This guy is great. You can feel the passion behind his vidoes of wanting to help us and Im all for it.
@MyDFIR6 ай бұрын
Yup! Im happy you can tell haha thanks for watching ❤️
@i_die_in_my_daydreams6 ай бұрын
true story. I'm binging
@MandeepSingh-wb1yz6 ай бұрын
Dude you have no idea how impactful your work is for us aspiring cyber professionals right now, you have our utmost appreciation. Keep it going!!
@MyDFIR6 ай бұрын
I appreciate that! Thank you ❤️
@MandeepSingh-wb1yz6 ай бұрын
@@MyDFIR Btw will this project deem valid for someone trying to land an entry level Security Administrator role?
@MyDFIR6 ай бұрын
Absolutely. Once you have this AD up, you can start to learn how to harden it as well.
@johnniestokes28376 ай бұрын
Loving the videos so far! Please keep them coming!
@MyDFIR6 ай бұрын
WOW!! Thank you so much ❤️❤️❤️ I am so grateful. More to come!
@aref5686 ай бұрын
this channel is my favorite cyber security channel, please upload more!
@LeonardOffor6 ай бұрын
These videos are golden and you are a lifesaver for those of us trying to get into SOC analyst roles. Cant wait for your series on setting up and monitoring alerts on the Splunk environment we just set up
@Kishan_S1ngh6 ай бұрын
This was quick Steve Now I can start my documentation process I will drop my blog as soon as you complete this series And as always 11/10 for the content ❣
@random_guy30782 ай бұрын
Did u done with ur blog
@hazy3896 ай бұрын
Great video and series. Very interested in your training series you have planned. Keep The great work up. Thank you. 🙏❤
@MyDFIR6 ай бұрын
Awesome, thank you!
@olatunbosunkayode96327 күн бұрын
Hi great video brother, really appreciate you. please i need help as i am stuck trying to extract the splunk enterprise from my file explorer, the file is empty . i have already deleted and downloaded a new one still the file seems empty . Please i am new to this but passionate to get it right. Thanks
@uzi41814 күн бұрын
when i download ur config file do i delete the original one and move the downloaded one into the local file?
@LeonardOffor6 ай бұрын
I had issues with forwarding logs from my AD server. What fixed it for me was to uninstall the Universal forwarder I had and re-install it again but this time during the installation I had to put in the server IP address as the deployment server address and used the default port 8089. If you have a similar issue, try this and hope it works for you.
@takrooni114 ай бұрын
same problem with me ,, i will reinstall it again
@takrooni114 ай бұрын
unfortunately not fixed , my splunk read only target-pc ,, ADDC not
@ftgljared4 ай бұрын
worked, thank you!
@marcpayz87476 ай бұрын
So I got to 25:00 part of the video, followed everything and once I put index=enpoint, I am getting "no results found. Try expanding the time range." And my time range is just like yours "Last 24 hours" plssssss help
@marcpayz87476 ай бұрын
nvmmmmm I switched to my AD server and followed the same steps, and when I went back to splunk to login, both hosts are there with logs :)
@MyDFIR6 ай бұрын
Niceee!! Great job
@marvintxx4 ай бұрын
@ 2:57 of the video when I hit the tab key i get thins sudo nano ?etc/netplan/50-cloud-init.yaml not sudo nano /etc/netplan/00-installer-config.yaml can you help me what am I doing wrong?
@MyDFIR4 ай бұрын
Thats fine, likely you are using a different provider than I am. Sounds like you are using the cloud vs on-prem.
@marvintxx4 ай бұрын
@@MyDFIR I am using 4 vm's with Virtual box. no cloud.
@legendinthegaming3 ай бұрын
Hey, I've enjoyed and appreciated your instruction so far. Even using VMWare workstation Pro, I'm able to follow along, or use alternate methods to keep up. Im having trouble with sending data to splunk. Currently my VMs can communicate with each other and the target machine can access splunk server hosted on ubuntu. When I try to send the endpoint index logs over, there is no telemetry. I think it may have something to do with Sysmon but I didn't devaite from that step, so I'm unsure what the issue is. Any help would be appreciated.
@MyDFIR3 ай бұрын
Is your inputs.conf updated and have you restarted your splunk service on the windows endpoint?
@legendinthegaming3 ай бұрын
@astrid5461 Here is fine. Ill do my best to help. What issues are you having with vmware?
@legendinthegaming3 ай бұрын
@@MyDFIR sorry for the late reply, but yes, I've put the updated inputs.conf file in the local directory and have restarted the service in windows, still no telemetry for the endpoint index, though the logs from Syston appear in the event viewer, so I know they're there, just not being forwarded
@marveII0us6 ай бұрын
Awesome! Currently at a previous part but will catch up soon
@MyDFIR6 ай бұрын
Have fun!
@tone3966 ай бұрын
when i type in the command that you did @5:08 apart of the video i get error messages saying "Cannot call Open vSwitch: ovsdb- server is not running." what does this mean?
@MyDFIR6 ай бұрын
Take a look at the comments as I believe someone had the same error as you did
@maryamrufai48569 күн бұрын
Thank you for the challenge of DIY, was worth it!!... ❤❤❤
@MyDFIR9 күн бұрын
You are so welcome!
@ByteBouncer20216 ай бұрын
Once again another great tutorial!! Is there a reason why in your instructions you not downloading Splunk and Splunk Forwarder via Command line?
@MyDFIR6 ай бұрын
Thanks! No reason, i just wanted to show another way of doing things. Download it how you want 👍
@Explorer10927 күн бұрын
was the splunk forwarder and sysmon downloaded on the virtual machine or the system
@MyDFIR27 күн бұрын
Always on the VM
@iXecurity3 ай бұрын
Good day bro Iam having issues configuring the NAT network on VMware workstations please anyone can help me
@MyDFIR3 ай бұрын
What are you experiencing?
@christophersimmons78383 ай бұрын
am i not getting any events because i dont have splunkforwarder on my ubuntu server
@MyDFIR3 ай бұрын
If you’re not getting events, check your inputs.conf file on your windows machine and make sure you have your index created. Check out the troubleshooting video if you haven’t already
@crzyassgoon1812 ай бұрын
Thanks for the content! I have an issue downloading sysmon as a zip. Every time I download it as and xml doc it opens up on edge instead of downloading as a zip. I tried it on Brave and same thing. Please help, much appreciated brotha! Update: I saw your other video and managed to figure it out👍
@iammartt4 ай бұрын
when i type in ip a my inet is 192.168.10.4/24 and when i try to use the installer config file nothing shows up
@MyDFIR4 ай бұрын
Make sure there are no typos - I would google how to setup a static IP to some written instructions/alternative guides as something weird could be happening
@headcase22266 ай бұрын
Was going to ask for help getting sysmon and splunk forwarder installed on the Ubuntu Server only to find out you meant the Windows Server .-.
@wafeeqfareed3668Ай бұрын
So I was able to configure and integrate sysmon in my windows machine. Apparently following the exact procedure on Windows Server machine hasn't been of much help
@MyDFIRАй бұрын
Strange, following the same step on the server should work.
@wafeeqfareed3668Ай бұрын
@@MyDFIR this is ofc taking into consideration the fact like IPv4. But apart from that I had followed it thoughout
@TheZikori6 ай бұрын
Great video. Thank you
@MyDFIR6 ай бұрын
Glad you liked it!
@DAREuDARE3 ай бұрын
Could we Use another server? And which? Coz since May, it looks like there's a bug interfering with the Server.... Most people just can't "connect the ubuntu Splunk server to the internet" I've been trying for days but to no avail. '
@MyDFIR3 ай бұрын
If I misunderstood your question please correct me! Using another server wouldn’t solve the problem of being unable to connect to the internet. What happens if you ping google.com?
@DAREuDARE3 ай бұрын
@@MyDFIR and this keeps happening after sudo netplan apply : response warning root: cannot call open vSwitch: ovsdb-server.service is not running.
@crowbar95662 ай бұрын
When I hit tab autocomplete I got a different command, so i typed it out in full. Also I don't get those pink screens when the downloads complete. Why's that? Also after the 2nd reboot I still got the fatal error 'the group vboxsf does not exist' . How do I make vboxsf exist?? I have no idea where I went wrong because i'm pausing the video and following along at every step .
@MyDFIR2 ай бұрын
You could try using wget to download splunk onto your virtual machine. Since I am unable to see your configuration, it is quite tough to troubleshoot. Worst case, restart from scratch.
@crowbar95662 ай бұрын
@@MyDFIR When did we create the group vboxsf? I put the splunk debian on my F drive rather than C:/.....do you think that makes a difference?
@ajayiosahontv2 ай бұрын
You're a G.O.A.T. Thank you for the amazing work. I'm in the process of setting up my HomeLab. I want to change my Wi-Fi network to Ethernet before I continue with Part 3, or do you think it's advisable to continue setting it up with a Wi-Fi network? Should I just switch to an Ethernet cable instead?
@MyDFIR2 ай бұрын
Thanks! Either or works, I would do it via ethernet if possible just cause its more “reliable”
@abroadstateofmind55714 ай бұрын
Following your series and I'm really enjoying the hands on experience..Definitely making a LinkedIn post and updating my resume after this is done. Thanks a lot man!
@MyDFIR4 ай бұрын
Awesome, thank you and great work!
@drmikeyg6 ай бұрын
Thanks and great job.💙
@MyDFIR6 ай бұрын
Thanks for watching!
@imca_b_55176 ай бұрын
You are rocking ❤
@MyDFIR6 ай бұрын
Thank you ❤️
@sanjaenelson1792 ай бұрын
@MyDFIR I a have a question, when I typed in sudo 2:48 it brought me to a blank page and don't see those same colored text. Is there a step that I skipped or miss configured? I also typed in 192.168.10.0/24 and in splunk I got a different IP 192.168.10.4 instead of your 192.168.10.9
@MyDFIR2 ай бұрын
Check your spelling and file path. Also its fine it you have a different IP address, as long as you can access it 👍
@sanjaenelson1792 ай бұрын
@@MyDFIR My spelling is ok. When I press Tab it pops (50-cloud-init.yaml) it brings me to the same scene shown on your video, but I have different blue writing stating something. Should I be concerned moving forward? Example: # This file is generated from information provided by the datasource. Changes # to it will not persist across an instance reboot. To disable cloud-init's # network configuration capabilities, write a file # /etc/cloud/cloud.cfg.d/99-disable-network-config.cfg with the following: # network: {config: disabled} 5:00 Also, after I pressed enter on "sudo netplan apply" I got hit with /ect/netplan/50-cloud-init.yaml Invalid YAML: inconsistent indentation, then of course its shows the addresse 192.168.10.10/24
@sanjaenelson1792 ай бұрын
@@MyDFIR Thank you! How could I write a file "/etc/cloud/cloud.cfg.d/99-disable-network-config.cfg"? I can't apply update until I am able to write this file with the following "network: {config: disabled}"
@ratyrat5Ай бұрын
i went thru all 5 parts, very good project. one random note is that i noticed you set the W10 machine to have a static IP address instead of it being DHCP assigned like in the diagram. i understand it's because there would be a conflict with the AD server, but couldn't there be a way to "refresh" the assigned ip? i thought of maybe trying ipconfig /release and /renew but that didn't work.
@MyDFIRАй бұрын
Yeah ipconfig /release and renew would provide another IP if DHCP was used. Ideally you would reserve some IPs for static purposes and put…say .50-254 on a /24 as dhcp
@mattbergey62795 ай бұрын
Great video brotha, I have a question though. So I set up Sysmon and the universal forwarder but when I log into the Splunk server on the "Search & Reporting" only the WinEventLog Security, Application, and System values come up in the "source" field. I did mess up the "inputs.conf" code and went back and fixed it and restarted the SplunkForwarder service however Sysmon is still not showing up on "Search & Reporting." Could you shed some light?
@MyDFIR5 ай бұрын
Check out the troubleshooting video, hopefully that could help fix the problem!
@PhannaPH302 ай бұрын
This is a great channel for SOC home labs. Even though I am not a SOC guy, I can still build it for my penetrating. Big thanks for your kindest.
@MyDFIR2 ай бұрын
Thanks for the kind words!
@hensolo88252 ай бұрын
I run into an error when I run sudo netplan apply: Openvswitch is not running So I fixed it by running sudo apt-get install openvswitch-switch-dpdk
@MyDFIR2 ай бұрын
Great job on fixing that 👏👏
@aka1Khalid4 ай бұрын
Question, So i'm using some old computers to run this project (3 to be exact and they each are running virtual box with a virtual machine). Before I start setting up the network, will this be a problem (i'm still new to using VM's and want to know if they can communicate with each other even if they are on different machines but same home network)?
@MyDFIR4 ай бұрын
That is fine 👍 you’ll likely need to put them into a bridged network (network adapter setting in VM)
@amosakogbe78305 ай бұрын
The project is very interesting so far. Thank you for the videos. I would like to know if the process for the installation of splunk and the use of virtualbox guest- additions iso are the same if you are using Vmware Workstation Pro for the lab ? Thanks.
@MyDFIR5 ай бұрын
Yeah installing Splunk is the same. For VMware, you’ll need to research how to install guest add ons
@MM-qv6kf5 ай бұрын
I installed sysmon not the sysmon64 xml. I followed the troubleshooting steps but its not generating any events. Do i need to instruct somewhere to read the inputs.conf from the local instead of the default. Been rewatching and cant find the issue. I dont know if installing the sysmon not the sysmon64 was the issue. Can you help please. Thanks.
@MyDFIR5 ай бұрын
“Not generating events” is this in Splunk or Windows event logs?
@bsairamshastri19466 ай бұрын
I configured my endpoints to forward logs on to the splunk server. Only thing missing is sysmon logs because I can't see sysmon as a source in splunk. I verified in inputs.conf and restarted splunk forwarder several times. Also tried restarting sysmon service. Configured my server the same way and same problem persists. Sysmon doesn't show up as source. Any thoughts? ❤
@MyDFIR6 ай бұрын
Do make sure that the service account is set to local and not the Splunk account.
@cobos26902 ай бұрын
@HouseholdtoolsReviews4 ай бұрын
I really don't understand whats the need to configure splunk this way when we can just use the web version, please make me understand. Thanks
@MyDFIR3 ай бұрын
I have you set it up this way as this is how it is typically installed in real world environments. Of course not all environments are the same but so far this is how ive seen it.
@ftgljared4 ай бұрын
I didnt see where you made the active directory folder? I guess I will just use my downloads folder and see what happens lol
@MyDFIR4 ай бұрын
Thats fine, any directory will suffice
@ftgljared4 ай бұрын
@@MyDFIR Appreciate it, I figured it was fine. After all, I bought a new HP Envy Tower Desktop with an i7 and 16gb of ram to practice all your labs on!
@MyDFIR4 ай бұрын
Beautiful! Love the specs 💪
@ESoFly3 ай бұрын
This video as well as the others are incredibly valuable. Thank you for spreading knowledge with such passion and detail!
@MyDFIR3 ай бұрын
Thank you for watching! I hope you learned a lot 😃
@pritampal65616 ай бұрын
Bro i am not receiving any data on splunk .. i dabble cheaked all points but still not getting any data . I restarted all lab but still don't . I edited inputs.conf file but still doesn't working . Please help
@MyDFIR6 ай бұрын
Confirmed your hosts are on the same network? Check out the troubleshooting video for this series for some assistance!
@PuffBittle3 ай бұрын
anybody have any idea why the yaml lines he writes at the 5 minute mark aren't working for me at all? im on the latest version which is like 24 and inputting them into the terminal window but i keep getting a thousand different reasons as to why it wont work. im not sure if its the version im using, if im somehow using the wrong terminal window, etc.
@MyDFIR3 ай бұрын
Yeah YAML can get kinda weird sometimes, try using this jsonformatter.org/yaml-formatter and see if that helps!
@sanjaenelson1792 ай бұрын
Thank you! @5:00 How could I write a file "/etc/cloud/cloud.cfg.d/99-disable-network-config.cfg"? I can't apply update until I am able to write this file with the following "network: {config: disabled}"
@MyDFIR2 ай бұрын
Not sure if I understood the question but this could be due to permissions? Have you tried editing/writing using sudo?
@sanjaenelson1792 ай бұрын
@@MyDFIR i have not I'm new to all this. I was just following your step but got stopped here. I've been researching on how i can write or create this file that is telling me too do but no clue where or how to do that. I cant move forward with the process util this file is disabled.
@MochiLearning8085 күн бұрын
I had the same issue as you when trying to configure static IP. Instead of 00-installer-config-.yaml, i had 50-cloud-init.yaml. It allowed me to modify 50-cloud-init.yaml, and the static IP takes place temporarily, but the problem is when I reboot the splunk server the IP reverts back to DHCP. I created "/etc/cloud/cloud.cfg.d/99-disable-network-config.cfg" and wrote "network: {config: disabled}", but this didn't help much. What did help is I created my own 00-installer-config-.yaml inside /etc/netplan/ and wrote what MyDFIR had in his. Now when I reboot the splunk server it has the static IP of 192.168.10.10 and I'm able to connect to it on my Win10 VM browser by searching 192.168.10.10:8000. Hope this helps.
@sanjaenelson1794 күн бұрын
@@MochiLearning808 buddy thank you. God bless you till this day I’m struggling 🤣. Do you have an email that I can connect with you that you can show how?
@Obrempong16 ай бұрын
I had run into some issues with the splunk, will try n screenshot n post it
@DanielRodriguez-gm1to4 ай бұрын
I really appreciate the time and effort you put into making this tutorial high-quality, and easy to follow. This makes it easy for beginner it professionals to follow along, and gain valuable experience. I have never seen this kind of work put into a cybersecurity tutorial anywhere on KZbin. Props my dude!
@MyDFIR4 ай бұрын
You're very welcome! It does take quite a bit of time and I appreciate you noticing that ❤️
@mateuszkacperski12114 ай бұрын
❤
@mateuszkacperski12114 ай бұрын
❤
@hammazahmed12895 ай бұрын
Just completed this part. How do you recommend putting this lab on our resume and Github?
@MyDFIR5 ай бұрын
Take a look at the GitHub video I have on my channel to get started. As for Resume, put in the skills you've learned but be sure you can speak to it.
@amrindersingh48486 ай бұрын
This is great practice, thanks!!. I have one question, the folder we share with Ubuntu, is it only to install splunk or does it have another use as well ??
@MyDFIR6 ай бұрын
It is up to you honestly, its just a shared folder.
@mehdizimhi32482 ай бұрын
Hello, i got 0 event when i searched the endpoint index , any advice ? thanks
@MyDFIR2 ай бұрын
What troubleshooting have you done so far? Did you take a look at the troubleshooting video by any chance?
@GCabanellas.6 ай бұрын
♥Great video. I have experience creating a virtual environment and setting up AD and so on but configuring Splunk, Sysmon and the universal forwarder was something completely new for me. Keep it up.
@MyDFIR6 ай бұрын
Awesome! More repetition, the easier it gets ❤️
@ucheobiora7616Ай бұрын
Everything was going fine till I put in a search I get no events no matter what I search it always comes down to 0 events
@MyDFIRАй бұрын
Make sure the index is created and you restarted your splunk UF service
@ucheobiora7616Ай бұрын
@@MyDFIR thank you that worked
@ucheobiora7616Ай бұрын
@@MyDFIR index_internal showed me events but the index=endpoint is still zero is there a reason for that ?
@ucheobiora7616Ай бұрын
I just restarted the whole process again and it worked thank you so much
@davidtran682011 күн бұрын
at 2:50 the file that appears for me is 50-cloud-init.yam1 instead of the installer-config one. What could be causing this?
@dxwid956710 күн бұрын
Yh I have the same thing did you figure it out yet ?
@dxwid956710 күн бұрын
Btw I just found the version he has but now I can't ping Google
@davidtran68209 күн бұрын
@@dxwid9567 it ends up being the same essentially. just follow his instructions as if they are the same file. worked for me
@JeronomoDclan5 ай бұрын
what is the other listen port for the windows server? 1997 is already in use
@MyDFIR5 ай бұрын
Sorry could you clarify why you would need another port on your windows server?
@xCyberAce4 ай бұрын
I've been following along so far but it seems that whenever I try to ping Google, I am able to transmit packets but I'm unable to receive them. I've tried re-doing the process but it's still not showing any received packets. When downloading ubuntu, I was only able to download the most recent version (24.04 LTS).I was unable to find the download file on my computer for 22.04.4 LTS, when I attempted to download that one. So when I input the "sudo nano" it looks like this "sudo nano/etc/netplan/5-cloud-init.yaml". I'm not sure if maybe that is the reason why I am not receiving any packets. Struggling a little lol.
@MyDFIR4 ай бұрын
Struggling is good! Level up those troubleshooting skills. Take a look at linuxconfig.org/setting-a-static-ip-address-in-ubuntu-24-04-via-the-command-line#:~:text=Setting%20a%20static%20IP%20address%20on%20Ubuntu%2024.04%20involves%20identifying,and%20securely%20on%20your%20network.
@xCyberAce4 ай бұрын
@@MyDFIR Thank you so much! I was able to figure out what I was doing wrong!!
@RanjaNyAina6 ай бұрын
i have troubles getting splunk, has it anything to with my mail address not being a business one ?
@MyDFIR6 ай бұрын
Nope, did you get redirected to a downloads page?
@hammazahmed12896 ай бұрын
Hey. How can put this on our resume and Github to kind of show an employer what we did?
@MyDFIR6 ай бұрын
I created a video about projects on GitHub and you can follow that, as for resumes you can either provide a high level summary or put down the skills you learned from this project
@tosinabiodun32863 ай бұрын
I followed all the steps correctly but not receiving windows logs
@MyDFIR3 ай бұрын
What troubleshooting have you done so far?
@tosinabiodun32863 ай бұрын
@@MyDFIR I have been able to establish that active forwards is configured but it's inactive. I can ping from the forwarder to the indexer and there is no firewall in between.
@tosinabiodun32863 ай бұрын
@@MyDFIR I managed to fix it and the logs are being ingested successfully. You are the real MVP man thank you!
@MyDFIR3 ай бұрын
Awesome work!
@FALS06 ай бұрын
I had an error when I tried to startmy Kali linux VM the error was VERR_FILE_NOT_FOUND
@FALS06 ай бұрын
nvm I fixed it, downloading Kali linux and unzipping with winRAR does Not work, you do have to use 7 ZIP
@MyDFIR6 ай бұрын
Great job figuring it out 🙌
@Vyper4436 ай бұрын
Great presentation Steve. Salute! One question, can I use this project as my portfolio or do I need to modify or tweak it and eventually present it to my future employer?
@MyDFIR6 ай бұрын
I would recommend you modify it to make it more tailored to you.
@brenenn15626 ай бұрын
Loving this lab! It is instructed and detailed perfectly! Lets me also figure things out on my own. This is great!♥
@MyDFIR6 ай бұрын
Awesome! Happy to hear that, thanks for participating ❤
@maybeitsme35544 ай бұрын
Hello brother , I was just looking at your video and am halfway through it. I am stuck at the part whre you open splunk enterprise page using 192.168.10.10:8000 , it just doesn't open in min. Can you tell me where would be the problem as my UBUNTU configs are properly implemented. Thank You.
@MyDFIR4 ай бұрын
Hey, couple things - 1) Make sure your IP is actually that, and not something else. 2) Did you start Splunk?
@maybeitsme35544 ай бұрын
@@MyDFIR Yes my ip is 100 percent that and I also started and configured the splunk in the same way , did not got any errors while configuring it. All my machines are connected with net it is just that it shows site is not able to reach when I type in to get the splunk page , like after configuring it such that it starts everytime splunk opens when machine reboots , I have not done anything manually .
@MyDFIR4 ай бұрын
@@maybeitsme3554 Can your machines ping splunk?
@maybeitsme35544 ай бұрын
@@MyDFIR so I ca ping my machine 192.168.10.10 from other machines but when I checked status of splunk , it said SPLUNK SERVICE FAILED TO EXECUTE /etc/init.d/splunk: Exec format error
@maybeitsme35544 ай бұрын
@@MyDFIR Hey maan ! Just solved the issue I had to repeat the process of configuring splunk user in the share folder , but was able to solve it quickly. There was something called as splunk helpers which was running instead of splunk , when I re configured IT actually stopped splunk helpers and instead started splunk. Thank you so much for you support man 😄😄
@ftgljared4 ай бұрын
Having a blast learning thank you
@cyberjuss6 ай бұрын
What if i am using vmare > hard for me to run the "sudo apt-get install command "
@MyDFIR6 ай бұрын
It shouldn’t matter which hypervisor you are using, unless I am misunderstanding the question - you can still run the command
@cvpherhack3r8196 ай бұрын
♥Thank you for this lab! I am loving diving back into Splunk again and installing it I cannot wait to configure Active Directory as so many positions ask for experience in it! Killing two birds with one stone! Thank you Steve! ❤
@MyDFIR6 ай бұрын
Anytime! Have fun 😁
@michaelsheppard73406 ай бұрын
Within Splunk, I am having trouble adding a user. It is saying that VirtualBox does not exist. After following the video and getting the guest-util update, some files failed to fetch. How can I resolve these failures?
@MyDFIR6 ай бұрын
Interesting, if failing to fetch makes me believe there might be some internet connectivity.
@michaelsheppard73406 ай бұрын
I was thinking the same, but it did download other files and errored out on some.@@MyDFIR
@hazemmasoud76656 ай бұрын
I got headache because all the details lol but I wont give up *-*
@MyDFIR6 ай бұрын
Haha thats the spirit! Take it slow
@DatBeastPJ5 ай бұрын
I can not access the splunk login page from my browser on my target-PC, "Hmmm.. can't reach this page" any suggestions?
@MyDFIR5 ай бұрын
Make sure you add in the port number as well and ensure splunk service is enabled on the splunk server
@PCX4253 ай бұрын
Make sure the VM for your server is actually on.
@cyberjuss6 ай бұрын
Hey how were you able to determine the IP address of the network you wanted to use
@MyDFIR6 ай бұрын
You can assign whatever address in the private IP space aka RFC1918 as long as they are in the same network, they should talk to each other.
@fixprob6986 ай бұрын
sir there is a problem when i am applying this command sudo netplan apply i am receiving this error WARNING:root:Cannot call Open vSwitch: ovsdb-server.service is not running. kindly help me
@muluwold59696 ай бұрын
How do you solve a problem?
@MyDFIR6 ай бұрын
Check the comments, someone had the same error and was able to solve it after installing it.
@muluwold59696 ай бұрын
Use these commands. # run this first $ sudo apt-get install linux-modules-extra-raspi # run this then $ sudo apt-get install openvswitch-switch-dpdk
@im_anubiz4 ай бұрын
I'm stuck at 9:07 in the video. I still can't add "vboxsf". It does not exists and I wasn't given the optional prompts on the screen to add it.
@MyDFIR4 ай бұрын
If that doesn’t work you can use the wget command to install splunk
@judgementknight4818Ай бұрын
If you add the user first, then add the user to vboxsf, it should work. for example: "adduser guest" After this command it'll ask for a new password and other info. When you fill that out then use the command, "adduser guest vboxsf" and it should work
@mark-jin-10-xk1po6 ай бұрын
❤ this videos. Please continue to make 'em for us aspiring cyber warriors!
@MyDFIR6 ай бұрын
More to come! Thanks for watching ❤️
@jerryasagba73525 ай бұрын
❤Thank you for the incredible content. I look forward to more
@MyDFIR5 ай бұрын
More to come!
@Rohitkumarsingh-q6f6 ай бұрын
❤❤ i get to know many things
@dominicanpa4u1035 ай бұрын
My splunk installer is not coming up on my share folder using la -ls. I exited and rebooted many times and still it wont come up
@MyDFIR5 ай бұрын
You can try and install Splunk via wget if you cannot get the shared drive up and running
@dominicanpa4u1035 ай бұрын
@MyDFIR appreciate the quick response i was having issues with my download folder but i figured it out. Thank you for the assist.
@bebryan12016 ай бұрын
does anyone know if Splunk was downloaded directly from the VM, or was it imported/added-in after it was downloaded?
@MyDFIR6 ай бұрын
This specific demo Splunk was downloaded from my host machine and transferred to the VM. However, you can use the command ‘wget’ to download Splunk directly from your VM.
@bebryan12016 ай бұрын
Some of the VM stuff, installs, settings etc is the most difficult part for me. I appreciate all that you are doing here!
@raymond43076 ай бұрын
This guy is the GOAT. Straight to the point I am very grateful I came across your channel
@MyDFIR6 ай бұрын
Thank you! Please consider sharing this to others if you believe someone in your network can benefit from it ♥
@kalibholland29686 ай бұрын
Followed the exact steps for putting splunk and sysmon on Target PC and did the same for ADDC01 but host in endpoint index only shows TargetPC and not ADDC01. When doing settings for internet protocol version 4 in ADDC01 I used the settings in Part 4 so could that be my problem?
@MyDFIR6 ай бұрын
Same settings as in same IP? If so, that is the problem as there is a conflict. Change the IP, make sure the DC is in the same network and restart your Splunk service.
@kalibholland29686 ай бұрын
I used different IP addresses but the same default gateway
@kalibholland29686 ай бұрын
Found the problem lol I must have messed up something when installing splunk forwarder so I uninstalled and reinstalled it, redid the inputs.conf file and restarted service and now I see the host name
@ВасилийТеркин-с3э6 ай бұрын
Go on! You are the best content creator in this field. Amazing video!
@MyDFIR6 ай бұрын
Thanks for the kind words ❤️
@cyberjuss6 ай бұрын
hi when downloading splunk on the windows server does that mean i have to chang the IP address as well using sudo nano in the spulnk server? or can I just downled spuk enterprise and fowarder and continue from there
@MyDFIR6 ай бұрын
Please refer to your network diagram that you've built in Part 1. Not sure what you mean by changing the IP as well using sudo nano - As long as these machines are in the same network you should be fine.
@cyberjuss6 ай бұрын
Great Thank you!@@MyDFIR
@jdez27014 ай бұрын
7:37 anyone have tips to why I can’t find the splunk download file? I can locate on my host folder but every time I look through the vm shared folder tool it’s not there .
@jdez27014 ай бұрын
Oh yeah also should mention, I didn’t get the screen pop up after the guest additions install, although it seem to have installed when I checked through cli and is updated
@MyDFIR4 ай бұрын
Strange, if you’ve followed step by step and it still doesn’t work you can use wget from your splunk VM to download Splunk
@jdez27014 ай бұрын
@@MyDFIR thank you! will try later today
@jelanimiller56346 ай бұрын
Hello, I’m having trouble connecting to the splunk page via the IP address. I followed the steps with a fine tooth comb. Is there another way of connecting to the page?
@MyDFIR6 ай бұрын
Make sure you are including the port number and the service is running
@jelanimiller56346 ай бұрын
I have, but it's timing out. I pinged to make sure I have connection, and it shows I'm connected. @@MyDFIR
@ftgljared4 ай бұрын
@@MyDFIR I felt so dumb after I saw this, clearly it needs to be running lol
@PhilosopherRoger6 ай бұрын
I really appreciate this series man! I’m learning a lot💪🏾❤️
@MyDFIR6 ай бұрын
Glad to hear it!
@Adewest6 ай бұрын
Great stuff @mydfir, always keeping me on my toes. I ran into some problem after installing Splunk enterprise on ubuntu, I can't access Splunk web interface. I have my hypervisor running on Intel base MacBook Pro, I configured it to use the NAT network using CIDR /24, I made sure port 8000 is listening on ubuntu FW, I have tried to telnet from a remote computer but it was unsuccessful, and Splunk services is running. Please kindly come to my rescue. Thanks😥👍
@MyDFIR6 ай бұрын
Just to make sure, did you install the Splunk enterprise? You should be able to access it, can also try restarting the service.
@Adewest5 ай бұрын
Solved. I was trying to access Splunk web interface on a different network. Thanks for the good work @@MyDFIR
@jacoblee34275 ай бұрын
@ADewest Hi, were you able to fix this? I am running on Intel base MacbookPro as well and having a same issue as you. I wonder if Splunk needs to be run in the background. Thanks.
@Adewest5 ай бұрын
@@jacoblee3427 yes. Are you running your labs on one hypervisor? In my case I wasn’t so I had to put everything on one hypervisor and made sure they all in the same NAT network and I didn’t encounter any error after trying to access splunk web interface on my target windows machine and AD
@syednaqvi35206 ай бұрын
Thanks and love the way you explain in detail Bravo
@MyDFIR6 ай бұрын
Glad you liked it!
@edgaracuna49146 ай бұрын
FYI for anyone that runs into an issue installing Splunk using the './splunk start' command, and gets an error 'File or directory doesn't exist'. I think when I switched user the directory I was on changed so I think I was in the root '/bin' directory. Once I changed directory again to '/opt/splunk/bin' I was able to run the command without an issue
@MyDFIR6 ай бұрын
Great catch 👍 always check your directories unless you added the binary as an environment variable!
@janisimow6 ай бұрын
This solved the issue I was having thank you
@syednaqvi35206 ай бұрын
Thanks for such great voses I was follwing you along ! however stuck at where start splunk from cd/bin folder ./splunk start says no such file or direcotry exist . All previous steps compelted and matched any help ?
@syednaqvi35206 ай бұрын
figured it out rebooted then ran agin it solved
@JEN-ge1lu14 күн бұрын
Stuck at the same point. how did you solve it?
@JEN-ge1lu14 күн бұрын
there is bin in the home and there is a bin in /opt (/opt/splunk/bin) enter this directory and execute ./splunk start
@AsmeromMicheal-u9z6 ай бұрын
Great Videos , Thank you
@MyDFIR6 ай бұрын
Glad you like them!
@tituskwenah15366 ай бұрын
♥ Great knowledge transfer here.
@MyDFIR6 ай бұрын
Glad to hear that!
@awumyvesagwo65816 ай бұрын
This is great.
@daveittt6 ай бұрын
I tried to access the Splunk server using 192.168.10.10:8000 and it's not working. What do I do? Please help.
@MyDFIR6 ай бұрын
What have you done to troubleshoot so far?
@daveittt6 ай бұрын
@@MyDFIR I tried tweaking the IPv4 settings. That did not work. I spent time reading online as well and haven't come across anything helpful.
@MyDFIR6 ай бұрын
is Splunk running? Check the services and are you on the same network? @@daveittt
@daveittt6 ай бұрын
It's working now! Thanks so much!
@Adewest6 ай бұрын
I am having the same issue, what did you do to solve it?@@daveittt
@RandomFaxx6 ай бұрын
I get: "WARNING:root: Cannot call Open vSwitch: ovsdb-server .service is not running" when I try to apply the netplan after configuring the ip adress file.. any clue why
@MyDFIR6 ай бұрын
As I have yet to encounter that error, I am not sure but try enabling the service and if that doesn’t work, Google should help!
@mcgam3r_tv8096 ай бұрын
run this and try again: $ sudo apt-get install openvswitch-switch-dpdk
@RandomFaxx6 ай бұрын
@@mcgam3r_tv809 I tried this but I only get hit with: E: Unable to locate package openvswitch-switch-dpkg" ?
@RandomFaxx6 ай бұрын
@@mcgam3r_tv809 Was able to install it with the command you provided -dpdk at the end... cheers
@mcgam3r_tv8096 ай бұрын
@@RandomFaxx happy to help!
@bryanwoodward40986 ай бұрын
Amazing work as always. ❤❤
@MyDFIR6 ай бұрын
Thank you so much 😀
@ethandann39176 ай бұрын
I need help installing the universal forwarder on the Splunk Server. I followed the instructions from the website and it starts and everything but when I installed it, it said port 8089 was already in use (since we used that for splunk enterprise), so I set it to 9997 since I thought that was correct. I configured everything on the target machine (indexes, receiving port to 9997) and no events show for index 'endpoint'. So I went over to the Splunk server and made sure there was a service running on port 9997 and it says splunkd is so I'm kinda at a loss... been trying to figure it out for the past 3 or 4 hours 😂 My only problem is the splunk forwarder, I hate asking for help but can someone help please?
@ethandann39176 ай бұрын
Also, when installing both splunk and splunkfwd it didn't create any inputs.conf or outputs.conf file, if that helps
@MyDFIR6 ай бұрын
You dont need to install a universal forwarder on your Splunk server. By doing so, you likely had overwritten some of the files. I would recommend you start your Splunk server from scratch and install only Splunk Enterprise.
@ethandann39176 ай бұрын
@@MyDFIR I thought for sure you said at the end of the splunk section to leave the universal forwarder to us, I guess I misunderstood 😅 so only install the forwarder on the windows target machine, and only splunk enterprise on the splunk server? I’ll give it a rewatch and start over. I appreciate the project though for real, awesome work