ããŸããŸãªããŒã¿ã
Splunkã«ããŒãããæ¹æ³ã«ã€ããŠãã質åãã
ãŸã ã æãäžè¬çãªé¢å¿ã®ãããœãŒã¹ã®1ã€ã¯ããªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã®åé¡ã远跡ããã³ç®¡çã§ãã
Windowsããã³
Linuxã®ãã°ã§ããã Splunkã«ããŒã¿ãã¢ããããŒãããããšã«ãããæ°åãŸãã¯æ°çŸã®ç°ãªããœãŒã¹ãããå Žåã§ãã1ãæã§ãã¹ãŠã®ã·ã¹ãã ã®åäœãåæã§ããŸãã

ãã®èšäºã§ã¯ãWindowsããã³LinuxããSplunkã«ããŒã¿ãããŠã³ããŒãããŠãããã«åŠçããã³åæããæ¹æ³ãé ã远ã£ãŠèª¬æããŸãã
åºæ¬çãªã€ã³ãã©ã¹ãã©ã¯ãã£ãæ§æãã
ããŒã¿ã®åéãéå§ããã«ã¯ã次ã®ã·ã¹ãã èŠçŽ ãå¿
èŠã§ãã
- Splunk-ã€ã³ãã¯ãµãŒ
- WindowsãµãŒããŒ
- LinuxãµãŒããŒ

Splunkã«ãã°ãã¢ããããŒãããã«ã¯ãæåã«ã€ã³ãã¯ãµãŒãèšå®ããå¿
èŠããããŸããããã«ã¯ä»¥äžãå¿
èŠã§ãã
â¢ããŒã¿ãåä¿¡ããããã«Splunk-indexerãã€ã³ã¹ããŒã«ããŠèšå®ããŸãããŸãããã·ã³ã«Splunkãå¿
èŠã«ãªããŸããããã¯ã€ã³ãã¯ãµãŒã§ãã Splunkãã€ã³ã¹ããŒã«ãããŠããªãå Žåã¯ãSplunkãã€ã³ã¹ããŒã«ããæ¹æ³ãšã·ã¹ãã ã®è©³çްã«ã€ããŠã¯
ãã¡ããã芧ãã ãã ã
ã€ã³ã¹ããŒã«åŸãããŒã¿ãåä¿¡ããããã«ã€ã³ãã¯ãµãŒãæ§æããå¿
èŠããããŸãã
èšå®-転éãšåä¿¡ ãæ¬¡ã«
[ ããŒã¿ã®
åä¿¡]ã»ã¯ã·ã§ã³ã§æ°ããæ§æã远å ããŸãïŒ
åä¿¡ãæ§æããŸãã


â¢ã€ã³ãã¯ãµãŒã«ããŒã¿ãéä¿¡ãããã¹ãŠã®ãœãŒã¹ã§è»¢éãæ§æãããã€ã³ãã¯ãµãŒã«éä¿¡ãã¢ããªã±ãŒã·ã§ã³ãäœæããŸãããã®ã¢ããªã±ãŒã·ã§ã³ã¯ããããã®ãœãŒã¹ã倿°ããå Žåãã倿Žãå ããããã«ã¢ã¯ã»ã¹ããããšãå°é£ãªå Žåã«ãããŒã¿ãœãŒã¹ã®ç®¡çãç°¡çŽ åããããã«å¿
èŠã§ãã ãŸãããã®ã¢ããªã±ãŒã·ã§ã³ã䜿çšãããšãå€ãã®ãã¹ãã§æœåšçã«èª€ã£ãæ§æå€æŽãè¡ããã1ã€ã®å Žæã§ã®ã¿å€æŽãå¶éã§ããŸãã
ã¢ããªã±ãŒã·ã§ã³ãäœæããŸãïŒ
ã¢ããª-ã¢ããªã®ç®¡ç-æ°èŠè¿œå 
â¢ãã©ãŒã outputs.confæ§æãã¡ã€ã«ã¢ããªã±ãŒã·ã§ã³ãäœæããããoutputs.confæ§æãã¡ã€ã«ãäœæããå¿
èŠããããŸãïŒãã®ãã¡ã€ã«ã®è©³çްã«ã€ããŠ
ã¯ãSplunkã®å
¬åŒWebãµã€ããã芧ãã ãã ïŒ
ããã¹ããšãã£ã¿ã§ã次ã®ããã¹ããå
¥åããŸã
ãindexer_hostname_or_ip_addressããåã®æé ã§èšå®ããã€ã³ãã¯ãµãŒã®ãã¹ãåãŸãã¯IPã¢ãã¬ã¹ãšåä¿¡ããŒãã«çœ®ãæããŸãã
[tcpout] defaultGroup = default-autolb-group [tcpout:default-autolb-group] server = <indexer_hostname_or_ip_address>:9997 [tcpout-server://<indexer_hostname_or_ip_address>:9997]
outputs.confãšããŠä¿åãããã©ã«ããŒ
\ etc \ apps \ sendtoindexer \ localã«è¿œå ããŸãïŒããŒã«ã«ãã©ã«ããŒãäœæããå¿
èŠããããŸãïŒã
â¢ã€ã³ãã¯ãµãŒãžã®éä¿¡ã¢ããªã±ãŒã·ã§ã³ããã³ãã®ä»ã®ã¢ããªã±ãŒã·ã§ã³ã管çããããã«Deployment Serverãæ§æããŸããDeployment Serverã¯ãä»ã®ãã¹ãäžã®ãã¹ãŠã®é¢é£ããSplunkã€ã³ã¹ã¿ã³ã¹ã«ã¢ããªã±ãŒã·ã§ã³ãšæ§æãé
åžããããã«å¿
èŠã§ãã Deployment Serverãã¢ã¯ãã£ãã«ããã«ã¯ãå°ãªããšã1ã€ã®ã¢ããªã±ãŒã·ã§ã³ãïŒ
SPLUNK_HOMEïŒ
\ etc \ deployment-appsãã©ã«ããŒã«é
眮ããå¿
èŠããããŸãã ãã®äŸã§ã¯ã Send to indexerã¢ããªã±ãŒã·ã§ã³ãããã«ç§»åããŸããã ïŒä»ã®ã¢ããªã±ãŒã·ã§ã³ã§æ¬¡ã«è¡ãããã«ãã³ããŒã§ã¯ãªãç§»åãããŸãããïŒ
ãã®æ®µéã§ãã€ã³ãã¯ãµãŒã®äºåèšå®ãå®äºããWindowsããã³Linuxãã·ã³ã«ãšãŒãžã§ã³ããã€ã³ã¹ããŒã«ããŸãã
WINDOWS
ãã°ãããŠã³ããŒãããããã®æ±çšããŒã«ã¯ãç¹å¥ãªãšãŒãžã§ã³ãã§ãã
Splunk Universal Forwarderã§ãã Universal Forwarderã¯ãæ©èœã倧å¹
ã«å¶éãããSplunk Enterpriseã®ããŒãžã§ã³ã§ããããã®å¯äžã®ã¿ã¹ã¯ã¯ãã¹ãããããŒã¿ãåéããŠéä¿¡ããããšã§ãã
ãã¡ãããããŠã³ããŒãã§ããŸãã

äžã®åçã¯ãUniversal ForwarderãWindowsãšLinuxãSolarisãšä»ã®ãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã®äž¡æ¹ã«ã€ã³ã¹ããŒã«ã§ããããšã瀺ããŠããŸãã
1.
Universal Forwarderãã€ã³ã¹ããŒã«ããŸã
Deployment ServerãšããŠããSend to indexerãã¢ããªã±ãŒã·ã§ã³ãäœæããSplunkã€ã³ãã¯ãµãŒã®IPã¢ãã¬ã¹ãŸãã¯ååãæå®ããŸãã ããã©ã«ãã®ããŒãã¯
8089ã§ãã ãã€ã³ãã¯ãµãŒã«éä¿¡ãããããã®æ©èœãå®è¡ãããããåä¿¡ã€ã³ãã¯ãµãŒã»ã¯ã·ã§ã³ã¯ç©ºçœã®ãŸãŸã«ãªããŸãã
2.次ã®ã¹ãããã¯ãSplunkã«æ»ãããã€ã³ãã¯ãµãŒã«éä¿¡ãã¢ããªã±ãŒã·ã§ã³ã®ãµãŒããŒã¯ã©ã¹ãå®çŸ©ããããšã§ãã
ãµãŒããŒã¯ã©ã¹ã¯ãã©ã®ã¿ãŒã²ããã¯ã©ã€ã¢ã³ããã·ã³éã§ã©ã®ã¢ããªã±ãŒã·ã§ã³ãé
åžãããã瀺ãã«ãŒã«ã«äŒŒãŠããŸãã ãµãŒããŒã®ããŸããŸãªã¯ã©ã¹ã®åœ¢æåºæºã¯ããã·ã³ã®ã¿ã€ããOSãå°ççé åããŸãã¯ã¢ããªã±ãŒã·ã§ã³ã®ã¿ã€ãã§ããå Žåããããã¯ã©ã¹ã¯éè€ããå ŽåããããŸãã ïŒè©³çްã¯
å
¬åŒãŠã§ããµã€ãã§èŠã€ããããšãã§ããŸãïŒ
èšå®-ãã©ã¯ãŒããŒç®¡ç-ç·šéã¢ã¯ã·ã§ã³-æ°ããã¯ã©ã¹ã远å ããŸãã
3.ä¿ååŸãé
åžããã¢ããªã±ãŒã·ã§ã³ã远å ããããæ±ããããŸããããã¯ãããããã¯ã©ã€ã¢ã³ããšåŒã°ããã·ã¹ãã ãã¿ãŒã²ããã«ããŠãé
åžå
ãšãªããã®ã§ãã

ã¢ããªã±ãŒã·ã§ã³ã»ã¯ã·ã§ã³ã«ã
ã€ã³ãã¯ãµãŒã«éä¿¡ ã
ã远å ããŸãã

4.次ã«ãã¯ã©ã€ã¢ã³ãã远å ããŸãã ã¯ã©ã€ã¢ã³ãã¯ãUniversal Forwarderãã€ã³ã¹ããŒã«ããWindowsãã·ã³ã«ãªããŸãã Universal Forwarderãæ£ããã€ã³ã¹ããŒã«ãããŠããã°ã
Deployment Serverã«æ¥ç¶ãããŠããã¯ã©ã€ã¢ã³ãã®ãªã¹ãã«ãã·ã³ã衚瀺ãã
ãŸã ã
IncludeïŒwhitelistïŒã«å
¥ã
ãŸã ã

5.
_internalã€ã³ããã¯ã¹ã®å
容ãèŠããšããã¹ãŠãæ£ããæ©èœãããã©ããã確èªã§ããŸãã ãã€ã³ãã¯ãµãŒã«éä¿¡ãããµãŒããŒã¯ã©ã¹ã«è¿œå ãããšãUniversal Forwarderã¯ããã§å
éšãã°ã®éä¿¡ãéå§ããŸãã ãŸãããã®ã€ã³ããã¯ã¹ã§ã¯ããšãŒãžã§ã³ããé©åã«æ©èœããŠãããã©ãããããã«ç£èŠã§ããŸãã
6.次ã«ã
SplunkBase Webãµã€ãããç¹å¥ãªã¢ããªã³ãããŠã³ããŒãããŸããããã«ãããWindowsã®æäœã«é¢ããããŒã¿ãåéã§ããŸãã
7. Splunk-Indexerã«ã¢ããªã±ãŒã·ã§ã³ãã€ã³ã¹ããŒã«ããŸãïŒ
ã¢ããª-ã¢ããªã®ç®¡ç-ãã¡ã€ã«ããã¢ããªãã€ã³ã¹ããŒã« ïŒ
ããã©ã«ãã§ã¯ããã£ã¬ã¯ããª
... \ Splunk \ etc \ apps \ Splunk_TA_windowsã«ã€ã³ã¹ããŒã«ãããŸããããã®ã¢ããªã±ãŒã·ã§ã³ãå±éãµãŒããŒã«ã¢ã¯ã»ã¹ã§ããããã«deployment-appsãã©ã«ããŒã«ã³ããŒããŠãåãæ¹æ³ã§ä»ã®ãã·ã³ã«éä¿¡ã§ããããã«ããå¿
èŠããããŸãããã³ãã€ã³ãã¯ãµãŒã«éä¿¡ãã ïŒ
éèŠ ïŒããŒã¿ã«å¿
èŠãªã€ã³ããã¯ã¹ãã€ã³ãã¯ãµãŒäžã«åœ¢æãããããã«ãappsãã©ã«ããŒã«ãä¿æããå¿
èŠããããŸãïŒã
8.次ã«ãã¢ããªã±ãŒã·ã§ã³ãäºåèšå®ããå¿
èŠããããŸãã
ãã£ã¬ã¯ããªã«ç§»åã
ãŸã... \ Splunk \ etc \ deployment-apps \ Splunk_TA_windowsãã®äžã«ãµããã£ã¬ã¯ããªãããŒã«ã«ããäœæããŸãïŒ
éèŠ ïŒããŒã«ã«ãã£ã¬ã¯ããªå
ã®æ§æãã¡ã€ã«ãåžžã«å€æŽããŸãïŒã
inputs.confãã¡ã€ã«ãã³ããŒããŸãã
.. \ Splunk \ etc \ deployment-apps \ Splunk_TA_windows \ default \ inputs.confã¯
ããŒã«ã«ãã£ã¬ã¯ããªã«ãããŸãã
å¿
èŠãªããŒã¿ã®ã€ã³ããã¯ã¹äœæããªã³ã«ããŸãã ãããè¡ãããã«ã
ããŒã«ã«ãã£ã¬ã¯ããªããããã¹ããšãã£ã¿ãä»ããŠ
inputs.confãã¡ã€ã«ã«ããã€ãã®å€æŽã
å ããŸãã ãã¡ã€ã«ã®å¿
èŠãªãããã¯ã§ãdisabled = 1ã®å€ãdisabled = 0ã«çœ®ãæããŸãã ã¢ããªã±ãŒã·ã§ã³ãã»ãã¥ãªãã£ãã·ã¹ãã ã®ã·ã¹ãã ãã°ã远å ããŸãããã

9.次ã«ãSplunk-indexerã§ãå
ã»ã©äœæãããµãŒããŒã¯ã©ã¹ãã¢ããªã±ãŒã·ã§ã³ã«è¿œå ããŸãã ïŒ
èšå®-ãã©ã¯ãŒããŒç®¡ç-ã¢ããª-Splunk_TA_Windows-ã+ã-Windows Forwarder ïŒ

10.
å±éãµãŒããŒãåèµ·åã
ãŸã ãããã¯ããã£ã¬ã¯ããª
... / splunk / binããã³ãã³ãã©ã€ã³ã䜿çšããŠå®è¡ã§ããŸãã
./splunk reload deploy-server
ããŒã¿ãã¢ããããŒããããŠãããã©ããã確èªããŸãã ïŒ
èšå®-ã€ã³ããã¯ã¹ ïŒwineventlogã€ã³ããã¯ã¹ã«å«ãŸããŠããå¿
èŠããããŸãã å³ãããããããã«ãçŸæç¹ã§æåŸã«ããŠã³ããŒããããããŒã¿ã«ã¯3ååã®ã¿ã€ã ã¹ã¿ã³ãããããŸãã

ãªããã¯ã¹
Linuxã®ã»ãã¥ãªãã£ãæ¹åããããŒã«ã®1ã€ã¯ãç£æ»æžã¿ç£æ»
ãµãã·ã¹ãã ã§ãã ãã®å©ããåããŠããã¹ãŠã®ã·ã¹ãã ã€ãã³ãã«é¢ãã詳现æ
å ±ãååŸã§ããŸãã Splunkã§ã€ã³ããã¯ã¹ãäœæããã®ã¯ããã®ã·ã¹ãã ã«ãã£ãŠçæãããããŒã¿ã§ãã
ïŒLinux CentOSã®ã³ãŒãã衚瀺ãããŸãïŒ
1.ãã·ã³ã«ç£æ»ã·ã¹ãã ãäºåã«ã€ã³ã¹ããŒã«ãããŠãããã©ããã確èªããã€ã³ã¹ããŒã«ãããŠããªãå Žåã¯ã€ã³ã¹ããŒã«ããŸãã
sudo yum list audit audit-libs sudo yum install audit audit-libs
远跡ããæ°ããã«ãŒã«ã远å ããŸãã
sudo auditctl -w /etc/ -p wa -k test_audit
æ©èœã䜿çšããŠãã®å¯çšæ§ã確èªã§ããŸãã
auditctl -l
auditdã«ãã£ãŠçæããããã°ã¯ããã¡ã€ã«ã«åé¡ãããŸãã
cd /var/log/audit/audit.log cat audit.log
2.次ã«ã
Universal Forwarderãã€ã³ã¹ããŒã«ããŸãã
ãªã³ã¯ã§ãã£ã¹ããªãã¥ãŒã·ã§ã³ãèŠã€ããããšãã§ããŸã
ã.rpmãã¡ã€ã«ãããŠã³ããŒãããå¿
èŠããããŸããããŠã³ããŒãããåŸãwgetãªã³ã¯ãååŸã§ããŸãã
yum install wget cd /tmp/ wget -O splunkforwarder-7.0.3-fa31da744b51-linux-2.6-x86_64.rpm 'https://www.splunk.com/bin/splunk/DownloadActivityServlet?architecture=x86_64&platform=linux&version=7.0.3&product=universalforwarder&filename=splunkforwarder-7.0.3-fa31da744b51-linux-2.6-x86_64.rpm&wget=true' rpm -i splunkforwarder-7.0.3-fa31da744b51-linux-2.6-x86_64.rpm
3.次ã«ãsplunkã®æäœãæ
åœããæ°ãããŠãŒã¶ãŒãäœæããŸãã
adduser splunk
4.äœæãããŠãŒã¶ãŒã«æš©éãä»äžããUniversalForwarderã«ä»£ãã£ãŠå®è¡ããŸãã
chown -R splunk:splunk /opt/splunkforwarder/ /opt/splunkforwarder/bin/splunk enable boot-start -user splunk
5. Windowsã®äžéšã®ããã«ããã©ã¯ãŒããŒãæ§æãã
Deployment Serverãæå®ããŸããããã¯ãIPã¢ãã¬ã¹ãŸãã¯ååSplunk-indexer /
/opt/splunkforwarder/bin/splunk set deploy-poll <IP- Splunk Indexer> :8089 -auth admin:changeme /opt/splunkforwarder/bin/splunk edit user admin -password < > -auth admin:changeme /opt/splunkforwarder/bin/splunk restart
6.ãã©ã¯ãŒããŒã次ã®ããã«æ©èœãããã©ããã確èªã§ããŸãã
cd /opt/splunkforwarder/bin/ ./splunk status
7.次ã«ãSplunk-indexerã«ç§»åããç¹å¥ãªã¢ããªã³ãã€ã³ã¹ããŒã«ããŠãLinuxãããã°ã転éã§ããããã«ããŸãã é
åž
ãªã³ã¯ãããŠã³ããŒãã§ããŸãã
8.ã€ã³ã¹ããŒã«åŸã次ã®ã¢ãã¬ã¹
../splunk/etc/apps/Splunk_TA_nixã«ã¢ããªã±ãŒã·ã§ã³ã®ãããã©ã«ããŒãèŠã€ãããŸãã
Splunk_TA_nixãã©ã«ããŒãã¢ããªãã
deployment-appsã«ã³ããŒã
ãŸã ã ãã®ã¢ããªã±ãŒã·ã§ã³ãå±éãµãŒããŒã§äœ¿çšå¯èœãšããŠè¡šç€ºãããããã
ãã£ã¬ã¯ããª... / deployment-apps / Splunk_TA_nixã§ãããŒã«ã«ãã©ã«ããŒãäœæããinput.confãã¡ã€ã«ã../Splunk_TA_nix/defaultãã©ã«ããŒããããã«ã³ããŒããŸãã
ãã¡ã€ã«... / deployment-apps / Splunk_TA_nix / local / input.confã§ãããã¹ããšãã£ã¿ãŒã䜿çšããŠãåéãããã©ã«ããŒã®ããŒã¿ã衚瀺ãã倿Žãè¡ããŸãã ç§ãã¡ã®å Žåãããã¯/ var / log / auditã§ãã
input.confã«ã¯ã»ã¯ã·ã§ã³[monitorïŒ/// var / log]ããããdisabled = 1ããdisabled = 0ã«å€æŽããå¿
èŠããããŸãïŒéèŠïŒå¿
èŠãªãã©ã«ããŒããã¯ã€ããªã¹ãã«ãªãå Žåã¯ããã¯ã€ããªã¹ãã«ããããšã確èªããŸããã远å ããå¿
èŠããããŸãïŒ
9.次ã«ãDeploymentãµãŒããŒãæ°ããã¯ã©ã€ã¢ã³ãã§ããLinuxãã·ã³ãæ€åºãããã©ããã確èªããŸãã ïŒ
èšå®-ãã©ã¯ãŒããŒç®¡ç-ã¯ã©ã€ã¢ã³ã ïŒã
ããã§ãªãå Žåã¯ããã·ã³ã®ååïŒãã¹ãåïŒã確èªããå¿
èŠããããŸãããã·ã³ã€ã³ãã¯ãµãŒã®ååãšäžèŽããå Žåã¯ã倿Žããå¿
èŠããããŸãã倿Žããªããšãšã©ãŒãçºçããŸãã
cd /etc/hosts cat hosts hostname test.testdomain.com
10.次ã«ãLinuxã«é¢é£ããæ°ãããµãŒããŒã¯ã©ã¹ãäœæããŸãã
èšå®-ãã©ã¯ãŒããŒç®¡ç-ãµãŒããŒã¯ã©ã¹-æ°ãããµãŒããŒã¯ã©ã¹
11.ãã€ã³ãã¯ãµãŒã«éä¿¡ãããã³ãSplunk_TA_nixãã¢ããªã±ãŒã·ã§ã³ããã®ã¯ã©ã¹ã«è¿œå ããLinuxãã·ã³ãã¯ã©ã€ã¢ã³ããšããŠè¿œå ããŸãã

ãŠãããŒãµã«ãã©ã¯ãŒããŒïŒãŠãããŒãµã«ãã©ã¯ãŒããŒã䜿çšãããŠãŒã¶ãŒïŒãç£èŠããå¿
èŠã®ãããã©ã«ããŒã«ã¢ã¯ã»ã¹ã§ããªãå Žåããã¡ã€ã«ã¯ããŠã³ããŒããããªãããšã«æ³šæããŠãã ããã ãããã£ãŠããã®ç¹ãèæ
®ããŠã¢ã¯ã»ã¹ãèš±å¯ããå¿
èŠããããŸãã
12.æåŸã«ã
å±é ãµãŒã㌠rãåèµ·åããå¿
èŠããããŸããããã¯ããã£ã¬ã¯ããª
... / splunk / binããã³ãã³ãã©ã€ã³ã䜿çšããŠå®è¡ã§ããŸãã
./splunk reload deploy-server
äžèšã®æäœãå®è¡ããåŸãOSã€ã³ããã¯ã¹ã«ããŒããããLinuxãã°ãåãåããŸãã
ãããã«
ãããã£ãŠã詳现ãªåæãšåŠçã®ããã«ãWindowsããã³LinuxããSplunkã«ãã°ãããŒãããæ¹æ³ã瀺ããŸããã ãã®æ
å ±ãã圹ã«ç«ãŠã°å¹žãã§ãã
ãã®ãããã¯ã«é¢ãããã¹ãŠã®è³ªåãšã³ã¡ã³ãã«åçãããŠããã ããŸãã ãŸãããã®åéããŸãã¯äžè¬çãªãã·ã³ããŒã¿åæã®åéã«ç¹ã«èå³ãããå Žåã¯ãç¹å®ã®ã¿ã¹ã¯ã®ããã«æ¢åã®ãœãªã¥ãŒã·ã§ã³ã宿ãããæºåãã§ããŠããŸãã ãããè¡ãã«ã¯ãã³ã¡ã³ãã«ããã«ã€ããŠæžãããåœç€Ÿã®
ãŠã§ããµã€ãã®ãã©ãŒã ãããªã¯ãšã¹ããéä¿¡ããŠãã ããã