Getting Data In

getting datasets

nina
Engager

Hello everyone, I'm working on a project ''Splunk Enterprise: An organization's go-to in detecting cyber threats''  please how/where can I get datasets and logs that I will use for my project.

Labels (1)
0 Karma
1 Solution

meetmshah
SplunkTrust
SplunkTrust

Hello @nina, There are a few ways - 

 - If you are planning to showcase some use cases as a part of Project - Splunk Security Essentials (https://splunkbase.splunk.com/app/3435) does have some built-in datasets. For example for Sample Brute Force Attack Detection

https://github.com/splunk/botsv3 does have a number of sample datasets for multiple sourcetypes

- You can use EventGen (https://splunkbase.splunk.com/app/1924) to generate "more" events based on existing event formats.

 

Please accept the solution and hit Karma, if this helps!

View solution in original post

nina
Engager

hello, thankyou so much for responding. even though i am entirely new to splunk and trying to find my way with youre recommendation, they are very useful.

0 Karma

inventsekar
SplunkTrust
SplunkTrust

Hi @nina ... to learn regex/rex, i have made lot of videos.. pls check it.. thanks. 

Splunk newbie learning videos, for absolute beginners:
https://www.youtube.com/@SiemNewbies101/playlists

0 Karma

meetmshah
SplunkTrust
SplunkTrust

Hello @nina, There are a few ways - 

 - If you are planning to showcase some use cases as a part of Project - Splunk Security Essentials (https://splunkbase.splunk.com/app/3435) does have some built-in datasets. For example for Sample Brute Force Attack Detection

https://github.com/splunk/botsv3 does have a number of sample datasets for multiple sourcetypes

- You can use EventGen (https://splunkbase.splunk.com/app/1924) to generate "more" events based on existing event formats.

 

Please accept the solution and hit Karma, if this helps!

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Agent Mode Engaged! Enchaining Agentic Operations with Splunk AI Assistant 2.0

    Are you ready to transform how your team handles complex data requests? We invite you to our upcoming ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...