Browser LabLD-SPL-LAB-001Easy
Browser LabLD-SPL-LAB-001Easy18 min
Filter to the Truth
An alert at Jisr Bank flags 'authentication anomalies' overnight. You are handed a slice of the auth sourcetype in Splunk. Millions of events, one question at a time: use field filters and boolean logic to isolate which account was actually taken over — not merely which had noise.
What you will be able to do
- Filter events on exact fields rather than loose keywords.
- Read a failed-then-succeeded pattern as account takeover.
- Distinguish a locked-out victim from a compromised one.
Log AnalysisSIEM OperationIncident TriageT1110 — Brute ForceT1078 — Valid Accounts
Sign in to start this lab.
Sign in