New Job-Role Training Path: Active Directory Penetration Tester! Learn More

mostowskie

Earned a new badge!

Badge Icon

SPL Witchcraft

For completing the Understanding Log Sources & Investigating with Splunk module

3073

Users earned this badge

0.18%

Users have this badge

Completed on 12 Mar 2024

Understanding Log Sources & Investigating with Splunk

This module provides a comprehensive introduction to Splunk, focusing on its architecture and the creation of effective detection-related SPL (Search Processing Language) searches. We will learn to investigate with Splunk as a SIEM tool and develop TTP-driven and analytics-driven SPL searches for enhanced threat detection and response. Through hands-on exercises, we will learn to identify and understand the ingested data and available fields within Splunk. We will also gain practical experience in leveraging Splunk's powerful features for security monitoring and incident investigation.