Minimum setup
- One local Splunk instance or training environment
- Sample logs from Windows, Linux, or web applications
- A notebook for searches, field meanings, and expected results
- No public exposure of admin interfaces
Hands-on layer
These lab blueprints are designed to turn theory into demonstrable skill while keeping a home setup simple and security-conscious.
Foundation
Exercises
Capstones
Build a service health dashboard that highlights HTTP errors, response anomalies, and outage signals by host and application path.
Build an authentication monitoring pack with searches for password spraying, off-hours access, and repeated account lockouts.
Create a one-page summary that explains what the data says, what matters now, and what should happen next.
Document a secure setup checklist covering access control, data onboarding standards, app hygiene, and exposure boundaries.