Splunk安全日志分析

原名:analyzing-security-logs-with-splunk

利用 Splunk 企业安全平台和 SPL 搜索处理语言。

分类
开发提效
版本
v1.0.0
作者
弈韬(@ra1nzzz)
下载
2
收藏
0
发布
2026-08-18
更新
2026-08-19
TRACE 评分
3.4 / 5

内容概览

- Investigating a security incident that requires correlation across multiple log sources - Hunting for adversary activity using known TTPs and IOCs - Building detection rules for specific attack patterns - Reconstructing an incident timeline from disparate log sources - Analyzing authentication anomalies, lateral movement, or data exfiltration patterns Do not use for real-time packet-level analysis; use Wireshark or Zeek for full packet capture analysis. - Splunk Enterprise or Splunk Cloud with Enterprise Security (ES) app installed - Log sources ingested: Windows Event Logs (via Splunk Universal Forwarder or WEF), firewall, proxy, DNS, EDR, email gateway - Splunk CIM (Common Information Model) data models configured for normalized field names - SPL proficiency at intermediate level or higher - Role-based access with search and accelerate search capabilities in Splunk Define search para…

查看 SKILL 详情