
Splunk Series III: System Administrator Class (Splunk Components, Processes and Installation)
Splunk admin notes - search heads, indexers, forwarders, deployment server roles - and the planning steps required before a production install.
Posts

Splunk admin notes - search heads, indexers, forwarders, deployment server roles - and the planning steps required before a production install.

Splunk Certified Architect prep - System Admin class topics: license management, configuration files, indexers, user management, and distributed search.

Save, load, export, and revert PAN-OS configuration snapshots - use named configs to recover from a failed firewall or migrate settings to a replacement.

Configure destination NAT on Palo Alto - publish a DMZ FTP server with custom service objects, NAT rules, and the matching inbound security policy.

Configure admin roles on a Palo Alto firewall - create custom permissions, assign role-based admin accounts via GUI, then replicate the same in CLI.

Configure Palo Alto interfaces, zones, and management profiles - set up Layer 3 interfaces with static IPs and lock down which protocols answer in-band.

Build Palo Alto security policies and source NAT rules - use Tags to organize objects, apply rules across zones, and verify both in GUI and CLI.
VERIS framework breakdown for incident response: actors, actions, assets, and attributes (the 4As) used to classify security incidents in the VCDB dataset.

Correlate events in Splunk using transactions - group related events with maxspan, maxpause, startswith, endswith - and when to use stats instead.

Filter and format Splunk data with eval, search, and where commands - calculate field values, apply conditional logic, and clean up report output.