How to Splunk Connect for syslog in under 5 minutes Centos 8 (SC4S)

preview_player
Показать описание
#Splunk Connect for syslog in under 5 minutes Centos 8 (#SC4S)

0:00 Introduction
0:20 2 minutes of SC4S overview
1:14 Splunk index configuration
2:56 I show you in 4 minutes how to download and run the script
6:55 I show you in 3 minutes the configuration in the Splunk web ui

Command to get the script

SC4S links

Other video on HTTP event collector (HEC) using postman
Рекомендации по теме
Комментарии
Автор

Do you by chance have an updated one for centos9? Or is it pretty much unchanged?

garrettBiebinger
Автор

Is it possible to connect a syslog server (e.g KIWI) to splunk using splunk connect ?

salwamela
Автор

Getting below error, Please suggest

curl: (3) Bad URL, colon is first character
SC4S_ENV_CHECK_HEC: Invalid Splunk HEC URL, invalid token, or other HEC connectivity issue index=main. sourcetype=sc4s:fallback
Startup will continue to prevent data loss if this is a transient failure.

Ujjwalkushwaha
Автор

I keep getting

Starting SC4S - This might take a while first time as the container is downloaded
Error: no container with name or ID "sc4sbuilder" found: no such container
Error: no container with name or ID "SC4S" found: no such container

any insight into troubleshooting resolving?
I tried tweaking SSL settings and the URL for pulling it from the github repo however haven't had any luck.

kiphackman