What you need for this tutorial
You need to create a Splunk.com account, access the free Trial version of the Splunk software, and download the tutorial data files. There might be other prerequisites, depending on which Splunk platform you use.
Create a splunk.com account
You need a splunk.com account to download the free Trial version of the Splunk software. Creating an account is free. If you do not already have a Splunk.com account, you need to create an account. If you already have an account, you need to log in to that account.
- In a separate browser window, go to https://www.splunk.com/.
- Use CTRL+click on the link to open the web site in a new browser tab.
- By using a separate browser tab, you can keep this tab open with the Search Tutorial instructions. You can switch back and forth between the browser tabs.
- In the upper right corner of the window, click the Splunk Account icon .
If you are already logged in, your name appears next to the icon.
- To create an account, click Sign Up and complete the registration information.
- To log in to an existing account, click Login.
Choose a platform
You can use this tutorial with a Trial version of Splunk Cloud Platform or Splunk Enterprise. The main difference in the Trial versions is the length of the license.
- Splunk Cloud Platform
- When you start a Splunk Cloud Platform Trial, you have access to Splunk Cloud Platform for 15 days. The Trial license includes all of the features in Splunk Cloud Platform, and access to select premium applications and add-ons. You can index up to 5GB of data each day.
- After 15 days, the access to your Splunk Cloud Platform Trial expires.
- Splunk Enterprise
- When you download Splunk Enterprise for the first time, you get a Splunk Enterprise Trial license for 60 days. This trial license includes all of the features in Splunk Enterprise, and access to all premium applications and add-ons. You can index up to 500MB of data each day.
- After 60 days, the Enterprise Trial license converts to a perpetual Free license and some of the features, such as user preferences, authentication, and alerting are disabled. The Free license also includes the 500MB daily indexing volume, but there is no expiration date. See About Splunk Free in the Admin manual.
System requirements
Ensure that your computer meets the system requirements for your chosen platform.
Splunk Cloud Platform
- You must have a web browser. The latest versions of Chrome, Firefox, and Safari browsers are supported with Splunk Cloud Platform.
Splunk Enterprise
- You can use Splunk Enterprise on Linux, Windows, or macOS (10.14 and 10.15 only). For this tutorial, your computer must meet the specifications listed in the following table.
Requirement Minimum supported hardware capacity Non-Windows platforms 2-core 64-bit CPU at 2GHz or greater, 4GB RAM Windows platforms 2-core 64-bit CPU at 2GHz or greater, 4GB RAM Web browser The latest versions of Chrome, Firefox, and Safari browsers are supported.
Download the tutorial data files
This tutorial uses a fictitious game store, called Buttercup Games, that sells games and related items in an online store.
You must download several data files to use with the tutorial. The data files contain web access log files, secure formatted log files, sales log files, and a price list in a CSV file.
If you use the Safari browser, under Preferences > General, ensure that the Open "safe" files after downloading
option is unchecked. The tutorialdata.zip
file must be compressed to upload the file successfully.
- Download the
tutorialdata.zip
file. Do not uncompress the file. - Download the
Prices.csv.zip
file. Do not uncompress the file at this time.
Access the Trial version of the Splunk software
For this tutorial, use the latest version of the software.
If you downloaded the Splunk Enterprise Trial software previously, download the Trial software again. It is possible that your Splunk Enterprise Trial license converted to a Free license. The Free license has some limitations that will not allow you to complete all parts of this tutorial.
- Go back to the tab in your browser for the Splunk web site, https://www.splunk.com/.
- In the upper right corner of the window, click Free Splunk.
- Choose the platform you want to use and click on the link to download the Trial software.
Splunk Cloud Platform
- Confirm that you are not a robot.
- Click Start Trial.
- A confirmation page appears stating "Your Splunk Cloud Platform Trial is Ready!". Click View My Instance.
You will also receive an email with the URL to your Splunk Cloud Platform Trial and other useful information.
- Accept the Terms of Service. Splunk Cloud Platform should open in a browser window.
- See Next step.
Splunk Enterprise
- Identify the installer that you want to use with the tutorial.
Operating system For this tutorial Available installers Windows Use the MSI file graphical installer that is appropriate for your computer. 2 installers. An MSI file for 64-bit and an MSI file for 32-bit. Linux Use the file that is appropriate for your Linux distribution. 3 installers. A RPM package, a DEB package, and a compressed TAR (.tgz) file. macOS Use the DMG packaged graphical installer. Support for MacOS is deprecated. You can install Splunk Enterprise only on versions 10.14 or 10.15.
2 installers. A compressed TAR (.tgz) file installer and a DMG package. - Click Download Now next to that installer.
- See Next step.
Next step
The next step depends on the Splunk platform that you are using.
Splunk Cloud Platform
- Splunk Web should launch automatically. The email you receive about your Splunk Cloud Platform Trial contains the username and password that you can use to access Splunk Cloud Platform. The default username is
sc_admin
.
- If you see a window welcoming you to the Splunk Cloud Platform Trial and inviting you to Drop your data file here, close that window. You will upload the tutorial data In Part 2. For now, go to Navigating Splunk Web.
Splunk Enterprise
- You must install Splunk Enterprise.
See also
System Requirements in the Installation Manual
Types of Splunk licenses in the Admin Manual
About the Search Tutorial | Install Splunk Enterprise |
This documentation applies to the following versions of Splunk® Enterprise: 8.2.0, 8.2.1, 8.2.2, 8.2.3, 8.2.4, 8.2.5, 8.2.6, 8.2.7, 8.2.8, 8.2.9, 8.2.10, 8.2.11, 8.2.12, 9.0.0, 9.0.1, 9.0.2, 9.0.3, 9.0.4, 9.0.5, 9.0.6, 9.0.7, 9.0.8, 9.0.9, 9.0.10, 9.1.0, 9.1.1, 9.1.2, 9.1.3, 9.1.4, 9.1.5, 9.1.6, 9.1.7, 9.2.0, 9.2.1, 9.2.2, 9.2.3, 9.2.4, 9.3.0, 9.3.1, 9.3.2, 9.4.0
Feedback submitted, thanks!