Skip to main content

Preview build: sign-in and grading run on the server. MFA is not enabled, and storage is in server memory so it does not survive a restart.

LearnDefend

Tool Path

Splunk

Turn a security question into a search. Learn events, fields and the SPL pipeline, then aggregate, correlate across log sources and reach an evidence-supported conclusion — hands-on, in the browser.

BeginnerLog AnalysisSIEM Operation

Curriculum

  1. 01

    Splunk & the Search Pipeline

    What Splunk is for, how it stores machine data as events with fields, and how a search reads left-to-right as a pipeline that narrows and transforms data.

    Available
  2. 02

    Searching and Filtering

    Cut millions of events down to the few that answer your question: keyword and field search, boolean logic, table and fields, sort and dedup.

    Available
  3. 03

    Aggregating and Transforming

    Turn events into answers: stats with count/values/dc, top and rare, eval for derived fields, and timechart to see a pattern over time.

    Available
  4. 04

    Investigating with Splunk

    Put it together: turn a question into a search, correlate across authentication, endpoint and network sources into one timeline, validate the hypothesis and avoid a misleading conclusion — then work a real investigation.

    Available

Related learning

SOC Analyst L1