Splunk

Overview

Splunk is one of the leading SIEM solutions in the market. It allows users to collect, analyze, and correlate network and machine logs in real time. It uses SPL (Search Processing Language) to make the search effective.

2. Description

Almost the first thing we want to look into is the Fields pane (like many other SIEM tool). We want to get an idea of the data that are collected. Fields pane are located on the left side.

2.1 Filtering

2.2 Structuring

Resources

Splunk Official Doc