SPL for SOC Analysts
Master Splunk Search Processing Language (SPL) to enhance your SOC analyst skills, enabling effective security investigations, threat hunting, and incident response.
...
Share
Introduction to SPL and Basic Event Retrieval
Unit 1: SPL Fundamentals
What is SPL?
SPL Syntax: The Basics
Your First SPL Search
Keywords are Key
Time Modifiers
Unit 2: Navigating the Splunk Interface
Splunk's UI: A Tour
Setting the Time Range
Search Job Inspector
Saving Your Searches
Exporting Results
Unit 3: Index-Specific Searches
What are Indexes?
Targeting Specific Indexes
Source Types
Hosts
Combining Index Filters
Filtering and Transforming Data with SPL
Unit 1: Filtering with SPL: `search` and `where`
Intro to SPL Filtering
The `search` Command
The `where` Command
`search` vs. `where`
Filtering Best Practices
Unit 2: Transforming Data: `dedup`, `sort`, and `head`
Intro to Transformations
Removing Duplicates
Sorting Events
Limiting Results
Transformation Chains
Unit 3: Extracting and Formatting Fields: `rex` and `eval`
Intro to Field Extraction
Regex Field Extractions
Calculated Fields
Formatting Field Values
Rex and Eval Best Practices
Statistical Analysis, Reporting, and Lookups with SPL
Unit 1: Statistical Analysis with SPL
Intro to Stats Command
Advanced Stats Functions
Time-Based Stats
Charting Basics
Advanced Charting
Unit 2: Reporting and Visualizations
Creating Basic Reports
Dashboards 101
Dashboard Drilldowns
Alerting Basics
Custom Alert Actions
Unit 3: Lookups for Data Enrichment
Lookup Basics
External Lookups
Lookup Best Practices
Automatic Lookups
Lookup Use Cases
Event Correlation, Alerting, and Optimization
Unit 1: Event Correlation with SPL
Intro to Event Correlation
Correlating by User ID
Correlating by IP Address
Correlating by Hostname
Using the `transaction` Command
Unit 2: Alerting with SPL
Intro to Alerting
Creating Basic Alerts
Alerting on Thresholds
Scheduled Reports as Alerts
Custom Alert Actions
Unit 3: SPL Optimization
Intro to SPL Optimization
Using Indexes Effectively
Filtering Early
Efficient Commands
Subsearches
Investigating Security Incidents and Threat Hunting with SPL
Unit 1: Investigating Malware Infections with SPL
Malware Investigation
Endpoint Log Analysis
Network Traffic Analysis
Detecting Lateral Movement
Containment Strategies
Unit 2: Investigating Phishing Attacks with SPL
Phishing Overview
Email Header Analysis
URL Analysis
User Behavior Analysis
Phishing Prevention
Unit 3: Threat Hunting with SPL
Threat Hunting Intro
IOC Sweeping
Anomaly Detection
Behavioral Analysis
Hunting Automation