To access material, start machines and answer questions login.
Welcome to this hands-on challenge room. In this scenario, you've just completed your third screening interview for a Level 2 role at MSSP Cybertees Ltd, and you're now faced with the final assessment to test your knowledge. You'll be given access to a instance receiving network logs from an unknown source. The data isn't arriving in a usable state, so before you can analyze what's happening on the network, you must Fixit!
Objectives
This challenge is divided into three phases
- Fix event boundaries for the incoming logs
- Extract custom fields from the available events
- Analyze event data to uncover network activity
Prerequisites
This challenge is based on the knowledge covered in the following rooms
- Check out Regular Expressions to get familiar with pattern matching
- Cover : Exploring for an overview of queries
- Explore : Data Manipulation to learn event parsing and field extraction
Lab Access
Click the Start Machine button below to start the lab. Please give five minutes to load and access the UI at http://MACHINE_IP:8000. Splunk is installed in the default /opt directory, and you will be working with the Fixit app.
If stops responding at any point, run /opt/splunk/bin/splunk restart as root and wait for a few minutes.
Set up your virtual environment
I understand the challenge and am ready to Fixit!
Ready to learn Cyber Security?
The Fixit room is only available for premium users. Signup now to access more than 500 free rooms and learn cyber security through a fun, interactive learning environment.
Already have an account? Log in
