Getting Data In

getting datasets

nina
Engager

Hello everyone, I'm working on a project ''Splunk Enterprise: An organization's go-to in detecting cyber threats''  please how/where can I get datasets and logs that I will use for my project.

Labels (1)
0 Karma
1 Solution

meetmshah
SplunkTrust
SplunkTrust

Hello @nina, There are a few ways - 

 - If you are planning to showcase some use cases as a part of Project - Splunk Security Essentials (https://splunkbase.splunk.com/app/3435) does have some built-in datasets. For example for Sample Brute Force Attack Detection

https://github.com/splunk/botsv3 does have a number of sample datasets for multiple sourcetypes

- You can use EventGen (https://splunkbase.splunk.com/app/1924) to generate "more" events based on existing event formats.

 

Please accept the solution and hit Karma, if this helps!

View solution in original post

nina
Engager

hello, thankyou so much for responding. even though i am entirely new to splunk and trying to find my way with youre recommendation, they are very useful.

0 Karma

inventsekar
SplunkTrust
SplunkTrust

Hi @nina ... to learn regex/rex, i have made lot of videos.. pls check it.. thanks. 

Splunk newbie learning videos, for absolute beginners:
https://www.youtube.com/@SiemNewbies101/playlists

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !
0 Karma

meetmshah
SplunkTrust
SplunkTrust

Hello @nina, There are a few ways - 

 - If you are planning to showcase some use cases as a part of Project - Splunk Security Essentials (https://splunkbase.splunk.com/app/3435) does have some built-in datasets. For example for Sample Brute Force Attack Detection

https://github.com/splunk/botsv3 does have a number of sample datasets for multiple sourcetypes

- You can use EventGen (https://splunkbase.splunk.com/app/1924) to generate "more" events based on existing event formats.

 

Please accept the solution and hit Karma, if this helps!

Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Beyond Detection: How Splunk and Cisco Integrated Security Platforms Transform ...

Financial services organizations face an impossible equation: maintain 99.9% uptime for mission-critical ...

Customer success is front and center at .conf25

Hi Splunkers, If you are not able to be at .conf25 in person, you can still learn about all the latest news ...

.conf25 Global Broadcast: Don’t Miss a Moment

Hello Splunkers, .conf25 is only a click away.  Not able to make it to .conf25 in person? No worries, you can ...