Installing Splunk Enterprise
In this chapter, we will install and deploy Splunk instances to simulate the environment used to generate the BOTS Dataset v1
app in our case study. Our deployment will consist of one deployment server, one indexer, one search head, and three forwarders. We will utilize AWS EC2 instances for each of the components. Figure 2.1 shows the main components. We will deploy the AWS EC2 Splunk Enterprise Amazon Machine Image (AMI) to host the deployment server (deploymentserver
), search head (searchhead
), and indexer (indexer
). These devices are represented as orange rectangles in Figure 2.1. The forwarders (forwarder1
, forwarder2
, and forwarder3
) are AWS EC2 instances running Windows Server 2019. The forwarders in the BOTS Dataset v1
app are named we8105desk
, de9041srv
, and we1149srv
, but we will use a simple naming convention (forwarder1
, forwarder2
, and forwarder3
) in the instructions. They are represented as blue rectangles here: