Tool Path
Splunk
Turn a security question into a search. Learn events, fields and the SPL pipeline, then aggregate, correlate across log sources and reach an evidence-supported conclusion — hands-on, in the browser.
Curriculum
- 01Available
Splunk & the Search Pipeline
What Splunk is for, how it stores machine data as events with fields, and how a search reads left-to-right as a pipeline that narrows and transforms data.
- 02Available
Searching and Filtering
Cut millions of events down to the few that answer your question: keyword and field search, boolean logic, table and fields, sort and dedup.
- 03Available
Aggregating and Transforming
Turn events into answers: stats with count/values/dc, top and rare, eval for derived fields, and timechart to see a pattern over time.
- 04Available
Investigating with Splunk
Put it together: turn a question into a search, correlate across authentication, endpoint and network sources into one timeline, validate the hypothesis and avoid a misleading conclusion — then work a real investigation.