Splunk安全日志分析
原名:analyzing-security-logs-with-splunk
利用 Splunk 企业安全平台和 SPL 搜索处理语言。
- 分类
- 开发提效
- 版本
- v1.0.0
- 作者
- 弈韬(@ra1nzzz)
- 下载
- 2
- 收藏
- 0
- 发布
- 2026-08-18
- 更新
- 2026-08-19
- TRACE 评分
- 3.4 / 5
内容概览
- Investigating a security incident that requires correlation across multiple log sources - Hunting for adversary activity using known TTPs and IOCs - Building detection rules for specific attack patterns - Reconstructing an incident timeline from disparate log sources - Analyzing authentication anomalies, lateral movement, or data exfiltration patterns Do not use for real-time packet-level analysis; use Wireshark or Zeek for full packet capture analysis. - Splunk Enterprise or Splunk Cloud with Enterprise Security (ES) app installed - Log sources ingested: Windows Event Logs (via Splunk Universal Forwarder or WEF), firewall, proxy, DNS, EDR, email gateway - Splunk CIM (Common Information Model) data models configured for normalized field names - SPL proficiency at intermediate level or higher - Role-based access with search and accelerate search capabilities in Splunk Define search para…