WDavid404 / THM_CyberDefense

0 stars 0 forks source link

Security Operations & Monitoring -- Splunk #7

Open WDavid404 opened 12 months ago

WDavid404 commented 12 months ago

Splunk Components

Three main components:

image

Splunk Forwarder

Splunk Forwarder is a lightweight agent installed on the endpoint intended to be monitored, and its main task is to collect the data and send it to the Splunk instance. It does not affect the endpoint's performance as it takes very few resources to process. Some of the key data sources are:

Splunk Indexer

Splunk Indexer plays the main role in processing the data it receives from forwarders. It takes the data, normalizes it into field-value pairs, determines the datatype of the data, and stores them as events. Processed data is easy to search and analyze.

Search Head

Splunk Search Head is the place within the Search & Reporting App where users can search the indexed logs as shown below. When the user searches for a term or uses a Search language known as Splunk Search Processing Language, the request is sent to the indexer and the relevant events are returned in the form of field-value pairs. image

Navigating Splunk

Splunk Bar

image

Splunk Dashboard

By default, no dashboards are displayed. You can choose from a range of dashboards readily available within your Splunk instance.

Adding Data

The data sources can be event logs, website logs, firewall logs, etc. Data sources are grouped into categories. image

WDavid404 commented 12 months ago

Splunk 2 -- 100 series questions

BOTSv2 Github: https://github.com/splunk/botsv2 A sample security dataset and CTF platform for information security professionals, researchers, students, and enthusiasts.

Case1:

image image

其他: 搜索跟beer公司相关邮件记录:index="botsv2" sourcetype="stream:smtp" berkbeer.com