Command displays results in a table
What is table
SOC
What is Security Operations Center
Type of malware encrypts files and demands payment
What is Ransomware
Records activity on a website
What is web server
Shows the IP address where the network traffic started
What is src
This symbol is called: *
What is a wildcard
IOC
What is Indicator of Compromise
You want to find all activity from one computer in Splunk. Which field would you search
What is host
Records users logging into Windows
What is Windows Security Log
Shows the IP address where the network traffic is going
What is dest
Command limits the number of returned events
What is head
SIEM
What is Security Information and Event Management
The field src represents
What is where the traffic came from
Shows process creation details
Identifies the computer or device that generated the event
What is host OR computer OR src
Command counts how many events match your search
What is stats count
IRT
What is Incident Response Team
You should be identifying these during an investigation
What is IOCs
Records failed login attempts
What is Authentication/Security Logs
Tells you when an event occurred
What is _time
Command sorts results by time or another field
What is sort
SPL
What is Search Processing Language
The last thing a Security Analyst should do when finishing the initial investigation
What is write-up a note/comment
Show blocked or allowed network traffic
What is firewall logs
Numerically identifies the type of Windows event that occurred
What is EventCode or EventID