Skip to main content

Preview build: sign-in and grading run on the server. MFA is not enabled, and storage is in server memory so it does not survive a restart.

LearnDefend
Browser LabLD-SPL-LAB-001Easy
Browser LabLD-SPL-LAB-001Easy18 min

Filter to the Truth

An alert at Jisr Bank flags 'authentication anomalies' overnight. You are handed a slice of the auth sourcetype in Splunk. Millions of events, one question at a time: use field filters and boolean logic to isolate which account was actually taken over — not merely which had noise.

What you will be able to do

  • Filter events on exact fields rather than loose keywords.
  • Read a failed-then-succeeded pattern as account takeover.
  • Distinguish a locked-out victim from a compromised one.
Log AnalysisSIEM OperationIncident TriageT1110Brute ForceT1078Valid Accounts

Sign in to start this lab.

Sign in