Splunk | Log Analysis | Adding Data | Searching / Querying | Incident Investigation | Dashboards & Reports | TryHackMe's Room Tasks
Splunk is one of the leading SIEM solutions in the market that provides the ability to collect, analyze and correlate the network and machine logs in real-time. It helps aggregate data from different data sources in the enterprise environment to help enhance security monitoring. Overview: In this project I will share how I used and learned Splunk during TryHackMe''s SOC L1 learning path. TryHackMe is a platform that provides hands-on Cybersecurity challenges and labs for learning and practicing various hacking and security-related skills. It's a legal and ethical platform designed for educational purposes, allowing users to develop their skills in a controlled environment. There were different rooms in which I performed many tasks utilizing Splunk such as how to ingest logs, analyze logs, querying data, how to perform investigation and creating dashboards Terminologies Used: Splunk Forwarder: Splunk Forwarder is a lightweight agent installed on the endpoint intended to b