| name | analyzing-security-logs-with-splunk |
| description | Use when leverages Splunk Enterprise Security and SPL (Search Processing Language) to investigate security incidents through log correlation, timeline reconstruction, and anomaly detection. Covers Windows event logs, firewall logs, proxy logs, and authentication data analysis. Activates for requests involving Splunk investigation, SPL queries, SIEM log analysis, security event correlation, or log-based incident investigation. |
| domain | cybersecurity |
| tags | ["splunk","SPL","SIEM","log-analysis","security-monitoring"] |
| subdomain | incident-response |
| mitre_attack | ["T1070","T1562","T1059"] |
| version | 1.0.0 |
| author | oyi77 |
| license | Apache-2.0 |
| atlas_techniques | ["AML.T0070","AML.T0066","AML.T0082"] |
| d3fend_techniques | ["Executable Denylisting","Execution Isolation","File Metadata Consistency Validation","Content Format Conversion","File Content Analysis"] |
| nist_ai_rmf | ["MEASURE-2.7","MAP-5.1","MANAGE-2.4","MANAGE-3.1","MEASURE-3.1"] |
| nist_csf | ["RS.MA-01","RS.MA-02","RS.AN-03","RC.RP-01"] |
Analyzing Security Logs With Splunk
Overview
Cybersecurity skill for analyzing security logs with splunk. Follows industry best practices and security standards.
When to Use
Trigger phrases:
-
"analyzing security logs with splunk"
-
"Leverages Splunk Enterprise Security and SPL (Search Processing Language) to inv"
-
Investigating a security incident that requires correlation across multiple log sources
-
Hunting for adversary activity using known TTPs and IOCs
-
Building detection rules for specific attack patterns
-
Reconstructing an incident timeline from disparate log sources
-
Analyzing authentication anomalies, lateral movement, or data exfiltration patterns
Do not use for real-time packet-level analysis; use Wireshark or Zeek for full packet capture analysis.
When NOT to Use
- When you lack proper authorization for testing
- For production systems without change management
- When the task requires legal or compliance expertise beyond technical scope
Prerequisites
- Splunk Enterprise or Splunk Cloud with Enterprise Security (ES) app installed
- Log sources ingested: Windows Event Logs (via Splunk Universal Forwarder or WEF), firewall, proxy, DNS, EDR, email gateway
- Splunk CIM (Common Information Model) data models configured for normalized field names
- SPL proficiency at intermediate level or higher
- Role-based access with
search and accelerate_search capabilities in Splunk
Workflow
import re
IOC_PATTERNS = {
"ip": r"\b(?:\d{1,3}\.){3}\d{1,3}\b",
"domain": r"\b[a-z0-9-]+\.[a-z]{2,}\b",
"hash_md5": r"\b[a-f0-9]{32}\b",
"hash_sha256": r"\b[a-f0-9]{64}\b",
}
def extract_iocs(text: str) -> dict:
{k: re.findall(v, text) k, v IOC_PATTERNS.items()}