Splunk Basics
SOC Acronyms
Investigation
Log Sources
Log Fields
100

Command displays results in a table

What is table

100

SOC

What is Security Operations Center

100

Type of malware encrypts files and demands payment

What is Ransomware

100

Records activity on a website

What is web server

100

Shows the IP address where the network traffic started

What is src

200

This symbol is called: *

What is a wildcard

200

IOC

What is Indicator of Compromise

200

You want to find all activity from one computer in Splunk. Which field would you search

What is host

200

Records users logging into Windows

What is Windows Security Log

200

Shows the IP address where the network traffic is going 

What is dest

300

Command limits the number of returned events

What is head

300

SIEM

What is Security Information and Event Management

300

The field src represents

What is where the traffic came from

300

Shows process creation details

What is sysmon
300

Identifies the computer or device that generated the event

What is host OR computer OR src

400

Command counts how many events match your search

What is stats count

400

IRT

What is Incident Response Team

400

You should be identifying these during an investigation

What is IOCs

400

Records failed login attempts

What is Authentication/Security Logs

400

Tells you when an event occurred

What is _time

500

Command sorts results by time or another field

What is sort

500

SPL

What is Search Processing Language

500

The last thing a Security Analyst should do when finishing the initial investigation

What is write-up a note/comment

500

Show blocked or allowed network traffic

What is firewall logs

500

Numerically identifies the type of Windows event that occurred

What is EventCode or EventID

M
e
n
u