Setup and Configuration

We'll run through deploying Splunk, setting SSL certs, and roles.

SSO/SAML isn't available in the free edition.

Virtual Machine

Deploy a standard VM. We're using Ubuntu 24.04.

Sign into your Splunk portal, and grab the .deb package link

$ wget -O splunk-10.0.2-e2d18b4767e9-linux-amd64.deb "https://download.splunk.com/products/splunk/releases/10.0.2/linux/splunk-10.0.2-e2d18b4767e9-linux-amd64.deb"

Install the package

$ sudo dpkg -i splunk-10.0.2-e2d18b4767e9-linux-amd64.deb

Check it's installed

$ dpkg --status splunk
Package: splunk
Status: install ok installed
Maintainer: Splunk Inc. <[email protected]>
Architecture: amd64
Version: 10.0.2
Description: Splunk The platform for machine data.

Start it

Accept the general terms and conditions

Wait for the self-signed certs to be generated

Last updated