{"id":6540,"date":"2013-05-13T07:00:04","date_gmt":"2013-05-13T05:00:04","guid":{"rendered":"http:\/\/nolabnoparty.com\/?p=6540"},"modified":"2020-03-15T17:35:32","modified_gmt":"2020-03-15T16:35:32","slug":"setup-ossec-with-splunk","status":"publish","type":"post","link":"https:\/\/nolabnoparty.com\/en\/setup-ossec-with-splunk\/","title":{"rendered":"Setup OSSEC with Splunk"},"content":{"rendered":"<p><img decoding=\"async\" style=\"background-image: none; margin: 10px auto 5px; padding-left: 0px; padding-right: 0px; display: block; float: none; padding-top: 0px; border-width: 0px;\" title=\"ossecsplunk01\" src=\"https:\/\/nolabnoparty.com\/wp-content\/uploads\/2013\/05\/ossecsplunk01.jpg\" alt=\"ossecsplunk01\" width=\"602\" height=\"202\" border=\"0\" \/><\/p>\n<p>Installing OSSEC with Splunk allows a <strong>better overview<\/strong> of the thousand information collected by the system useful to <strong>create reports<\/strong> for the management.<\/p>\n<p>Splunk is the tools that can be integrated into OSSEC to <strong>transform the logs in a graphic format<\/strong> with some built-in reports that allows to better check monitored systems.<\/p>\n<p><!--more--><\/p>\n<h2><span style=\"color: #666666;\">Configure OSSEC<\/span><\/h2>\n<p>OSSEC installation procedure can be found in <a href=\"https:\/\/nolabnoparty.com\/en\/setup-ossec-with-splunk\/\" target=\"_blank\" rel=\"noopener noreferrer\">this post<\/a>.<\/p>\n<p>To enable syslog, edit OSSEC configuration file <em>ossec.conf<\/em> and add the following lines:<\/p>\n<pre class=\"lang:default decode:true brush: shell; gutter: true\">&lt;syslog_output&gt;\r\n   &lt;server&gt;192.168.10.109&lt;\/server&gt;        # OSSEC server IP\r\n   &lt;port&gt;10002&lt;\/port&gt;\r\n&lt;\/syslog_output&gt;<\/pre>\n<p><span style=\"color: #0000a0;\"># vi \/var\/ossec\/etc\/ossec.conf<\/span><\/p>\n<p style=\"text-align: center;\"><img decoding=\"async\" class=\"aligncenter\" style=\"border: 0px;\" title=\"ossecsplunk02\" src=\"https:\/\/nolabnoparty.com\/wp-content\/uploads\/2013\/05\/ossecsplunk02.jpg\" alt=\"ossecsplunk02\" width=\"600\" height=\"199\" \/><\/p>\n<p>Enable module <strong>syslog_output<\/strong> and restart OSSEC.<\/p>\n<p><span style=\"color: #0000a0;\"># \/var\/ossec\/bin\/ossec-control enable client-syslog<br \/>\n# \/var\/ossec\/bin\/ossec-control restart<\/span><\/p>\n<p><img decoding=\"async\" style=\"background-image: none; margin: 0px auto; padding-left: 0px; padding-right: 0px; display: block; float: none; padding-top: 0px; border-width: 0px;\" title=\"ossecsplunk03\" src=\"https:\/\/nolabnoparty.com\/wp-content\/uploads\/2013\/05\/ossecsplunk03.jpg\" alt=\"ossecsplunk03\" width=\"600\" height=\"290\" border=\"0\" \/><\/p>\n<p>&nbsp;<\/p>\n<h2><span style=\"color: #666666;\">Install Splunk<\/span><\/h2>\n<p>Download from <a href=\"http:\/\/www.splunk.com\/\" target=\"_blank\" rel=\"noopener\">website<\/a> latest Splunk release and install the application through rpm command.<\/p>\n<p><span style=\"color: #0000a0;\"># rpm -Uvh splunk-5.0.2-149561-linux-2.6-x86_64.rpm<\/span><\/p>\n<p><img decoding=\"async\" style=\"background-image: none; margin: 0px auto; padding-left: 0px; padding-right: 0px; display: block; float: none; padding-top: 0px; border-width: 0px;\" title=\"ossecsplunk04\" src=\"https:\/\/nolabnoparty.com\/wp-content\/uploads\/2013\/05\/ossecsplunk04.jpg\" alt=\"ossecsplunk04\" width=\"600\" height=\"371\" border=\"0\" \/><\/p>\n<p>Edit the configuration file<em> inputs.conf<\/em> and <strong>add this stanza<\/strong>:<\/p>\n<pre class=\"lang:default decode:true brush: shell; gutter: true \">[udp:\/\/192.168.10.109:10002]             # OSSEC server IP\r\ndisabled = false\r\nsourcetype = ossec<\/pre>\n<p><span style=\"color: #0000a0;\"># vi \/opt\/splunk\/etc\/system\/default\/inputs.conf<\/span><\/p>\n<p><img decoding=\"async\" style=\"background-image: none; margin: 0px auto; padding-left: 0px; padding-right: 0px; display: block; float: none; padding-top: 0px; border-width: 0px;\" title=\"ossecsplunk05\" src=\"https:\/\/nolabnoparty.com\/wp-content\/uploads\/2013\/05\/ossecsplunk05.jpg\" alt=\"ossecsplunk05\" width=\"600\" height=\"247\" border=\"0\" \/><\/p>\n<p>Restart Splunk. If this is the first time application starts, you need to <strong>accept the EULA<\/strong>.<\/p>\n<p><span style=\"color: #0000a0;\"># \/opt\/splunk\/bin\/splunk restart<\/span><\/p>\n<p><img decoding=\"async\" style=\"background-image: none; margin: 0px auto; padding-left: 0px; padding-right: 0px; display: block; float: none; padding-top: 0px; border-width: 0px;\" title=\"ossecsplunk06\" src=\"https:\/\/nolabnoparty.com\/wp-content\/uploads\/2013\/05\/ossecsplunk06.jpg\" alt=\"ossecsplunk06\" width=\"600\" height=\"340\" border=\"0\" \/><\/p>\n<p>Type on your browser <strong><span style=\"color: #ff0000;\">http:\/\/OSSEC_IP:8000<\/span><\/strong> and login to Splunk using default credential <strong>admin\/changeme<\/strong>. At first logon, you are prompted to change the password. If the firewall is turned on, add exception\u00a0<strong>TCP:8000<\/strong>.<\/p>\n<p><img decoding=\"async\" style=\"background-image: none; margin: 0px auto; padding-left: 0px; padding-right: 0px; display: block; float: none; padding-top: 0px; border-width: 0px;\" title=\"ossecsplunk07\" src=\"https:\/\/nolabnoparty.com\/wp-content\/uploads\/2013\/05\/ossecsplunk07.jpg\" alt=\"ossecsplunk07\" width=\"600\" height=\"383\" border=\"0\" \/><\/p>\n<p>Splunk main screen.<\/p>\n<p><img decoding=\"async\" style=\"background-image: none; margin: 0px auto; padding-left: 0px; padding-right: 0px; display: block; float: none; padding-top: 0px; border-width: 0px;\" title=\"ossecsplunk08\" src=\"https:\/\/nolabnoparty.com\/wp-content\/uploads\/2013\/05\/ossecsplunk08.jpg\" alt=\"ossecsplunk08\" width=\"600\" height=\"274\" border=\"0\" \/><\/p>\n<p>&nbsp;<\/p>\n<h2><span style=\"color: #666666;\">Install Splunk for OSSEC<\/span><\/h2>\n<p>Download <a href=\"http:\/\/www.splunk.com\" target=\"_blank\" rel=\"noopener noreferrer\">Splunk for OSSEC application<\/a> and from Splunk main window click on menu <strong>App &gt; Manage apps<\/strong>.<\/p>\n<p><img decoding=\"async\" style=\"background-image: none; margin: 0px auto; padding-left: 0px; padding-right: 0px; display: block; float: none; padding-top: 0px; border-width: 0px;\" title=\"ossecsplunk09\" src=\"https:\/\/nolabnoparty.com\/wp-content\/uploads\/2013\/05\/ossecsplunk09.jpg\" alt=\"ossecsplunk09\" width=\"321\" height=\"200\" border=\"0\" \/><\/p>\n<p>Click on <strong>Install app from file<\/strong> button.<\/p>\n<p><img decoding=\"async\" style=\"background-image: none; margin: 0px auto; padding-left: 0px; padding-right: 0px; display: block; float: none; padding-top: 0px; border-width: 0px;\" title=\"ossecsplunk10\" src=\"https:\/\/nolabnoparty.com\/wp-content\/uploads\/2013\/05\/ossecsplunk10.jpg\" alt=\"ossecsplunk10\" width=\"510\" height=\"253\" border=\"0\" \/><\/p>\n<p>Click on <strong>Choose File<\/strong> button and select the downloaded file <strong>ossec-1.1.89.tgz<\/strong>. Click <strong>Upload<\/strong> to load the application into Splunk.<\/p>\n<p><img decoding=\"async\" style=\"background-image: none; margin: 0px auto; padding-left: 0px; padding-right: 0px; display: block; float: none; padding-top: 0px; border-width: 0px;\" title=\"ossecsplunk11\" src=\"https:\/\/nolabnoparty.com\/wp-content\/uploads\/2013\/05\/ossecsplunk11.jpg\" alt=\"ossecsplunk11\" width=\"600\" height=\"225\" border=\"0\" \/><\/p>\n<p>When the application has been uploaded, system needs to be restarted. Click <strong>Restart Splunk<\/strong> to continue.<\/p>\n<p><img decoding=\"async\" style=\"background-image: none; margin: 0px auto; padding-left: 0px; padding-right: 0px; display: block; float: none; padding-top: 0px; border-width: 0px;\" title=\"ossecsplunk12\" src=\"https:\/\/nolabnoparty.com\/wp-content\/uploads\/2013\/05\/ossecsplunk12.jpg\" alt=\"ossecsplunk12\" width=\"600\" height=\"139\" border=\"0\" \/><\/p>\n<p>System is then <strong>restarted<\/strong>.<\/p>\n<p><img decoding=\"async\" style=\"background-image: none; margin: 0px auto; padding-left: 0px; padding-right: 0px; display: block; float: none; padding-top: 0px; border-width: 0px;\" title=\"ossecsplunk13\" src=\"https:\/\/nolabnoparty.com\/wp-content\/uploads\/2013\/05\/ossecsplunk13.jpg\" alt=\"ossecsplunk13\" width=\"600\" height=\"266\" border=\"0\" \/><\/p>\n<p>Once logged in again into system, you get the <strong>notification of installed app<\/strong>.<\/p>\n<p><img decoding=\"async\" style=\"background-image: none; margin: 0px auto; padding-left: 0px; padding-right: 0px; display: block; float: none; padding-top: 0px; border-width: 0px;\" title=\"ossecsplunk14\" src=\"https:\/\/nolabnoparty.com\/wp-content\/uploads\/2013\/05\/ossecsplunk14.jpg\" alt=\"ossecsplunk14\" width=\"392\" height=\"230\" border=\"0\" \/><\/p>\n<p>Clicking <strong>Apps<\/strong> on main screen, a list with all installed apps appears. Identify the line <strong>Splunk for OSSEC <\/strong>and click <strong>Launch app<\/strong> under <strong>Actions<\/strong>.<\/p>\n<p><img decoding=\"async\" style=\"background-image: none; margin: 0px auto; padding-left: 0px; padding-right: 0px; display: block; float: none; padding-top: 0px; border-width: 0px;\" title=\"ossecsplunk15\" src=\"https:\/\/nolabnoparty.com\/wp-content\/uploads\/2013\/05\/ossecsplunk15.jpg\" alt=\"ossecsplunk15\" width=\"600\" height=\"225\" border=\"0\" \/><\/p>\n<p>Splunk for OSSEC main screen opens.<\/p>\n<p><img decoding=\"async\" style=\"background-image: none; margin: 0px auto; padding-left: 0px; padding-right: 0px; display: block; float: none; padding-top: 0px; border-width: 0px;\" title=\"ossecsplunk16\" src=\"https:\/\/nolabnoparty.com\/wp-content\/uploads\/2013\/05\/ossecsplunk16.jpg\" alt=\"ossecsplunk16\" width=\"600\" height=\"248\" border=\"0\" \/><\/p>\n<p>Click <strong>Dashboards &amp; Views<\/strong> menu and select <strong>OSSEC Dashboard<\/strong> option.<\/p>\n<p><img decoding=\"async\" style=\"background-image: none; margin: 0px auto; padding-left: 0px; padding-right: 0px; display: block; float: none; padding-top: 0px; border-width: 0px;\" title=\"ossecsplunk17\" src=\"https:\/\/nolabnoparty.com\/wp-content\/uploads\/2013\/05\/ossecsplunk17.jpg\" alt=\"ossecsplunk17\" width=\"600\" height=\"368\" border=\"0\" \/><\/p>\n<p>Collected data are displayed in <strong>graphic format<\/strong> easy to be read at first sight.<\/p>\n<p><img decoding=\"async\" style=\"background-image: none; margin: 0px auto; padding-left: 0px; padding-right: 0px; display: block; float: none; padding-top: 0px; border-width: 0px;\" title=\"ossecsplunk18\" src=\"https:\/\/nolabnoparty.com\/wp-content\/uploads\/2013\/05\/ossecsplunk18.jpg\" alt=\"ossecsplunk18\" width=\"600\" height=\"525\" border=\"0\" \/><\/p>\n<p>Splunk is a powerful tool to display collected data and reports can be easily created selecting available templates under <strong>Searches &amp; Reports<\/strong> menu.<\/p>\n<p>&nbsp;<\/p>\n<h2>Remove data from indexes<\/h2>\n<p>To delete indexed data permanently from your disk, from the console run the the following commands:<\/p>\n<p><span style=\"color: #000080;\"># service splunk stop<\/span><br \/>\n<span style=\"color: #000080;\"># \/opt\/splunk\/bin<\/span><br \/>\n<span style=\"color: #000080;\"># .\/splunk clean eventdata<\/span><br \/>\n<span style=\"color: #000080;\"># service splunk start\u00a0<\/span><\/p>\n<p>This command <strong>completely deletes<\/strong> the data in all indexes releasing unused disk space.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/nolabnoparty.com\/wp-content\/uploads\/images\/firma.jpg\" alt=\"\" title=\"\"><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Installing OSSEC with Splunk allows a better overview of the thousand information collected by the system useful to create reports for the management. Splunk is the tools that can be integrated into OSSEC to transform the logs in a graphic format with some built-in reports that allows to better check monitored systems.<\/p>\n","protected":false},"author":3,"featured_media":6522,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"rop_custom_images_group":[],"rop_custom_messages_group":[],"rop_publish_now":"initial","rop_publish_now_accounts":{"facebook_2879994398731222_17841400390232720":"","mastodon_115463926174894442_115463926174894442":"","linkedin_93tdZWzMZc_93tdZWzMZc":"","bluesky_did:plc:tkabz5kl2rukzdwtuongv3kz_did:plc:tkabz5kl2rukzdwtuongv3kz":""},"rop_publish_now_history":[],"rop_publish_now_status":"pending","footnotes":""},"categories":[899,898],"tags":[639,634,589,594,645],"class_list":["post-6540","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-data-analysis-en","category-monitoring-en","tag-data-analysis","tag-monitoring-en","tag-ossec-en","tag-splunk-en","tag-syslog-en","has_thumb"],"_links":{"self":[{"href":"https:\/\/nolabnoparty.com\/en\/wp-json\/wp\/v2\/posts\/6540","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/nolabnoparty.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/nolabnoparty.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/nolabnoparty.com\/en\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/nolabnoparty.com\/en\/wp-json\/wp\/v2\/comments?post=6540"}],"version-history":[{"count":0,"href":"https:\/\/nolabnoparty.com\/en\/wp-json\/wp\/v2\/posts\/6540\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/nolabnoparty.com\/en\/wp-json\/wp\/v2\/media\/6522"}],"wp:attachment":[{"href":"https:\/\/nolabnoparty.com\/en\/wp-json\/wp\/v2\/media?parent=6540"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/nolabnoparty.com\/en\/wp-json\/wp\/v2\/categories?post=6540"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/nolabnoparty.com\/en\/wp-json\/wp\/v2\/tags?post=6540"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}