Skip to main content

Introduction

Splunk is a powerful tool for collecting and analyzing machine data. At Penn, Splunk is a critical component of the Security Logging Service. To learn more about how Splunk can be used to understand system events, visit Splunk's website on machine data. Access to Penn's Splunk service is restricted to authorized IT and departmental staff.

Getting Started

The first step to using Splunk to analyze your servers' activity is to work with the ISC Splunk team to configure the connections between your system and the Splunk server.

Submit a request via help@isc to send the following information to the Splunk Support team:

  • The number of hosts you'd like to have submit logs.
  • The operating systems your hosts are running.
  • The file system, network and application logs you'd like to send to the Service.
  • The approximate daily volume of log data you anticipate sending to the Service.

Help Using Splunk

The following contact methods are available to get help in using Splunk at Penn:

Additional resources from the vendor:

Documentation

Documentation is available at these external resources:

Security Logging Q&A Session

A monthly Security Logging Q&A session is held on the second Thursday of the month. The session is a dedicated opportunity to speak to the Office of Information Security (OIS) about the security logging capabilities of ISC's Data Analytics Service, and security logging in general. In each session, OIS will answer your questions and help you work through your use cases. 

Location: Virtual via MS TEAMS

Time: 1:30 PM - 3:00 PM

Date: Every second Thursday of the month 

Registration: Please contact security@isc.upenn.edu to request an invitation to the Security Logging Q&A sessions.