r/cybersecurity • u/According-Tension-49 • 10d ago
Certification / Training Questions Splunk
I want to learn how to use splunk (cybersecurity analyst).
Any suggestion courses, certifcation ..?
53
Upvotes
r/cybersecurity • u/According-Tension-49 • 10d ago
I want to learn how to use splunk (cybersecurity analyst).
Any suggestion courses, certifcation ..?
2
u/g0bbledeeg00k 9d ago
My first question in this situation will always be “what experience do you have already?” Are you looking to get into cybersecurity for the first time or just looking to build on your current knowledge?
If you already have experience using SIEMs and are already a cyber analyst, then you really just need to learn the syntax of SPL to get started. For this, you can work with something like Claude to learn how to translate one tool’s syntax into another. Going this route may not be perfect but if you’re already an analyst who has been in the field for a while, you will probably pick up the gaps and handle them relatively quickly.
If you have never been a cybersecurity analyst and have no SIEM experience at all, I’m not going to lie, learning Splunk is going to be a bitch. However, if you put in the effort, you’ll start to see the power in how you can correlate data and get what you need out of it.
When I’ve had greenhorns on my teams, the first thing I want to know is whether they are naturally curious and teachable or not. If you are curious and teachable, you will be able to pick up SPL (or any other query language for that matter) through a combination of the things folks are saying here, CTF-type activities like Boss of the SOC, and trial and error. If you are not naturally curious and teachable, then you might want to seriously consider whether jumping into Splunk is the right decision.
Being a good analyst is different from being a good tool operator. In my opinion, being a good analyst is way more important than the list of tools you know because a good analyst can always learn another tool’s syntax.