Splunk Search

how to perform Log analysis at home wifi

soumya_1617
New Member

i have to get hands on experience on log analysis using home wifi and add it to my resume so this will help me get a job 

 

Labels (1)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

Log analysis needs two things. One - as @ITWhisperer already mentioned - is the logs themselves. You must have the data to analyse. You can't analyse something you don't have.

Another important thing is the goal of your analysis - what you want to get from your logs. A question you want answered using the data you have. You don't just "analyse logs" for fun. You want the logs to tell you, for example - if anyone tried to log in to your network and failed. How many such attempts were made? Were someone persistent in their attempts or were there just "random" occurrences? Or you can check performance data - what connection quality your clients had. What bandwidth did they use. And so on.

Of course to answer such questions you need a relevant set of data for each use case. You can't typically tell much about security from performance data and vice versa. (Sometimes anomalies in one type of data can be a hint of something happening elsewhere but that's a much more advanced topic and for now don't bother with it).

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Have you managed to get your "wifi" logs into Splunk?

0 Karma

soumya_1617
New Member

No

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

You need to start there then. This will depend on your router/modem and what capabilities you have available to you there. Essentially, you need to find a way to get your logs ingested into Splunk so you can start your analysis.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...