
Learn the defensive side of cybersecurity by tracing the evolution from security information management to security event management, log management, and siem, using Splunk in a cloud-based lab.
Understand why organizations need SIEM to monitor logs, prioritize events, normalize and correlate data, detect breaches, and meet compliance with Splunk.
Explore how a security operations center uses siem to monitor events, detect anomalies, investigate root causes, manage logs, and drive proactive threat monitoring through pen testing and vulnerability assessment.
Discover how a SIEM collects, stores, analyzes, and reports on logs from diverse sources, normalizes data, correlates events, and alerts on security incidents.
prioritize events and spot security issues using siem to manage vast data from machine events. normalize and correlate raw machine events, and add indexes to enable search and reporting.
Explore the SIEM architecture as system input from endpoints and network devices feeds a scene that collects event data and contextual data, denormalizes and aggregates logs for a searchable dashboard.
See how siem collects logs from firewalls, servers, endpoints, and cloud sources, routes them to a receiver, normalizes and aggregates, then indexes and displays them in a searchable dashboard.
Explore the features of a next-generation SIEM, including log collection and analysis, event correlation, log forensic reporting, dashboards, user activity monitoring, real-time alerting, log retention, and integrity monitoring.
Identify critical events to monitor, such as new processes, PowerShell use, suspicious logons, and possible lateral movement, then investigate file share activity, new services, registry changes, and data exfiltration indicators.
Learn to monitor Windows event IDs, including new process and logon activities, and recognize firewall network events and registry changes that indicate malware, exfiltration, or privilege abuse.
Discover six siem-made protections against threats: detect compromised credentials; anomalous privilege escalation; command and control; data exfiltration; usb drive insertion via personal email; and rapid encryption and lateral movements.
Learn how Splunk powers SIEM with forwarders, indexers, and search heads to collect and index logs from endpoints in real time, using apps and API integrations.
Explore Splunk fields, including selected and interesting fields, and learn how hosts, sources, and source types shape log searches and event displays in SIEM workflows.
Learn how to search Splunk events with its search language syntax, set index to web, specify source type, and use pipes, built-in commands, and concatenate results to calculate fields.
Learn Splunk search best practices for siem: set time frames and indices, use precise terms, dedupe duplicates, avoid leading wildcards, and present results with table and stats.
Sign up for Splunk Cloud, create an account with a valid email, and update your temporary password, then learn to upload logs by re-uploading a Linux log source in Splunk.
Navigate to settings, add data, and upload the compressed log files to Splunk for your lab; follow the demo steps and upload each file individually.
Explore how forwarders install on endpoints, configure to send Windows event logs or syslog to a Splunk server by specifying the IP address, and ensure connectivity so logs upload automatically.
Filter logs by stats count to identify top IPs with failed login attempts, view events, and investigate abnormal brute-force SSH activity across multiple ports.
Save and index your search parameters in SIEM workflows to reuse common queries, keeping a notepad or reference index so you can quickly recall and apply them without retyping.
Investigate suspicious IP addresses by tracing who uses each IP, how long the user has been using it, and the SSH activity, identifying brute force signs from log data.
Analyze web application logs with SIEM queries to identify top client IPs, monitor HTTP status codes, and investigate potential attacks by cross-referencing IPs with VirusTotal and Hybrid Analysis.
Investigate whether a vpn ip is malicious by analyzing user behavior, http status codes like 503 and 404, and logs to identify attempts to drop a malicious payload.
Explore how the visualization tab turns security data into graphical charts for quick insight and executive reports, highlighting IPs with a high rate of file not found errors.
Utilize three modes—fast, smart, and verbose—for SIEM searches in SOC investigations. Verbose shows all events and fields; smart offers quick searches, while fast provides balance, with no mode preference.
As an admin, create users, assign roles, and restrict permissions so departments can only view or record, handling administrative tasks alongside log analysis.
Explore how SIEM analyzes logs to reveal compromised systems and support defense in depth, while noting it cannot unmask masked IPs; rely on perimeter devices and IP verification.
Are you ready to take your cybersecurity skills to the next level? In this course "SOC Analysis with SIEM: Mastering Log Event Monitoring," you will gain practical, job-ready experience in how modern Security Operations Centers (SOCs) detect, analyze, and respond to threats using SIEM tools.
This beginner-intermediate-level course is designed for IT professionals, security enthusiasts, and anyone looking to break into the cybersecurity field. You’ll learn how to work with log data, identify suspicious activity, and use SIEM platforms to investigate security incidents. Through real-world examples and guided exercises, you'll explore how log events from various systems—such as firewalls, servers, and endpoints—can be correlated to detect and respond to attacks.
Key topics include threat detection, log event analysis, alert triage, and incident response within a SOC environment. You’ll also gain insights into industry compliance standards and how SIEM supports regulatory requirements. No prior experience with SIEM tools is required, but a basic understanding of networking and cybersecurity fundamentals will help you get the most out of this course.
Whether you're aiming to become a SOC Analyst or simply want to strengthen your threat detection skills, this course will give you a solid foundation and real-world context for using SIEM in active defense.