Sie sind auf Seite 1von 4

Splunk Enterprise Splunk Enterprise

Overview 7.0.0
Splunk Enterprise Administration
Generated: 10/02/2017 1:38 am

Copyright (c) 2017 Splunk Inc. All Rights Reserved


Splunk Enterprise Administration
This topic lists tasks that administrators might want to do and takes you to the
manuals and topics to learn how to do them.

Install and upgrade Splunk Enterprise

The Installation Manual describes how to install and upgrade Splunk Enterprise.

Task: Look here:


Understand installation requirements Plan your installation
Estimate hardware capacity needs Estimate hardware requirements
Install Splunk Enterprise on Windows
Install Splunk Enterprise Install Splunk Enterprise on Unix,
Linux, or MacOS
Upgrade Splunk Enterprise Upgrade from an earlier version
Back up configuration information
Perform backups Back up indexed data
Set a retirement and archiving policy
Get data into Splunk Enterprise

Getting Data In is the place to go for information about Splunk data inputs,
including how to consume data from external sources and how to enhance the
value of your data.

Task: Look here:


Learn how to consume external data How to get data into Splunk Enterprise
Configure file and directory inputs Get data from files and directories
Configure network inputs Get network events
Configure Windows inputs Get Windows data
Configure miscellaneous inputs Other ways to get data in
Configure event processing
Configure timestamps
Configure indexed field extraction
Enhance the value of your data
Configure host values
Configure source types
Manage event segmentation

1
See how your data will look after
The Set Sourcetype page
indexing
Improve the process Use a test index to test your inputs
How data moves through Splunk
Understand the data pipeline
Enterprise: the data pipeline
Manage indexes and indexers

Managing Indexers and Clusters tells you how to configure indexes. It also
explains how to manage the components that maintain indexes: indexers and
clusters of indexers.

Task: Look here:


Learn about indexing Indexing overview
Manage indexes Manage indexes
Manage index storage How the indexer stores indexes
Back up indexes Back up indexed data
Archive indexes Set a retirement and archiving policy
Learn about clusters and index
About clusters and index replication
replication
Deploy clusters Deploy clusters
Configure clusters Configure clusters
Manage clusters Manage clusters
Learn about cluster architecture How clusters work
Scale Splunk Enterprise

The Distributed Deployment Manual describes how to distribute Splunk


Enterprise functionality across multiple components, such as forwarders,
indexers, and search heads. Associated manuals cover distributed components
in detail:

The Forwarding Data Manual describes forwarders.


The Distributed Search Manual describes search heads.
The Updating Splunk Components Manual explains how to use the
deployment server and forwarder management to manage your
deployment.

2
Task: Look here:
Learn about distributed Splunk
Distributed Splunk Enterprise overview
Enterprise
Perform capacity planning for Splunk
Estimate hardware requirements
deployments
Learn how to forward data Forward data
Distribute searches across multiple
Search across multiple indexers
indexers
Deploy configuration updates across
Update the deployment
your environment
Secure Splunk Enterprise

Securing Splunk discusses how to secure your Splunk Enterprise deployment.

Task: Look here:


Authenticate users and edit roles User and role-based access control
Secure Splunk data with SSL Secure authentication and encryption
Use Splunk Enterprise to audit your
Audit Splunk Enterprise
system activity
Use Single Sign-on (SSO) with Splunk
Configure Single Sign-on
Enterprise
Use Splunk Enterprise with LDAP Set up user authentication with LDAP

Das könnte Ihnen auch gefallen