Midnight theme

Midnight is a theme for GitHub Pages.


Project maintained by GiBoris Hosted on GitHub Pages — Theme by mattgraham

Splunk Fundamentals Lab (Search, Analysis, Dashboards & Alerting)

This lab documents hands-on Splunk fundamentals completed as part of self-directed cybersecurity training and SOC-focused practice.

The purpose of this lab is to demonstrate understanding of SIEM fundamentals and hands-on ability to:


Lab Environment

Hypervisor

Virtual Machines

Software

Datasets


Objectives

This lab demonstrates the ability to:

  1. Install and validate Splunk Enterprise;
  2. Upload and search log data;
  3. Use SPL for analysis and aggregation;
  4. Extract fields from raw log events;
  5. Perform DNS investigation workflows;
  6. Create dashboards and alerts based on security logic.

Lab Tasks and Implementation

1. Splunk Enterprise Installation


2. Data Upload (BOTSv3 Dataset)

Data Upload


3. SPL Fundamentals & Initial Analysis

SPL


4. DNS Log Analysis & Field Extraction

4.1 Field Extraction

Extracted meaningful fields from DNS logs to support investigations:

Field Extraction

4.2 Top Queried Domains

Identified 20 most frequently queried domains.

Domains

4.3 Suspicious Domain Investigation

Investigation

5. Alert Creation (Processes Executed Before 8AM)

Created an alert to detect processes launched outside normal business hours.

Alert

6. Reporting & Dashboard

Built reports and dashboards to monitor VPN activity and authentication results.

Dashboard

Key Skills Demonstrated


Disclaimer

All systems and data used in this lab are non-production, isolated, and for educational purposes only. No real user data or sensitive information was used.