← Back to SOC Analyst - Blue Team Operations

Lesson 2 of 10

SIEM Deep Dive - Splunk & ELK

Splunk

index=windows EventCode=4625 | stats count by src_ip
index=firewall action=blocked | top src_ip

ELK

  • Filebeat → Logstash → Elasticsearch → Kibana
  • Creating detections