Splunk Enterprise Security

Splunk Enterprise Security: Where to learn SPL, searches, and log sources?

dzejsonborn
New Member

Hi everyone,
I need to learn SPL searches quickly.
In particular, I need to focus on covering the log source (CWS, CLM - Checkpoint).
Where do I start?

0 Karma
1 Solution

kmorris_splunk
Splunk Employee
Splunk Employee

You could take the Splunk Fundamentals 1 class. It is a free, online, self-paced class that gives you the fundamentals of getting data in, searching, reporting, alerting, dashboarding. If you do it start to finish it should take you about half to 3/4 of a day from what I have heard.

https://www.splunk.com/en_us/training/courses/splunk-fundamentals-1.html

As for searching that data, you may also want to start with any existing apps / add-ons available on splunkbase.com for free. For example, there is an add-on for CWS, and an app, Cisco Security Suite, which provides visualizations for that and many other Cisco security related sources of data. You can always utilize what is in those dashboards, and even look at the searches behind the panels to learn how they were created.

https://splunkbase.splunk.com/app/2791/
https://splunkbase.splunk.com/app/3197/
https://splunkbase.splunk.com/app/4293/
https://splunkbase.splunk.com/app/525/

View solution in original post

0 Karma

kmorris_splunk
Splunk Employee
Splunk Employee

You could take the Splunk Fundamentals 1 class. It is a free, online, self-paced class that gives you the fundamentals of getting data in, searching, reporting, alerting, dashboarding. If you do it start to finish it should take you about half to 3/4 of a day from what I have heard.

https://www.splunk.com/en_us/training/courses/splunk-fundamentals-1.html

As for searching that data, you may also want to start with any existing apps / add-ons available on splunkbase.com for free. For example, there is an add-on for CWS, and an app, Cisco Security Suite, which provides visualizations for that and many other Cisco security related sources of data. You can always utilize what is in those dashboards, and even look at the searches behind the panels to learn how they were created.

https://splunkbase.splunk.com/app/2791/
https://splunkbase.splunk.com/app/3197/
https://splunkbase.splunk.com/app/4293/
https://splunkbase.splunk.com/app/525/

0 Karma
Get Updates on the Splunk Community!

New in Observability - Improvements to Custom Metrics SLOs, Log Observer Connect & ...

The latest enhancements to the Splunk observability portfolio deliver improved SLO management accuracy, better ...

Improve Data Pipelines Using Splunk Data Management

  Register Now   This Tech Talk will explore the pipeline management offerings Edge Processor and Ingest ...

3-2-1 Go! How Fast Can You Debug Microservices with Observability Cloud?

Register Join this Tech Talk to learn how unique features like Service Centric Views, Tag Spotlight, and ...