Hello everyone, I'm working on a project ''Splunk Enterprise: An organization's go-to in detecting cyber threats'' please how/where can I get datasets and logs that I will use for my project.
Hello @nina, There are a few ways -
- If you are planning to showcase some use cases as a part of Project - Splunk Security Essentials (https://splunkbase.splunk.com/app/3435) does have some built-in datasets. For example for Sample Brute Force Attack Detection
- https://github.com/splunk/botsv3 does have a number of sample datasets for multiple sourcetypes
- You can use EventGen (https://splunkbase.splunk.com/app/1924) to generate "more" events based on existing event formats.
Please accept the solution and hit Karma, if this helps!
hello, thankyou so much for responding. even though i am entirely new to splunk and trying to find my way with youre recommendation, they are very useful.
Hi @nina ... to learn regex/rex, i have made lot of videos.. pls check it.. thanks.
Splunk newbie learning videos, for absolute beginners:
https://www.youtube.com/@SiemNewbies101/playlists
Hello @nina, There are a few ways -
- If you are planning to showcase some use cases as a part of Project - Splunk Security Essentials (https://splunkbase.splunk.com/app/3435) does have some built-in datasets. For example for Sample Brute Force Attack Detection
- https://github.com/splunk/botsv3 does have a number of sample datasets for multiple sourcetypes
- You can use EventGen (https://splunkbase.splunk.com/app/1924) to generate "more" events based on existing event formats.
Please accept the solution and hit Karma, if this helps!