I am a Korean university student studying Digital Forensics (incident Response).
I want to study splunk and participate in BOTS Day.
I think it will be a process to become a security expert.
However, "https://www.splunk.com/en_us/blog/security/boss-of-the-soc-2-0-dataset-questions-and-answers-open-so..." seems to require the Enterprise version to handle dataset for BOTS Day.
"https://www.splunk.com/en_us/download/get-started-with-your-free-trial.html" states that the Enterprise version is only available for 60 days.
Do I have to purchase the Enterprise version to prepare for BOTS Day?
Can't I prepare for BOTS Day and get good results with Splunk Phantom Free Community Edition?
Based on my last BOTS experience, you do not need Phantom or Splunk Enterprise Security to prepare for BOTS Day. Nor do you need to purchase Splunk as the free version should be enough.
Consider downloading the BOSS of the SOC (BOTS) Advanced APT Hunting Companion App for Splunk (https://splunkbase.splunk.com/app/4430/) as a study guide.
So ... Install Splunk, load the dataset, and play with it
If it doesn't continue to work after the install flips to free mode in 60 days, remove Splunk, reinstall, and reload the dataset