Installing Splunk Enterprise

1.5 hours
  • 5 Learning Objectives

About this Hands-on Lab

So you want to use Splunk? Well, let’s start with the basics. In this hands-on lab, you are given the opportunity to install Splunk Enterprise on a CentOS 7 cloud server, manually create the administrator credentials, configure Splunk to start on boot, and explore the Splunk Enterprise web console.

Learning Objectives

Successfully complete this lab by achieving the following learning objectives:

As the “root” user, install Splunk Enterprise using the RPM in the “root” user’s home directory

Become the root user:

sudo su -

Install Splunk:

cd ~
rpm -i splunk-7.2.4.2.rpm
Manually create the administrator credentials without starting Splunk

Become the root user:

sudo su -

The file /opt/splunk/etc/system/local/user-seed.conf should contain the following:

[user_info]
USERNAME = admin
PASSWORD = $p|unkEnt3rpr!$e
Configure Splunk to start on boot and accept the Splunk Enterprise license

Become the root user:

sudo su -

Enable boot-start and accept the Splunk Enterprise license:

/opt/splunk/bin/splunk enable boot-start --accept-license
Start Splunk

Become the root user:

sudo su -

Start Splunk:

/opt/splunk/bin/splunk start
Log in to and explore the Splunk Enterprise web console using your public IP address and the admin credentials created earlier

In your web browser, go to http://your_public_ip_address:8000.

Log in as the user admin and password $p|unkEnt3rpr!$e.

Explore the Splunk Enterprise web console.

Additional Resources

You are a system administrator working on a log centralization project. You have been asked to perform a proof-of-concept (POC) of a Splunk Enterprise logging solution. To facilitate this POC, you must first install a single-node Splunk node on a CentOS cloud server. The Splunk service should be configured to start on boot, and the administrator credentials for Splunk should be as follows:

  • User: admin
  • Password: $p|unkEnt3rpr!$e

Finally, start the Splunk service and explore the web console using your public IP address and the default console port 8000 to get a better understanding of the Splunk console interface and its capabilities.

What are Hands-on Labs

Hands-on Labs are real environments created by industry experts to help you learn. These environments help you gain knowledge and experience, practice without compromising your system, test without risk, destroy without fear, and let you learn from your mistakes. Hands-on Labs: practice your skills before delivering in the real world.

Sign In
Welcome Back!

Psst…this one if you’ve been moved to ACG!

Get Started
Who’s going to be learning?