The SIEM skills line on more job ads than any other tool. Splunk Free (500MB/day) in your home lab = real, list-able SOC experience.
Follow the steps β click any step card to replay the terminal demo from that point. Everything runs in a lab you control.
SPL is a pipeline: search β transform β table. Start inside its own logs.
stats is your daily driver: count/rare/top by field.
4625 = failed Windows login. 4624 = success. Security gold.
You're now doing detection engineering, in the GUI, for free.
The legendary free dataset: real Splunk IR practice recruiters recognize.
| index= | which dataset |
| | stats count by x | group/aggr |
| | top / rare | frequency |
| EventCode=4625 | failed Windows logon |
| earliest=-1h | time window |
| | table a b c | clean output |
Learn 10 SPL verbs (stats, table, rex, eval, where, sort, dedupβ¦) β everything else compounds.
Splunk Fundamentals 1 course is officially free β certificate for your profile.
Sysmon + SwiftOnSecurity config into Splunk = pro-grade home telemetry.
Alerts -> notable events -> SOAR is the exact job workflow; mimic it.
Use Splunk (Free) only on systems you own or have written permission to test. Your lab: Kali + Metasploitable2, DVWA, TryHackMe & HackTheBox β plenty of legal targets, zero risk.