<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Ubuntu on Everything Cyber</title><link>https://everything-cyber.netlify.app/tags/ubuntu/</link><description>Recent content in Ubuntu on Everything Cyber</description><generator>Hugo -- gohugo.io</generator><language>en-us</language><lastBuildDate>Sun, 02 Jul 2023 12:49:58 +0530</lastBuildDate><atom:link href="https://everything-cyber.netlify.app/tags/ubuntu/index.xml" rel="self" type="application/rss+xml"/><item><title>Splunk Enterprise with remote Hosts</title><link>https://everything-cyber.netlify.app/blog/splunk/</link><pubDate>Sun, 02 Jul 2023 12:49:58 +0530</pubDate><guid>https://everything-cyber.netlify.app/blog/splunk/</guid><description>Splunk Enterprise with remote Hosts Description This is a sample project to setup a Splunk SIEM lab and forward alerts and events from remote hosts to the splunk server for monitoring and analysing
Prerequisites - Virtual box - Ubuntu server iso for hosting our Splunk server - Windows machine (here using windows 7) - Splunk Enterprise Edition and Splunk forwarder (we can get a 14 day trial version from Splunk to use the enterprise edition) Setup - Create 2 VM in Virtual box with Bridged network adapter and enabling Promiscuous mode</description></item></channel></rss>