Skip to main content

Understand advanced Splunk capabilities to search data for anomalies by creating complex search queries, applying regex, and creating presentable reports and dashboards.

In this module, we will install a Splunk instance and set up a forwarder to ingest logs from different log sources. We will learn how to create complex search queries and use regex to parse logs to improve incident investigation and threat hunting capabilities. Additionally, we will learn how to create presentable reports and dashboards to assist with the analysis.

What are modules?

A learning pathway is made up of modules, and a module is made of bite-sized rooms (think of a room like a mini security lab).

Hierarchical diagram showing how learning pathways contain modules, which contain individual rooms.