ãã®èšäºã§ã¯ãWindowsããã³LinuxããSplunkã«ããŒã¿ãããŠã³ããŒãããŠãããã«åŠçããã³åæããæ¹æ³ãé ãè¿œã£ãŠèª¬æããŸãã
åºæ¬çãªã€ã³ãã©ã¹ãã©ã¯ãã£ãæ§æãã
ããŒã¿ã®åéãéå§ããã«ã¯ã次ã®ã·ã¹ãã èŠçŽ ãå¿ èŠã§ãã
- Splunk-ã€ã³ãã¯ãµãŒ
- WindowsãµãŒããŒ
- LinuxãµãŒããŒ
Splunkã«ãã°ãã¢ããããŒãããã«ã¯ãæåã«ã€ã³ãã¯ãµãŒãèšå®ããå¿ èŠããããŸããããã«ã¯ä»¥äžãå¿ èŠã§ãã
â¢ããŒã¿ãåä¿¡ããããã«Splunk-indexerãã€ã³ã¹ããŒã«ããŠèšå®ããŸãã
ãŸãããã·ã³ã«Splunkãå¿
èŠã«ãªããŸããããã¯ã€ã³ãã¯ãµãŒã§ãã Splunkãã€ã³ã¹ããŒã«ãããŠããªãå Žåã¯ãSplunkãã€ã³ã¹ããŒã«ããæ¹æ³ãšã·ã¹ãã ã®è©³çŽ°ã«ã€ããŠã¯ãã¡ããã芧ãã ãã ã
ã€ã³ã¹ããŒã«åŸãããŒã¿ãåä¿¡ããããã«ã€ã³ãã¯ãµãŒãæ§æããå¿ èŠããããŸãã
èšå®-転éãšåä¿¡ ã次ã«[ ããŒã¿ã®åä¿¡]ã»ã¯ã·ã§ã³ã§æ°ããæ§æãè¿œå ããŸãïŒ åä¿¡ãæ§æããŸãã
ã€ã³ã¹ããŒã«åŸãããŒã¿ãåä¿¡ããããã«ã€ã³ãã¯ãµãŒãæ§æããå¿ èŠããããŸãã
èšå®-転éãšåä¿¡ ã次ã«[ ããŒã¿ã®åä¿¡]ã»ã¯ã·ã§ã³ã§æ°ããæ§æãè¿œå ããŸãïŒ åä¿¡ãæ§æããŸãã
â¢ã€ã³ãã¯ãµãŒã«ããŒã¿ãéä¿¡ãããã¹ãŠã®ãœãŒã¹ã§è»¢éãæ§æãããã€ã³ãã¯ãµãŒã«éä¿¡ãã¢ããªã±ãŒã·ã§ã³ãäœæããŸãã
ãã®ã¢ããªã±ãŒã·ã§ã³ã¯ããããã®ãœãŒã¹ãå€æ°ããå Žåããå€æŽãå ããããã«ã¢ã¯ã»ã¹ããããšãå°é£ãªå Žåã«ãããŒã¿ãœãŒã¹ã®ç®¡çãç°¡çŽ åããããã«å¿
èŠã§ãã ãŸãããã®ã¢ããªã±ãŒã·ã§ã³ã䜿çšãããšãå€ãã®ãã¹ãã§æœåšçã«èª€ã£ãæ§æå€æŽãè¡ããã1ã€ã®å Žæã§ã®ã¿å€æŽãå¶éã§ããŸãã
ã¢ããªã±ãŒã·ã§ã³ãäœæããŸãïŒ ã¢ããª-ã¢ããªã®ç®¡ç-æ°èŠè¿œå
ã¢ããªã±ãŒã·ã§ã³ãäœæããŸãïŒ ã¢ããª-ã¢ããªã®ç®¡ç-æ°èŠè¿œå
â¢ãã©ãŒã outputs.confæ§æãã¡ã€ã«
ã¢ããªã±ãŒã·ã§ã³ãäœæããããoutputs.confæ§æãã¡ã€ã«ãäœæããå¿
èŠããããŸãïŒãã®ãã¡ã€ã«ã®è©³çŽ°ã«ã€ããŠã¯ãSplunkã®å
¬åŒWebãµã€ããã芧ãã ãã ïŒ
ããã¹ããšãã£ã¿ã§ã次ã®ããã¹ããå ¥åããŸããindexer_hostname_or_ip_addressããåã®æé ã§èšå®ããã€ã³ãã¯ãµãŒã®ãã¹ãåãŸãã¯IPã¢ãã¬ã¹ãšåä¿¡ããŒãã«çœ®ãæããŸãã
outputs.confãšããŠä¿åãããã©ã«ããŒ\ etc \ apps \ sendtoindexer \ localã«è¿œå ããŸãïŒããŒã«ã«ãã©ã«ããŒãäœæããå¿ èŠããããŸãïŒã
ããã¹ããšãã£ã¿ã§ã次ã®ããã¹ããå ¥åããŸããindexer_hostname_or_ip_addressããåã®æé ã§èšå®ããã€ã³ãã¯ãµãŒã®ãã¹ãåãŸãã¯IPã¢ãã¬ã¹ãšåä¿¡ããŒãã«çœ®ãæããŸãã
[tcpout] defaultGroup = default-autolb-group [tcpout:default-autolb-group] server = <indexer_hostname_or_ip_address>:9997 [tcpout-server://<indexer_hostname_or_ip_address>:9997]
outputs.confãšããŠä¿åãããã©ã«ããŒ\ etc \ apps \ sendtoindexer \ localã«è¿œå ããŸãïŒããŒã«ã«ãã©ã«ããŒãäœæããå¿ èŠããããŸãïŒã
â¢ã€ã³ãã¯ãµãŒãžã®éä¿¡ã¢ããªã±ãŒã·ã§ã³ããã³ãã®ä»ã®ã¢ããªã±ãŒã·ã§ã³ã管çããããã«Deployment Serverãæ§æããŸãã
Deployment Serverã¯ãä»ã®ãã¹ãäžã®ãã¹ãŠã®é¢é£ããSplunkã€ã³ã¹ã¿ã³ã¹ã«ã¢ããªã±ãŒã·ã§ã³ãšæ§æãé
åžããããã«å¿
èŠã§ãã Deployment Serverãã¢ã¯ãã£ãã«ããã«ã¯ãå°ãªããšã1ã€ã®ã¢ããªã±ãŒã·ã§ã³ãïŒ
SPLUNK_HOMEïŒ
\ etc \ deployment-appsãã©ã«ããŒã«é
眮ããå¿
èŠããããŸãã ãã®äŸã§ã¯ã Send to indexerã¢ããªã±ãŒã·ã§ã³ãããã«ç§»åããŸããã ïŒä»ã®ã¢ããªã±ãŒã·ã§ã³ã§æ¬¡ã«è¡ãããã«ãã³ããŒã§ã¯ãªã移åãããŸãããïŒ
ãã®æ®µéã§ãã€ã³ãã¯ãµãŒã®äºåèšå®ãå®äºããWindowsããã³Linuxãã·ã³ã«ãšãŒãžã§ã³ããã€ã³ã¹ããŒã«ããŸãã
WINDOWS
ãã°ãããŠã³ããŒãããããã®æ±çšããŒã«ã¯ãç¹å¥ãªãšãŒãžã§ã³ãã§ããSplunk Universal Forwarderã§ãã Universal Forwarderã¯ãæ©èœãå€§å¹ ã«å¶éãããSplunk Enterpriseã®ããŒãžã§ã³ã§ããããã®å¯äžã®ã¿ã¹ã¯ã¯ãã¹ãããããŒã¿ãåéããŠéä¿¡ããããšã§ãã
ãã¡ãããããŠã³ããŒãã§ããŸãã
äžã®åçã¯ãUniversal ForwarderãWindowsãšLinuxãSolarisãšä»ã®ãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã®äž¡æ¹ã«ã€ã³ã¹ããŒã«ã§ããããšã瀺ããŠããŸãã
1. Universal Forwarderãã€ã³ã¹ããŒã«ããŸã
Deployment ServerãšããŠããSend to indexerãã¢ããªã±ãŒã·ã§ã³ãäœæããSplunkã€ã³ãã¯ãµãŒã®IPã¢ãã¬ã¹ãŸãã¯ååãæå®ããŸãã ããã©ã«ãã®ããŒãã¯8089ã§ãã ãã€ã³ãã¯ãµãŒã«éä¿¡ãããããã®æ©èœãå®è¡ãããããåä¿¡ã€ã³ãã¯ãµãŒã»ã¯ã·ã§ã³ã¯ç©ºçœã®ãŸãŸã«ãªããŸãã
2.次ã®ã¹ãããã¯ãSplunkã«æ»ãããã€ã³ãã¯ãµãŒã«éä¿¡ãã¢ããªã±ãŒã·ã§ã³ã®ãµãŒããŒã¯ã©ã¹ãå®çŸ©ããããšã§ãã
ãµãŒããŒã¯ã©ã¹ã¯ãã©ã®ã¿ãŒã²ããã¯ã©ã€ã¢ã³ããã·ã³éã§ã©ã®ã¢ããªã±ãŒã·ã§ã³ãé åžãããã瀺ãã«ãŒã«ã«äŒŒãŠããŸãã ãµãŒããŒã®ããŸããŸãªã¯ã©ã¹ã®åœ¢æåºæºã¯ããã·ã³ã®ã¿ã€ããOSãå°ççé åããŸãã¯ã¢ããªã±ãŒã·ã§ã³ã®ã¿ã€ãã§ããå Žåããããã¯ã©ã¹ã¯éè€ããå ŽåããããŸãã ïŒè©³çŽ°ã¯å ¬åŒãŠã§ããµã€ãã§èŠã€ããããšãã§ããŸãïŒ
èšå®-ãã©ã¯ãŒããŒç®¡ç-ç·šéã¢ã¯ã·ã§ã³-æ°ããã¯ã©ã¹ãè¿œå ããŸãã
3.ä¿ååŸãé åžããã¢ããªã±ãŒã·ã§ã³ãè¿œå ããããæ±ããããŸããããã¯ãããããã¯ã©ã€ã¢ã³ããšåŒã°ããã·ã¹ãã ãã¿ãŒã²ããã«ããŠãé åžå ãšãªããã®ã§ãã
ã¢ããªã±ãŒã·ã§ã³ã»ã¯ã·ã§ã³ã«ã ã€ã³ãã¯ãµãŒã«éä¿¡ ã ãè¿œå ããŸãã
4.次ã«ãã¯ã©ã€ã¢ã³ããè¿œå ããŸãã ã¯ã©ã€ã¢ã³ãã¯ãUniversal Forwarderãã€ã³ã¹ããŒã«ããWindowsãã·ã³ã«ãªããŸãã Universal Forwarderãæ£ããã€ã³ã¹ããŒã«ãããŠããã°ã Deployment Serverã«æ¥ç¶ãããŠããã¯ã©ã€ã¢ã³ãã®ãªã¹ãã«ãã·ã³ã衚瀺ãããŸã ã IncludeïŒwhitelistïŒã«å ¥ããŸã ã
5. _internalã€ã³ããã¯ã¹ã®å 容ãèŠããšããã¹ãŠãæ£ããæ©èœãããã©ããã確èªã§ããŸãã ãã€ã³ãã¯ãµãŒã«éä¿¡ãããµãŒããŒã¯ã©ã¹ã«è¿œå ãããšãUniversal Forwarderã¯ããã§å éšãã°ã®éä¿¡ãéå§ããŸãã ãŸãããã®ã€ã³ããã¯ã¹ã§ã¯ããšãŒãžã§ã³ããé©åã«æ©èœããŠãããã©ãããããã«ç£èŠã§ããŸãã
6.次ã«ã SplunkBase Webãµã€ãããç¹å¥ãªã¢ããªã³ãããŠã³ããŒãããŸããããã«ãããWindowsã®æäœã«é¢ããããŒã¿ãåéã§ããŸãã
7. Splunk-Indexerã«ã¢ããªã±ãŒã·ã§ã³ãã€ã³ã¹ããŒã«ããŸãïŒ ã¢ããª-ã¢ããªã®ç®¡ç-ãã¡ã€ã«ããã¢ããªãã€ã³ã¹ããŒã« ïŒ
ããã©ã«ãã§ã¯ããã£ã¬ã¯ããª... \ Splunk \ etc \ apps \ Splunk_TA_windowsã«ã€ã³ã¹ããŒã«ãããŸããããã®ã¢ããªã±ãŒã·ã§ã³ãå±éãµãŒããŒã«ã¢ã¯ã»ã¹ã§ããããã«deployment-appsãã©ã«ããŒã«ã³ããŒããŠãåãæ¹æ³ã§ä»ã®ãã·ã³ã«éä¿¡ã§ããããã«ããå¿ èŠããããŸãããã³ãã€ã³ãã¯ãµãŒã«éä¿¡ãã ïŒ éèŠ ïŒããŒã¿ã«å¿ èŠãªã€ã³ããã¯ã¹ãã€ã³ãã¯ãµãŒäžã«åœ¢æãããããã«ãappsãã©ã«ããŒã«ãä¿æããå¿ èŠããããŸãïŒã
8.次ã«ãã¢ããªã±ãŒã·ã§ã³ãäºåèšå®ããå¿ èŠããããŸãã
ãã£ã¬ã¯ããªã«ç§»åããŸã... \ Splunk \ etc \ deployment-apps \ Splunk_TA_windows
ãã®äžã«ãµããã£ã¬ã¯ããªãããŒã«ã«ããäœæããŸãïŒ éèŠ ïŒããŒã«ã«ãã£ã¬ã¯ããªå ã®æ§æãã¡ã€ã«ãåžžã«å€æŽããŸãïŒã
inputs.confãã¡ã€ã«ãã³ããŒããŸãã .. \ Splunk \ etc \ deployment-apps \ Splunk_TA_windows \ default \ inputs.confã¯ããŒã«ã«ãã£ã¬ã¯ããªã«ãããŸãã
å¿ èŠãªããŒã¿ã®ã€ã³ããã¯ã¹äœæããªã³ã«ããŸãã ãããè¡ãããã«ã ããŒã«ã«ãã£ã¬ã¯ããªããããã¹ããšãã£ã¿ãä»ããŠinputs.confãã¡ã€ã«ã«ããã€ãã®å€æŽãå ããŸãã ãã¡ã€ã«ã®å¿ èŠãªãããã¯ã§ãdisabled = 1ã®å€ãdisabled = 0ã«çœ®ãæããŸãã ã¢ããªã±ãŒã·ã§ã³ãã»ãã¥ãªãã£ãã·ã¹ãã ã®ã·ã¹ãã ãã°ãè¿œå ããŸãããã
9.次ã«ãSplunk-indexerã§ãå ã»ã©äœæãããµãŒããŒã¯ã©ã¹ãã¢ããªã±ãŒã·ã§ã³ã«è¿œå ããŸãã ïŒ èšå®-ãã©ã¯ãŒããŒç®¡ç-ã¢ããª-Splunk_TA_Windows-ã+ã-Windows Forwarder ïŒ
10. å±éãµãŒããŒãåèµ·åããŸã ãããã¯ããã£ã¬ã¯ããª... / splunk / binããã³ãã³ãã©ã€ã³ã䜿çšããŠå®è¡ã§ããŸãã
./splunk reload deploy-server
ããŒã¿ãã¢ããããŒããããŠãããã©ããã確èªããŸãã ïŒ èšå®-ã€ã³ããã¯ã¹ ïŒwineventlogã€ã³ããã¯ã¹ã«å«ãŸããŠããå¿ èŠããããŸãã å³ãããããããã«ãçŸæç¹ã§æåŸã«ããŠã³ããŒããããããŒã¿ã«ã¯3ååã®ã¿ã€ã ã¹ã¿ã³ãããããŸãã
ãªããã¯ã¹
Linuxã®ã»ãã¥ãªãã£ãæ¹åããããŒã«ã®1ã€ã¯ãç£æ»æžã¿ç£æ»ãµãã·ã¹ãã ã§ãã ãã®å©ããåããŠããã¹ãŠã®ã·ã¹ãã ã€ãã³ãã«é¢ãã詳现æ å ±ãååŸã§ããŸãã Splunkã§ã€ã³ããã¯ã¹ãäœæããã®ã¯ããã®ã·ã¹ãã ã«ãã£ãŠçæãããããŒã¿ã§ãã
ïŒLinux CentOSã®ã³ãŒãã衚瀺ãããŸãïŒ
1.ãã·ã³ã«ç£æ»ã·ã¹ãã ãäºåã«ã€ã³ã¹ããŒã«ãããŠãããã©ããã確èªããã€ã³ã¹ããŒã«ãããŠããªãå Žåã¯ã€ã³ã¹ããŒã«ããŸãã
sudo yum list audit audit-libs sudo yum install audit audit-libs
远跡ããæ°ããã«ãŒã«ãè¿œå ããŸãã
sudo auditctl -w /etc/ -p wa -k test_audit
æ©èœã䜿çšããŠãã®å¯çšæ§ã確èªã§ããŸãã
auditctl -l
auditdã«ãã£ãŠçæããããã°ã¯ããã¡ã€ã«ã«åé¡ãããŸãã
cd /var/log/audit/audit.log cat audit.log
2.次ã«ã Universal Forwarderãã€ã³ã¹ããŒã«ããŸãã ãªã³ã¯ã§ãã£ã¹ããªãã¥ãŒã·ã§ã³ãèŠã€ããããšãã§ããŸãã
.rpmãã¡ã€ã«ãããŠã³ããŒãããå¿ èŠããããŸããããŠã³ããŒãããåŸãwgetãªã³ã¯ãååŸã§ããŸãã
yum install wget cd /tmp/ wget -O splunkforwarder-7.0.3-fa31da744b51-linux-2.6-x86_64.rpm 'https://www.splunk.com/bin/splunk/DownloadActivityServlet?architecture=x86_64&platform=linux&version=7.0.3&product=universalforwarder&filename=splunkforwarder-7.0.3-fa31da744b51-linux-2.6-x86_64.rpm&wget=true' rpm -i splunkforwarder-7.0.3-fa31da744b51-linux-2.6-x86_64.rpm
3.次ã«ãsplunkã®æäœãæ åœããæ°ãããŠãŒã¶ãŒãäœæããŸãã
adduser splunk
4.äœæãããŠãŒã¶ãŒã«æš©éãä»äžããUniversalForwarderã«ä»£ãã£ãŠå®è¡ããŸãã
chown -R splunk:splunk /opt/splunkforwarder/ /opt/splunkforwarder/bin/splunk enable boot-start -user splunk
5. Windowsã®äžéšã®ããã«ããã©ã¯ãŒããŒãæ§æãã Deployment Serverãæå®ããŸããããã¯ãIPã¢ãã¬ã¹ãŸãã¯ååSplunk-indexer /
/opt/splunkforwarder/bin/splunk set deploy-poll <IP- Splunk Indexer> :8089 -auth admin:changeme /opt/splunkforwarder/bin/splunk edit user admin -password < > -auth admin:changeme /opt/splunkforwarder/bin/splunk restart
6.ãã©ã¯ãŒããŒã次ã®ããã«æ©èœãããã©ããã確èªã§ããŸãã
cd /opt/splunkforwarder/bin/ ./splunk status
7.次ã«ãSplunk-indexerã«ç§»åããç¹å¥ãªã¢ããªã³ãã€ã³ã¹ããŒã«ããŠãLinuxãããã°ã転éã§ããããã«ããŸãã é åžãªã³ã¯ãããŠã³ããŒãã§ããŸãã
8.ã€ã³ã¹ããŒã«åŸã次ã®ã¢ãã¬ã¹../splunk/etc/apps/Splunk_TA_nixã«ã¢ããªã±ãŒã·ã§ã³ã®ãããã©ã«ããŒãèŠã€ãããŸãã Splunk_TA_nixãã©ã«ããŒãã¢ããªããdeployment-appsã«ã³ããŒããŸã ã ãã®ã¢ããªã±ãŒã·ã§ã³ãå±éãµãŒããŒã§äœ¿çšå¯èœãšããŠè¡šç€ºãããããã
ãã£ã¬ã¯ããª... / deployment-apps / Splunk_TA_nixã§ãããŒã«ã«ãã©ã«ããŒãäœæããinput.confãã¡ã€ã«ã../Splunk_TA_nix/defaultãã©ã«ããŒããããã«ã³ããŒããŸãã
ãã¡ã€ã«... / deployment-apps / Splunk_TA_nix / local / input.confã§ãããã¹ããšãã£ã¿ãŒã䜿çšããŠãåéãããã©ã«ããŒã®ããŒã¿ã衚瀺ããå€æŽãè¡ããŸãã ç§ãã¡ã®å Žåãããã¯/ var / log / auditã§ãã
input.confã«ã¯ã»ã¯ã·ã§ã³[monitorïŒ/// var / log]ããããdisabled = 1ããdisabled = 0ã«å€æŽããå¿ èŠããããŸãïŒéèŠïŒå¿ èŠãªãã©ã«ããŒããã¯ã€ããªã¹ãã«ãªãå Žåã¯ããã¯ã€ããªã¹ãã«ããããšã確èªããŸãããè¿œå ããå¿ èŠããããŸãïŒ
9.次ã«ãDeploymentãµãŒããŒãæ°ããã¯ã©ã€ã¢ã³ãã§ããLinuxãã·ã³ãæ€åºãããã©ããã確èªããŸãã ïŒ èšå®-ãã©ã¯ãŒããŒç®¡ç-ã¯ã©ã€ã¢ã³ã ïŒã
ããã§ãªãå Žåã¯ããã·ã³ã®ååïŒãã¹ãåïŒã確èªããå¿ èŠããããŸãããã·ã³ã€ã³ãã¯ãµãŒã®ååãšäžèŽããå Žåã¯ãå€æŽããå¿ èŠããããŸããå€æŽããªããšãšã©ãŒãçºçããŸãã
cd /etc/hosts cat hosts hostname test.testdomain.com
10.次ã«ãLinuxã«é¢é£ããæ°ãããµãŒããŒã¯ã©ã¹ãäœæããŸãã
èšå®-ãã©ã¯ãŒããŒç®¡ç-ãµãŒããŒã¯ã©ã¹-æ°ãããµãŒããŒã¯ã©ã¹
11.ãã€ã³ãã¯ãµãŒã«éä¿¡ãããã³ãSplunk_TA_nixãã¢ããªã±ãŒã·ã§ã³ããã®ã¯ã©ã¹ã«è¿œå ããLinuxãã·ã³ãã¯ã©ã€ã¢ã³ããšããŠè¿œå ããŸãã
ãŠãããŒãµã«ãã©ã¯ãŒããŒïŒãŠãããŒãµã«ãã©ã¯ãŒããŒã䜿çšãããŠãŒã¶ãŒïŒãç£èŠããå¿ èŠã®ãããã©ã«ããŒã«ã¢ã¯ã»ã¹ã§ããªãå Žåããã¡ã€ã«ã¯ããŠã³ããŒããããªãããšã«æ³šæããŠãã ããã ãããã£ãŠããã®ç¹ãèæ ®ããŠã¢ã¯ã»ã¹ãèš±å¯ããå¿ èŠããããŸãã
12.æåŸã«ã å±é ãµãŒã㌠rãåèµ·åããå¿ èŠããããŸããããã¯ããã£ã¬ã¯ããª... / splunk / binããã³ãã³ãã©ã€ã³ã䜿çšããŠå®è¡ã§ããŸãã
./splunk reload deploy-server
äžèšã®æäœãå®è¡ããåŸãOSã€ã³ããã¯ã¹ã«ããŒããããLinuxãã°ãåãåããŸãã
ãããã«
ãããã£ãŠã詳现ãªåæãšåŠçã®ããã«ãWindowsããã³LinuxããSplunkã«ãã°ãããŒãããæ¹æ³ã瀺ããŸããã ãã®æ å ±ãã圹ã«ç«ãŠã°å¹žãã§ãã
ãã®ãããã¯ã«é¢ãããã¹ãŠã®è³ªåãšã³ã¡ã³ãã«åçãããŠããã ããŸãã ãŸãããã®åéããŸãã¯äžè¬çãªãã·ã³ããŒã¿åæã®åéã«ç¹ã«èå³ãããå Žåã¯ãç¹å®ã®ã¿ã¹ã¯ã®ããã«æ¢åã®ãœãªã¥ãŒã·ã§ã³ãå®æãããæºåãã§ããŠããŸãã ãããè¡ãã«ã¯ãã³ã¡ã³ãã«ããã«ã€ããŠæžãããåœç€Ÿã®ãŠã§ããµã€ãã®ãã©ãŒã ãããªã¯ãšã¹ããéä¿¡ããŠãã ããã