Getting Data In

getting datasets

nina
Engager

Hello everyone, I'm working on a project ''Splunk Enterprise: An organization's go-to in detecting cyber threats''  please how/where can I get datasets and logs that I will use for my project.

Labels (1)
0 Karma
1 Solution

meetmshah
Builder

Hello @nina, There are a few ways - 

 - If you are planning to showcase some use cases as a part of Project - Splunk Security Essentials (https://splunkbase.splunk.com/app/3435) does have some built-in datasets. For example for Sample Brute Force Attack Detection

https://github.com/splunk/botsv3 does have a number of sample datasets for multiple sourcetypes

- You can use EventGen (https://splunkbase.splunk.com/app/1924) to generate "more" events based on existing event formats.

 

Please accept the solution and hit Karma, if this helps!

View solution in original post

nina
Engager

hello, thankyou so much for responding. even though i am entirely new to splunk and trying to find my way with youre recommendation, they are very useful.

0 Karma

inventsekar
SplunkTrust
SplunkTrust

Hi @nina ... to learn regex/rex, i have made lot of videos.. pls check it.. thanks. 

Splunk newbie learning videos, for absolute beginners:
https://www.youtube.com/@SiemNewbies101/playlists

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !
0 Karma

meetmshah
Builder

Hello @nina, There are a few ways - 

 - If you are planning to showcase some use cases as a part of Project - Splunk Security Essentials (https://splunkbase.splunk.com/app/3435) does have some built-in datasets. For example for Sample Brute Force Attack Detection

https://github.com/splunk/botsv3 does have a number of sample datasets for multiple sourcetypes

- You can use EventGen (https://splunkbase.splunk.com/app/1924) to generate "more" events based on existing event formats.

 

Please accept the solution and hit Karma, if this helps!

Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...