Splunk Ninja - Inside the Cloud Favorite

This website uses Adobe® Flash™ Player 9
Download Flash Now

If you are using Internet Explorer, you will need to restart your browser after installing Flash.
Adobe and Flash are registered trademarks of Adobe Systems incorporated. All rights reserved.

684 views • Uploaded June 24, 2008

Amazon's EC2 Command-Line Utilities: http://developer.amazonwebservices.com/connect/entry.jspa?externalID=351

Elasticfox Firefox Browser Plugin: http://developer.amazonwebservices.com/connect/entry.jspa?externalID=609

I use the Flock browser because its the best! Built on the Firefox 3 core, its just Firefox, how it should have been. http://flock.com

I have three "Elastic IP's". They are static IP's I can assign to any running instance.

Elasticfox makes it easy for me to see what ports I have open to the outside.

Rightscale's view of all images is great. They even have a pile of images you can use -- more than Amazon does!

Assigning one of my elastic IP's to this running (or starting) instance.

We'll fast forward a few hours and check out our results.

Launched my Splunk server, get ready for some dev goodness

Download Splunk Replay from SplunkBase our community of users: http://www.splunkbase.com/apps/All/Technologies/app:Splunk+Replay

I'm issuing a search in the same way I would do in the default Splunk UI

Map the src_ip field on the Y axis to see the attacker

Map "user" on the X access to plot the user name the hacker was entering in their attack

Press play and watch the attack be replayed for you. Very interesting way to visualize IT data, eh?

Grab the Splunk Globe application from SplunkBase: http://www.splunkbase.com/apps/All/Business_Intelligence/app:Splunk+Globe

All of the data that this application is plotting came from a search on the Splunk server, and it updates--In real time!

SSHing in to your instance from your browser is tres cool!

Bonus combo feature! - CloudStatus - Hyperic's service to monitor AWS

Download Splunk. It comes with a free license level: http://download.splunk.com

Comments Feed