<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: datasets/logs in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-can-I-get-datasets-logs-for-monitoring-and-analysis/m-p/659779#M111578</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/261242"&gt;@kattey&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;how much do you know Splunk?&lt;/P&gt;&lt;P&gt;if you start from scratch you need to learn hot to ingest data in Splunk and how to search on Splunk.&lt;/P&gt;&lt;P&gt;Data sources com from you infrastructure, if you haven't, you could use an automatic generator, but it isn't another stack to learn!&lt;/P&gt;&lt;P&gt;Best way, is to search in Community answers about basic learning (e.g. Search Tutorial) and getting data in.&lt;/P&gt;&lt;P&gt;Then you should define a perimeter to identify the data sources to ingest.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
    <pubDate>Thu, 05 Oct 2023 12:37:51 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2023-10-05T12:37:51Z</dc:date>
    <item>
      <title>How can I get datasets/logs for monitoring and analysis?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-I-get-datasets-logs-for-monitoring-and-analysis/m-p/659774#M111576</link>
      <description>&lt;P&gt;Hello, good day&lt;BR /&gt;I am very new to Splunk, i and my team want to work on a mini project using splunk cloud with the topic "Splunk Enterprise: An organization's go-to in detecting cyberthreats"&lt;BR /&gt;how/where can i easily get datasets/logs that i can use in splunk for monitoring and analysis.&amp;nbsp; and what best way should we go about this topic?&lt;/P&gt;</description>
      <pubDate>Thu, 05 Oct 2023 15:31:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-I-get-datasets-logs-for-monitoring-and-analysis/m-p/659774#M111576</guid>
      <dc:creator>kattey</dc:creator>
      <dc:date>2023-10-05T15:31:27Z</dc:date>
    </item>
    <item>
      <title>Re: datasets/logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-I-get-datasets-logs-for-monitoring-and-analysis/m-p/659778#M111577</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/261242"&gt;@kattey&lt;/a&gt;&amp;nbsp;... please check these things:&lt;/P&gt;&lt;P&gt;1) As i heard, the Splunk Essentials app got some sample data.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://splunkbase.splunk.com/app/3435" target="_blank" rel="nofollow noopener noreferrer"&gt;https://splunkbase.splunk.com/app/3435&lt;/A&gt;&lt;/P&gt;&lt;P&gt;2) and then you can find some sample data in this repo:&lt;/P&gt;&lt;P&gt;&lt;A href="https://github.com/splunk/botsv3" target="_blank" rel="nofollow noopener noreferrer"&gt;https://github.com/splunk/botsv3&lt;/A&gt;&lt;/P&gt;&lt;P&gt;3) and then, there is an app.. EventGen. very difficult to configure and very worst documentation. i would suggest this as last resort. thanks.&amp;nbsp;&lt;/P&gt;&lt;P class=""&gt;4) Splunk Datasets Add-On: This Splunk add-on provides a variety of sample data sets, including security logs, for you to work with. You can download and install the add-on directly from Splunkbase:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A class="" href="https://splunkbase.splunk.com/app/3245/" target="_blank" rel="noopener nofollow ugc"&gt;https://splunkbase.splunk.com/app/3245/&lt;/A&gt;&lt;/P&gt;&lt;P class=""&gt;5) Boss of the SOC (BOTS) datasets: You've already mentioned BOTS v1-3, but don't forget about BOTS v4, which was released later. You can find it here:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A class="" href="https://github.com/splunk/botsv4" target="_blank" rel="noopener nofollow ugc"&gt;https://github.com/splunk/botsv4&lt;/A&gt;&lt;/P&gt;&lt;P class=""&gt;6) Elastic Common Data Model (ECS) sample data: Although intended for the Elastic Stack, you can adapt these sample logs for use in Splunk. The repository contains logs from various sources, such as network traffic, security events, and web server logs:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A class="" href="https://github.com/elastic/ecs/tree/master/generated/samples" target="_blank" rel="noopener nofollow ugc"&gt;https://github.com/elastic/ecs/tree/master/generated/samples&lt;/A&gt;&lt;/P&gt;&lt;P class=""&gt;6) Sample Log Generator: This tool generates synthetic logs that you can customize to fit your needs. While not real-world data, it can be useful for testing specific scenarios or queries:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A class="" href="https://github.com/ErikEJ/SqlQueryStress" target="_blank" rel="noopener nofollow ugc"&gt;https://github.com/ErikEJ/SqlQueryStress&lt;/A&gt;&lt;/P&gt;&lt;P class=""&gt;7) NIST National Vulnerability Database (NVD) data feeds: NVD provides various data feeds containing vulnerability information. While not logs per se, this data can be useful for exploring security-related data in Splunk:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A class="" href="https://nvd.nist.gov/vuln/data-feeds" target="_blank" rel="noopener nofollow ugc"&gt;https://nvd.nist.gov/vuln/data-feeds&lt;/A&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;span class="lia-unicode-emoji" title=":smiling_face_with_sunglasses:"&gt;😎&lt;/span&gt; SecRepo: You've already mentioned this repository, but I'd like to emphasize its value as it contains various sample logs from different sources:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A class="" href="http://www.secrepo.com/" target="_blank" rel="noopener nofollow ugc"&gt;http://www.secrepo.com/&amp;nbsp;&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;9)&amp;nbsp;&lt;A href="https://github.com/gfek/Real-CyberSecurity-Datasets" target="_blank"&gt;https://github.com/gfek/Real-CyberSecurity-Datasets&lt;/A&gt;&lt;/P&gt;&lt;P class=""&gt;10)&amp;nbsp;&lt;A href="https://github.com/shramos/Awesome-Cybersecurity-Datasets" target="_blank"&gt;https://github.com/shramos/Awesome-Cybersecurity-Datasets&lt;/A&gt;&lt;/P&gt;&lt;P class=""&gt;11)&amp;nbsp;&lt;A href="https://www.secrepo.com/" target="_blank"&gt;https://www.secrepo.com/&lt;/A&gt;&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;&lt;P class=""&gt;hope this helps you and other splunkers.. thanks. karma / upvotes appreciated by all, thanks.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 05 Oct 2023 12:37:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-I-get-datasets-logs-for-monitoring-and-analysis/m-p/659778#M111577</guid>
      <dc:creator>inventsekar</dc:creator>
      <dc:date>2023-10-05T12:37:36Z</dc:date>
    </item>
    <item>
      <title>Re: datasets/logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-I-get-datasets-logs-for-monitoring-and-analysis/m-p/659779#M111578</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/261242"&gt;@kattey&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;how much do you know Splunk?&lt;/P&gt;&lt;P&gt;if you start from scratch you need to learn hot to ingest data in Splunk and how to search on Splunk.&lt;/P&gt;&lt;P&gt;Data sources com from you infrastructure, if you haven't, you could use an automatic generator, but it isn't another stack to learn!&lt;/P&gt;&lt;P&gt;Best way, is to search in Community answers about basic learning (e.g. Search Tutorial) and getting data in.&lt;/P&gt;&lt;P&gt;Then you should define a perimeter to identify the data sources to ingest.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 05 Oct 2023 12:37:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-I-get-datasets-logs-for-monitoring-and-analysis/m-p/659779#M111578</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-10-05T12:37:51Z</dc:date>
    </item>
  </channel>
</rss>

