To access material, start machines and answer questions login.
A few weeks ago, Jasmine, the owner of Coffely, reported a data breach where her secret recipe was stolen by an insider from the IT department. Thanks to the Forensics team, the culprit was quickly identified, and the recipe was recovered.
Now, Jasmine wants to build an in-house to continuously monitor critical logs and detect threats early. She has enlisted your help to set up locally, integrating logs from a host and the Coffely web server to build a centralized monitoring capability.
Objectives
- Learn how to install Splunk and the Universal Forwarder on a Linux host
- Explore Splunk configuration via the command line
- Understand how to ingest Linux and Web logs into Splunk
Prerequisites
- Cover Introduction to for an overview of SIEM usage for log analysis
- Check out Splunk: Basics to get comfortable navigating the Splunk interface
- Work through Splunk: Exploring to learn about Splunk's Search Processing Language
About the Lab
In this lab, you'll work with a Linux environment to install and configure Splunk, integrate key log sources, and forward data from system files and a web server. By the end, you'll have a working setup for centralized log monitoring using Splunk.
I understand the learning objectives and am ready to set up a SOC lab!
Ready to learn Cyber Security?
The Splunk: Setting up a SOC Lab room is only available for Premium or Max subscribers. Signup now to access more than 500 free rooms and learn cyber security through a fun, interactive learning environment.
Already have an account? Log in

