Splunk Installation and Working - v1.1
Splunk Installation and Working - v1.1
1. Project Statement
This project focuses on the installation and initial configuration of Splunk Enterprise on a
Windows Server 2022 environment. Participants will follow a structured process to download,
install, and set up Splunk, then upload a sample dataset for analysis. The objective is to provide
hands-on experience with data ingestion and querying within Splunk, allowing users to gain
insights into Splunk’s data indexing and search capabilities.
Scenario-Based Questions:
1. After installing Splunk Enterprise, you encounter an issue where the uploaded dataset doesn’t
appear in the search results. What steps would you take to troubleshoot and identify the problem?
2. Imagine you’re tasked with analyzing a CSV file containing application logs. Describe how
you would configure Splunk to ingest this file and prepare it for efficient querying.
3. A security alert has been triggered, and you need to quickly search the logs for events that
occurred on August 27. How would you construct your Splunk query to locate relevant data
efficiently?
4. Suppose the dataset you’re working with is over 500 MB, which exceeds the upload limit in
Splunk. What are alternative methods you could use to analyze large datasets within Splunk?
5. During the initial setup, you created a custom username and password. If you forget your
credentials, what steps can you take to recover access to your Splunk instance?
2. Lab Requirements:
Procedure:
● Firstly download splunk dataset and click on upload. Dataset download link : GitHub -
splunk/botsv1 .
● Visit link:
“https://s3.amazonaws.com/botsdataset/botsv1/csv-by-sourcetype/botsv1.WinEventLog
%3AApplication.csv.gz”
● Click on select file . Remember maximum file which can be uploaded is of 500 MB.
● After successful file upload click on NEXT.
Query 2: