image
The Ultimate Drawing Course Beginner to Advanced...
$179
$79
image
User Experience Design Essentials - Adobe XD UI UX...
$179
$79
Total:
$659

Description

Machines are trying to tell us something through logs, so they are a very valuable resource for IT departments to ensure that everything is working as expected and to give us an idea of what is going on in our IT environments which will help to respond faster to incidents.
In this
hands-on
course, we will learn how to set up a small virtual LAB to simulate
real-world logging and monitoring scenarios
, where we will collect logs from
Apache web server
and
Fortigate firewall
and send them to
Splunk
for storage, analysis, visualization and alerting.
I selected these two log sources specifically because they represent
the majority of log sources
you will find in your environment, so you can follow the same steps in the course to integrate different log sources in the future.
There are more complex log sources to integrate like logs that are pulled from database but they are not suitable to be discussed in an introductory course.
After we onboard logs to
Splunk
, we will search and explore data we received then we will add knowledge to it by extracting interesting fields in these logs. 
At this point, our logs will be ready to be treated by
Splunk Searching Processing Language (SPL)
to create reports, dashboards, and alerts.
This course will make you ready to dig deep into more advanced topics of Splunk administration like,
High availability
Indexers clusters
Search head clusters
Deployments servers
Splunk Apps
Advanced SPL
But you have to walk before you run, so my vision for this course is to master the basics first to break the ice.
Note:
When the course was recorded Splunk version was
8.0.4.1
, On 10-09-2022 I validated
Splunk Enterprise 9.0.1
on my own test lab and the steps and instructions in this course still apply.
Who this course is for:
Security engineers
IT Administrators
Security operations center engineers
Security incident handlers
Systems administrators
Anyone wants to explore huge log files/feeds
Anyone interested to learn Splunk

What you'll learn

Requirements

  • You will need a copy of Adobe XD 2019 or above. A free trial can be downloaded from Adobe.
  • No previous design experience is needed.
  • No previous Adobe XD skills are needed.

Course Content

27 sections • 95 lectures
Expand All Sections
1-Introduction
3
1.1-Introduction to the course
1.2-Course structure
1.3-Udemy 101: Getting the most from this course
2-Preparing LAB
5
2.1-Installing VMware Workstation Player
2.2-Installing Ubuntu virtual machines
2.3-Assign Static IPs to Ubuntu machines and change default password
2.4-Downloading Splunk and installing Apache server
2.5-Importing Fortigate Appliance
3-Installing Splunk
3
3.1-Installing Splunk and Splunk Universal Forwarder
3.2-Deployment types
3.3-Configure Splunk to receive logs
4-Getting data in
2
4.1-Collecting logs from remote nodes
4.2-Configure Syslog source
5-Searching and exploring logs
3
5.1-Search and explore data on Splunk
5.2-Extract fields and add knowledge to data
5.3-Splunk Search Processing Language (SPL)
6-Reporting and monitoring
2
6.1-Creating reports and dashboards
6.2-Creating alerts
7-Keep learning
2
7.1-More to explore
7.2-Don't forget to leave a rating!