Splunk Enterprise Security

Splunk Enterprise Security: Where to learn SPL, searches, and log sources?

dzejsonborn
New Member

Hi everyone,
I need to learn SPL searches quickly.
In particular, I need to focus on covering the log source (CWS, CLM - Checkpoint).
Where do I start?

0 Karma
1 Solution

kmorris_splunk
Splunk Employee
Splunk Employee

You could take the Splunk Fundamentals 1 class. It is a free, online, self-paced class that gives you the fundamentals of getting data in, searching, reporting, alerting, dashboarding. If you do it start to finish it should take you about half to 3/4 of a day from what I have heard.

https://www.splunk.com/en_us/training/courses/splunk-fundamentals-1.html

As for searching that data, you may also want to start with any existing apps / add-ons available on splunkbase.com for free. For example, there is an add-on for CWS, and an app, Cisco Security Suite, which provides visualizations for that and many other Cisco security related sources of data. You can always utilize what is in those dashboards, and even look at the searches behind the panels to learn how they were created.

https://splunkbase.splunk.com/app/2791/
https://splunkbase.splunk.com/app/3197/
https://splunkbase.splunk.com/app/4293/
https://splunkbase.splunk.com/app/525/

View solution in original post

0 Karma

kmorris_splunk
Splunk Employee
Splunk Employee

You could take the Splunk Fundamentals 1 class. It is a free, online, self-paced class that gives you the fundamentals of getting data in, searching, reporting, alerting, dashboarding. If you do it start to finish it should take you about half to 3/4 of a day from what I have heard.

https://www.splunk.com/en_us/training/courses/splunk-fundamentals-1.html

As for searching that data, you may also want to start with any existing apps / add-ons available on splunkbase.com for free. For example, there is an add-on for CWS, and an app, Cisco Security Suite, which provides visualizations for that and many other Cisco security related sources of data. You can always utilize what is in those dashboards, and even look at the searches behind the panels to learn how they were created.

https://splunkbase.splunk.com/app/2791/
https://splunkbase.splunk.com/app/3197/
https://splunkbase.splunk.com/app/4293/
https://splunkbase.splunk.com/app/525/

0 Karma
Get Updates on the Splunk Community!

Announcing the Expansion of the Splunk Academic Alliance Program

The Splunk Community is more than just an online forum — it’s a network of passionate users, administrators, ...

Learn Splunk Insider Insights, Do More With Gen AI, & Find 20+ New Use Cases You Can ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Buttercup Games: Further Dashboarding Techniques (Part 7)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...