home/toolvault/soc & defense/splunk-free

Splunk (Free) //

SOC & Defensesiem

The SIEM skills line on more job ads than any other tool. Splunk Free (500MB/day) in your home lab = real, list-able SOC experience.

difficulty Β· intermediate
30 min
time to first win
5
guided steps
0
students started here*

HOW TO USE SPLUNK

Follow the steps β€” click any step card to replay the terminal demo from that point. Everything runs in a lab you control.

splunk-free β€” guided lab session
static view
step 01

Install & first search

index=_internal | top sourcetype

SPL is a pipeline: search β†’ transform β†’ table. Start inside its own logs.

step 02

Find the errors

index=* error | stats count by host

stats is your daily driver: count/rare/top by field.

step 03

Decode a field-heavy log

index=wineventlog EventCode=4625 | stats count by user, src_ip

4625 = failed Windows login. 4624 = success. Security gold.

step 04

Build an alert

search β†’ Save As β†’ Alert (cron 5 min)

You're now doing detection engineering, in the GUI, for free.

step 05

Boss of the SOC

import BOTS dataset v3 β†’ investigate

The legendary free dataset: real Splunk IR practice recruiters recognize.

THE WORKFLOW AT A GLANCE

πŸ“₯
Ingest
logs/forwarders
πŸ”
SPL
search pipes
πŸ“Š
stats
patterns emerge
🚨
Alert
detections live
πŸ§‘β€πŸ’»
Triage
analyst workflow
LEARNING CURVE
intermediate β€” 30 min to first win

FLAGS & SUPER-MOVES

index=which dataset
| stats count by xgroup/aggr
| top / rarefrequency
EventCode=4625failed Windows logon
earliest=-1htime window
| table a b cclean output

PRO TIPS

01

Learn 10 SPL verbs (stats, table, rex, eval, where, sort, dedup…) β€” everything else compounds.

Learn 10 SPL verbs (stats, table, rex, eval, where, sort, dedup…) β€” everything else compounds.

02

Splunk Fundamentals 1 course is officially free β€” certificate for your profile.

Splunk Fundamentals 1 course is officially free β€” certificate for your profile.

03

Sysmon + SwiftOnSecurity config into Splunk = pro-grade home telemetry.

Sysmon + SwiftOnSecurity config into Splunk = pro-grade home telemetry.

04

Alerts -> notable events -> SOAR is the exact job workflow; mimic it.

Alerts -> notable events -> SOAR is the exact job workflow; mimic it.

βš–οΈ

Golden rule

Use Splunk (Free) only on systems you own or have written permission to test. Your lab: Kali + Metasploitable2, DVWA, TryHackMe & HackTheBox β€” plenty of legal targets, zero risk.

KEEP DIGGING

CYBER//ZERO ToolVault
Animated deep-dives on every tool in the guide.
✍️ Author LDM · ldmhub4u@gmail.com
full guide v1 Β· v2 immersive Β· latest news
Made for learners, everywhere Β· 2026
*plausibly. verify commands with official docs.