Long time EH-Net contributor offers up his first article. Well done, and we'll look for many more.
Permanent link:
[Article]-What the Splunk?By Bill Varhol, Security+, CEH, LPT
By now you’re probably wondering, ‘What in the world is Splunk?’ Well guess what? I have your answer. In its simplest statement, Splunk is by far one of the coolest log analysis/indexers available! Anything you have that generates logs of some shape, size, or form (and I really mean anything) can be sent to Splunk for indexing and future analysis.
Sure there are other things out there that do something similar, but nothing that indexes every piece of data the way Splunk does. By every piece, I mean you have the ability to search for IP addresses, time, date, web requests, error messages and more! This makes troubleshooting all sorts of different issues a breeze. Don’t believe me? Watch the
demonstration video of ‘Search IT’ available from the Splunk Website. This is a great example of how powerful Splunk can be.
Let us know what you think and if we should do a follow-up review to drill down more with some more data and reporting on security incidents.
Don