Travaux pratiques guidés sur 5 jours pour concevoir, déployer et opérer un SOC complet avec centralisation des journaux, détection d'intrusion et visualisation des incidents.
wget -O splunk-10.2.2-linux-amd64.deb "https://download.splunk.com/products/splunk/releases/10.2.2/linux/splunk-10.2.2-80b90d638de6-linux-amd64.deb"
wget -O splunkforwarder-10.2.2-linux-amd64.deb "https://download.splunk.com/products/universalforwarder/releases/10.2.2/linux/splunkforwarder-10.2.2-979a540794c5-linux-amd64.deb"
sudo /opt/splunk/bin/splunk statuscurl -s localhost:9200 | python3 -m json.tool | grep taglinesudo systemctl status logstashsudo systemctl status suricatasudo /var/ossec/bin/agent_control -ldf -h /sudo /opt/splunkforwarder/bin/splunk statussudo systemctl status rsyslogsudo fail2ban-client statussudo /var/ossec/bin/wazuh-control statussudo systemctl status apache2ip a | grep "inet 192"