General
History
Commands
Notable Events
Correlation Searches
100

Powerful software platform used to collect, analyze, and visualize machine-generated data

What is a Security Information and Event Management (SIEM)?

100

Company founded in 2003 by Rob Das and Eric Swan.

What is Splunk?

100

Most common wildcard, used in search terms to match any sequence of characters.

What is an asterisk (*)?

100

This dashboard shows all triggered notable events

What is Incident Review?

100

This type of search links multiple events based on shared fields like src, user, or host

What is a correlation search?

200

Proprietary query language used to search, analyze, and manipulate data within Splunk

What is Search Processing Language (SPL)?

200

The company name, Splunk, was inspired by this sport

What is "spelunking"?

200

Displays a table of your previously run searches in the current app

What is the "history" command?

200

This field in a notable event indicates its importance

What is urgency?

200

This mapping allows correlation searches to align with MITRE ATT&CK tactics

What is security content mapping?

300

A repository where Splunk stores and organizes your data

What is an index?

300

In 2023, this company announced its acquisition of Splunk for $28B

What is Cisco?

300

This field in a correlation search defines how often the search runs, such as every 5 minutes or hourly

What is the "cron" schedule?

300

This action can be taken on a notable event to assign it to an analyst

What is assign owner?

300

This field accumulates risk scores for identities over time

What is risk_object?

400

An instance dedicated to managing and coordinating searches in a distributed environment

What is a Search Head?

400

Company expanded into cybersecurity with the introduction of this product in 2015

What is Splunk Enterprise Security?

400

Correlation searches are typically built using this SPL command to filter and transform raw data into security-relevant insights.

What is "|" search?

400

This status means the event has been reviewed and resolved.

What is closed?

400

This framework helps prioritize alerts based on user and asset risk

What is Risk-Based Alerting (RBA)?

500

A collection of defined fields, extractions, event types, and other data objects stored on the search head

What is a knowledge object?

500

This solution uses artificial intelligence and machine learning to provide end-to-end visibility into IT infrastructure and services.

What is Splunk IT Service Intelligence (ITSI) 

500

Feature allows correlation searches to trigger adaptive responses such as creating a notable event or sending an alert

What is an adaptive response action?

500

This field links a notable event to a correlation search.

What is rule_name?

500

This type of search increases a user’s risk score based on suspicious behavior

What is a risk modifier search?

M
e
n
u