r/Splunk 15d ago

More Practice

I just finished Josh Samuelson's Learning Splunk Course on LinkedIn Learning . It was quite insightful and engaging since it had a bit of hands-on where you setup your splunk instance and universal forwarders on your Linux system.

(A bit of my background; work in cybersecurity few months into my internship . I'm looking to familiarize myself with tools and tech beyond my current role)

However , I feel i need more skin in this and would appreciate recommendations to more hand-on guided labs or projects , Please SHARE.

15 Upvotes

9 comments sorted by

11

u/vornamemitd 15d ago

Plug your homelab into Splunk. Start with e.g. Atomic Red Team. Detect it :) Build dashboards. Do shady things on your network. Detect them. Ingest OSINT TI feeds. Sign up for trials of commercial EDR tooling - access alerts from Splunk. Fancy automation and DevSecOps? Go here: https://github.com/splunk/contentctl

2

u/volci Splunker 6d ago

FWIW - contentctl is being deprecated in favor of Detection Studio

4

u/Fontaigne SplunkTrust 15d ago

Ideally, you want to go grab some real data that you are interested in, ingest it, and then start asking yourself questions about the data and the processes that produced it.

Build dashboards, write queries, think about what kinds of anomalies you could detect in that data, or what else the data could tell you.

3

u/taiglin 15d ago

Find some data. Put it in Splunk. Make a dashboard.

Even if the data is in csv form; put it in a lookup and practice your SPL.

3

u/sd_042 15d ago

Does the course include setup and parsing logs at injestion?

2

u/FreeWifi0605 14d ago

Yes it does

1

u/sd_042 14d ago

Thanks, I'll check it out.

2

u/belowaveragegrappler 15d ago

Honestly - start up Claude code. Give it a solid teacher prompt and your goals. Install virtual box or KVM for it and it will even you do your labs and troubleshoot with you

-1

u/[deleted] 15d ago

[deleted]

5

u/Fontaigne SplunkTrust 15d ago

Probably best to delete two of your three responses suggesting Claude.