Skip to content

This repository features a collection of hands-on projects focused on analyzing different types of logs using Splunk SIEM. Each project includes clear, step-by-step guidance on uploading sample log files, conducting targeted analysis, and extracting meaningful insights from various log sources.

Notifications You must be signed in to change notification settings

HannachiHassen/Splunk-Projects-Beginners

Repository files navigation

πŸ“Š Splunk SIEM Log Analysis Projects

This repository features a collection of hands-on projects focused on analyzing different types of logs using Splunk SIEM. Each project includes clear, step-by-step guidance on uploading sample log files, conducting targeted analysis, and extracting meaningful insights from various log sources.

πŸ”Ž Overview

These projects are designed for:

  • SOC Analyst training

  • Cybersecurity students and beginners

  • Anyone learning Splunk SIEM fundamentals

  • Hands-on practice with log analysis and detection techniques

Each project includes:

βœ” Sample log files

βœ” Data onboarding steps

βœ” SPL (Search Processing Language) queries

βœ” Analysis walkthroughs

βœ” Security insights and detection examples

πŸ“ Project List

  1. Analyzing DNS Logs Using Splunk SIEM: This project provides a step-by-step guide for analyzing DNS (Domain Name System) log files using Splunk SIEM. It covers uploading sample log files, extracting relevant fields, analyzing DNS query patterns, detecting anomalies, and monitoring DNS traffic.
  2. Analyzing FTP Logs Using Splunk SIEM: This project guides you through analyzing FTP (File Transfer Protocol) log files using Splunk SIEM. It includes steps for uploading sample log files, extracting fields, analyzing FTP activity patterns, detecting anomalies, and monitoring FTP traffic.
  3. Analyzing HTTP Logs Using Splunk SIEM: This project outlines the process of analyzing HTTP (Hypertext Transfer Protocol) log files using Splunk SIEM. It covers uploading sample log files, extracting relevant fields, analyzing HTTP request patterns, detecting anomalies, and monitoring HTTP traffic.
  4. Analyzing SSH Logs Using Splunk SIEM: This project provides a comprehensive guide for analyzing SSH (Secure Shell) log files using Splunk SIEM. It includes steps for uploading sample log files, extracting fields, analyzing SSH activity patterns, detecting anomalies, and correlating SSH logs with other data sources.
  5. Analyzing Tunnel Logs Using Splunk SIEM: This project demonstrates how to analyze tunnel log traffic (e.g., GRE, IPv4, IPv6) from Zeek IDS using Splunk SIEM. It covers uploading sample log files, performing analysis, detecting anomalies, and correlating tunnel logs with other logs for enhanced threat detection.
  6. Analyzing SMTP Logs Using Splunk SIEM: This project provides a structured approach for analyzing SMTP (Simple Mail Transfer Protocol) log files using Splunk SIEM. It includes steps for uploading sample log files, extracting fields, analyzing email traffic patterns, detecting anomalies, and monitoring SMTP activity.
  7. Analyzing DHCP Logs Using Splunk SIEM: This project offers guidance on analyzing DHCP (Dynamic Host Configuration Protocol) log files using Splunk SIEM. It covers uploading sample log files, extracting fields, analyzing IP address assignments, detecting anomalies, and monitoring DHCP traffic.

🀝 Contributing

Contributions, improvements, and additional log samples are welcome! Feel free to open an issue or submit a pull request.

πŸ“§ Contact

Hassen Hannachi GitHub: @HannachiHassen LinkedIn available upon request

About

This repository features a collection of hands-on projects focused on analyzing different types of logs using Splunk SIEM. Each project includes clear, step-by-step guidance on uploading sample log files, conducting targeted analysis, and extracting meaningful insights from various log sources.

Topics

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published