Hey all, I've got an interview and I need to show some level of competency at using Splunk, I'm doing a short presentation on it and I have used it a little. I know it organises a lot of data from logs into useful information and it's handy for forensics, security and auditing users - I'm sure much more as well. My task is this, to run Splunk on my computer and monitor operating system events and/or performance. I did monitor data from the source called "Local Event Logs" and picked Security, Application, System and Setup and I have had a quick look over them but something is bugging me. How can I make this more interesting because I'm doing a presentation on it? Is there a field or something that would be good to talk about? There's so many options so it's a bit tough to pick or a find a good one. Odd question, I know but any suggestions would be appreciated. Thank you for the read guys.
... View more