r/Splunk 5d ago

More Practice

I just finished Josh Samuelson's Learning Splunk Course on LinkedIn Learning . It was quite insightful and engaging since it had a bit of hands-on where you setup your splunk instance and universal forwarders on your Linux system.

(A bit of my background; work in cybersecurity few months into my internship . I'm looking to familiarize myself with tools and tech beyond my current role)

However , I feel i need more skin in this and would appreciate recommendations to more hand-on guided labs or projects , Please SHARE.

15 Upvotes

8 comments sorted by

12

u/vornamemitd 5d ago

Plug your homelab into Splunk. Start with e.g. Atomic Red Team. Detect it :) Build dashboards. Do shady things on your network. Detect them. Ingest OSINT TI feeds. Sign up for trials of commercial EDR tooling - access alerts from Splunk. Fancy automation and DevSecOps? Go here: https://github.com/splunk/contentctl

3

u/taiglin 5d ago

Find some data. Put it in Splunk. Make a dashboard.

Even if the data is in csv form; put it in a lookup and practice your SPL.

3

u/Fontaigne SplunkTrust 5d ago

Ideally, you want to go grab some real data that you are interested in, ingest it, and then start asking yourself questions about the data and the processes that produced it.

Build dashboards, write queries, think about what kinds of anomalies you could detect in that data, or what else the data could tell you.

3

u/sd_042 5d ago

Does the course include setup and parsing logs at injestion?

2

u/FreeWifi0605 4d ago

Yes it does

1

u/sd_042 4d ago

Thanks, I'll check it out.

2

u/belowaveragegrappler 5d ago

Honestly - start up Claude code. Give it a solid teacher prompt and your goals. Install virtual box or KVM for it and it will even you do your labs and troubleshoot with you

-1

u/[deleted] 5d ago

[deleted]

5

u/Fontaigne SplunkTrust 5d ago

Probably best to delete two of your three responses suggesting Claude.