To access material, start machines and answer questions login.
Welcome to this hands-on challenge room. In this scenario, you've just completed your third screening interview for a Level 2 role at Cybertees Ltd, and you're now faced with the final assessment to test your knowledge. You'll be given access to a Splunk instance receiving network logs from an unknown source. The data isn't arriving in a usable state, so before you can analyze what's happening on the network, you must Fixit!
Objectives
This challenge is divided into three phases
- Fix event boundaries for the incoming logs
- Extract custom fields from the available events
- Analyze event data to uncover network activity
Prerequisites
This challenge is based on the knowledge covered in the following rooms
- Check out Regular Expressions to get familiar with pattern matching
- Cover Splunk: Exploring for an overview of Splunk queries
- Explore Splunk: Data Manipulation to learn event parsing and field extraction
Lab Access
Click the Start Lab Machine button below to start the lab. Please give Splunk five minutes to load and access the UI at http://MACHINE_IP:8000. Splunk is installed in the default /opt directory, and you will be working with the Fixit app.
If Splunk stops responding at any point, run /opt/splunk/bin/splunk restart as root and wait for a few minutes.
Set up your virtual environment
I understand the challenge and am ready to Fixit!
Ready to learn Cyber Security?
The Fixit room is only available for Premium or Max subscribers. Signup now to access more than 500 free rooms and learn cyber security through a fun, interactive learning environment.
Already have an account? Log in

