2026-04-13 08-52-50
May 25, 2026 14:34
· 10:19
· English
· Whisper Turbo
· 2 Speaker
Dat ass haut den Numm vum Duerf.
Upgrade fir permanent Speicherung →
Just ze gesinn
0:08
S…
Speaker 1 (2026-04-13 08-52-50)
In this video,
0:08
S…
Speaker 2 (2026-04-13 08-52-50)
we're going to go over what Splunk is and
0:13
S…
Speaker 2 (2026-04-13 08-52-50)
how it can be used in threat hunting.
0:16
S…
Speaker 1 (2026-04-13 08-52-50)
So to start off with,
0:18
S…
Speaker 2 (2026-04-13 08-52-50)
what is Splunk?
0:19
S…
Speaker 2 (2026-04-13 08-52-50)
If you are not familiar with Splunk,
0:21
S…
Speaker 2 (2026-04-13 08-52-50)
it is a security information and event management system,
0:25
S…
Speaker 2 (2026-04-13 08-52-50)
or a SIEM or SIEM,
0:27
S…
Speaker 2 (2026-04-13 08-52-50)
depending on how you want to pronounce it.
0:29
S…
Speaker 2 (2026-04-13 08-52-50)
It's used for a lot more than just security.
0:33
S…
Speaker 2 (2026-04-13 08-52-50)
A lot of organizations use it for things like system monitoring,
0:37
S…
Speaker 2 (2026-04-13 08-52-50)
performance information,
0:39
S…
Speaker 2 (2026-04-13 08-52-50)
error correlation,
0:40
S…
Speaker 2 (2026-04-13 08-52-50)
things like that.
0:41
S…
Speaker 2 (2026-04-13 08-52-50)
For our purposes,
0:42
S…
Speaker 2 (2026-04-13 08-52-50)
we're going to be looking at it from a threat hunting perspective.
0:46
S…
Speaker 2 (2026-04-13 08-52-50)
It's capable of performing analysis on logs
0:50
S…
Speaker 2 (2026-04-13 08-52-50)
and other data that is fed into the system,
0:54
S…
Speaker 2 (2026-04-13 08-52-50)
and it can collect logs from multiple different sources,
0:59
S…
Speaker 2 (2026-04-13 08-52-50)
performing both aggregation and correlation activities,
1:04
S…
Speaker 2 (2026-04-13 08-52-50)
basically tying logs together from multiple different systems to
1:08
S…
Speaker 2 (2026-04-13 08-52-50)
kind of build the story about what's been happening on those systems
1:13
S…
Speaker 2 (2026-04-13 08-52-50)
and on the network in general.
1:15
S…
Speaker 2 (2026-04-13 08-52-50)
It does have capabilities for real -time analysis.
1:18
S…
Speaker 2 (2026-04-13 08-52-50)
There are a lot of alerting capabilities included in
1:23
S…
Speaker 2 (2026-04-13 08-52-50)
Splunk, and a lot of organizations will use Splunk as part of their security
1:27
S…
Speaker 2 (2026-04-13 08-52-50)
operations center as well.
1:29
S…
Speaker 2 (2026-04-13 08-52-50)
for the alerting and also for the dashboards
1:34
S…
Speaker 2 (2026-04-13 08-52-50)
and visualizations capabilities that Splunk has inside.
1:38
S…
Speaker 1 (2026-04-13 08-52-50)
Now,
1:39
S…
Speaker 2 (2026-04-13 08-52-50)
for the most part in threat hunting,
1:41
S…
Speaker 2 (2026-04-13 08-52-50)
we're not really going to be taking a look at the dashboards because those are going to be more
1:45
S…
Speaker 2 (2026-04-13 08-52-50)
of reactive measures waiting for Splunk to
1:49
S…
Speaker 2 (2026-04-13 08-52-50)
analyze data and show information on those dashboards where
1:54
S…
Speaker 2 (2026-04-13 08-52-50)
threat hunting is more of a proactive activity.
1:58
S…
Speaker 2 (2026-04-13 08-52-50)
Visualizations can sometimes be used in threat hunting just basically
2:02
S…
Speaker 2 (2026-04-13 08-52-50)
as a way to show the data a bit more cleaner,
2:06
S…
Speaker 2 (2026-04-13 08-52-50)
and we'll take a look at some forms of visualizations like
2:10
S…
Speaker 2 (2026-04-13 08-52-50)
tables and things like that as we go through this course and start working
2:15
S…
Speaker 2 (2026-04-13 08-52-50)
with Splunk a bit more.
2:17
S…
Speaker 2 (2026-04-13 08-52-50)
One thing that is very common to use in threat hunting
2:21
S…
Speaker 2 (2026-04-13 08-52-50)
with Splunk is raw searches of the logs.
2:24
S…
Speaker 1 (2026-04-13 08-52-50)
And this is done in Splunk,
2:27
S…
Speaker 2 (2026-04-13 08-52-50)
specifically using what's known as SPL,
2:29
S…
Speaker 2 (2026-04-13 08-52-50)
the Splunk Processing Language.
2:32
S…
Speaker 2 (2026-04-13 08-52-50)
That is the language that's used to craft the queries
2:36
S…
Speaker 2 (2026-04-13 08-52-50)
that are used to search through logs in Splunk.
2:39
S…
Speaker 2 (2026-04-13 08-52-50)
We'll take a look at SPL in more detail in a later video
2:43
S…
Speaker 2 (2026-04-13 08-52-50)
in this course,
2:44
S…
Speaker 1 (2026-04-13 08-52-50)
though.
2:45
S…
Speaker 2 (2026-04-13 08-52-50)
It also has a lot of options for add
2:49
S…
Speaker 2 (2026-04-13 08-52-50)
-on applications from various different vendors and security
2:53
S…
Speaker 2 (2026-04-13 08-52-50)
providers to kind of expand upon the functionality that's
2:58
S…
Speaker 2 (2026-04-13 08-52-50)
included in Splunk by default.
3:00
S…
Speaker 2 (2026-04-13 08-52-50)
For the purposes of threat hunting,
3:02
S…
Speaker 2 (2026-04-13 08-52-50)
though, we're not going to be looking at any of that.
3:04
S…
Speaker 2 (2026-04-13 08-52-50)
The most important thing we're going to be looking at is the raw searches.
3:08
S…
Speaker 1 (2026-04-13 08-52-50)
Again,
3:09
S…
Speaker 2 (2026-04-13 08-52-50)
with a little bit of visualization kind of sprinkled in there,
3:12
S…
Speaker 1 (2026-04-13 08-52-50)
if you will.
3:13
S…
Speaker 2 (2026-04-13 08-52-50)
So Splunk has a very specific architecture that
3:18
S…
Speaker 2 (2026-04-13 08-52-50)
you should be aware of.
3:19
S…
Speaker 2 (2026-04-13 08-52-50)
The key component of Splunk is the indexer.
3:24
S…
Speaker 2 (2026-04-13 08-52-50)
It is in charge of storing and organizing all
3:28
S…
Speaker 2 (2026-04-13 08-52-50)
of the log information that is fed into it through a number
3:32
S…
Speaker 2 (2026-04-13 08-52-50)
of forwarders.
3:33
S…
Speaker 2 (2026-04-13 08-52-50)
The forwarder's jobs are to collect and send data
3:37
S…
Speaker 2 (2026-04-13 08-52-50)
to the indexer.
3:39
S…
Speaker 1 (2026-04-13 08-52-50)
Now, in this case,
3:40
S…
Speaker 2 (2026-04-13 08-52-50)
we're talking about forwarders in this kind of instance as kind of a generic term
3:44
S…
Speaker 2 (2026-04-13 08-52-50)
for anything that sends log data to the
3:49
S…
Speaker 2 (2026-04-13 08-52-50)
indexer.
3:50
S…
Speaker 2 (2026-04-13 08-52-50)
There is an actual Splunk forwarder kind of application
3:54
S…
Speaker 2 (2026-04-13 08-52-50)
that can be installed on systems to help with that.
3:57
S…
Speaker 1 (2026-04-13 08-52-50)
But in this instance,
3:59
S…
Speaker 2 (2026-04-13 08-52-50)
we're using forwarder in more of the generic term,
4:02
S…
Speaker 1 (2026-04-13 08-52-50)
if you will.
4:03
S…
Speaker 1 (2026-04-13 08-52-50)
Now,
4:03
S…
Speaker 2 (2026-04-13 08-52-50)
coupled with the indexer,
4:05
S…
Speaker 2 (2026-04-13 08-52-50)
you also have what's known as the search head.
4:08
S…
Speaker 2 (2026-04-13 08-52-50)
This is kind of what provides the interface for
4:12
S…
Speaker 2 (2026-04-13 08-52-50)
running searches,
4:13
S…
Speaker 2 (2026-04-13 08-52-50)
showing dashboards,
4:15
S…
Speaker 2 (2026-04-13 08-52-50)
that kind of thing.
4:16
S…
Speaker 2 (2026-04-13 08-52-50)
and the data from the indexer is what's included in those searches.
4:20
S…
Speaker 2 (2026-04-13 08-52-50)
Now, the indexer and the search head can be on one system,
4:24
S…
Speaker 2 (2026-04-13 08-52-50)
or it can be spread across multiple indexers,
4:28
S…
Speaker 2 (2026-04-13 08-52-50)
multiple search heads.
4:29
S…
Speaker 2 (2026-04-13 08-52-50)
That's going to really depend on the amount of data being ingested
4:34
S…
Speaker 1 (2026-04-13 08-52-50)
into Splunk,
4:35
S…
Speaker 2 (2026-04-13 08-52-50)
the requirements the organization has,
4:38
S…
Speaker 2 (2026-04-13 08-52-50)
the deployment model that's being used.
4:41
S…
Speaker 2 (2026-04-13 08-52-50)
For the sake of what we're looking at in our labs
4:45
S…
Speaker 2 (2026-04-13 08-52-50)
and in everything,
4:46
S…
Speaker 2 (2026-04-13 08-52-50)
this is all kind of an all -in -one system.
4:49
S…
Speaker 2 (2026-04-13 08-52-50)
So you can have just one server running both the
4:53
S…
Speaker 2 (2026-04-13 08-52-50)
indexer and search head,
4:55
S…
Speaker 2 (2026-04-13 08-52-50)
or you can have multiple indexers and multiple search heads.
4:58
S…
Speaker 1 (2026-04-13 08-52-50)
But now let's...
5:00
S…
Speaker 1 (2026-04-13 08-52-50)
take a break from the slides and move over into our lab environment
5:04
S…
Speaker 1 (2026-04-13 08-52-50)
and take a look at Splunk really quick just so you're familiar with the interface
5:08
S…
Speaker 1 (2026-04-13 08-52-50)
before we jump in and start working on writing queries.
5:12
S…
Speaker 1 (2026-04-13 08-52-50)
So when you first log into Splunk this is
5:16
S…
Speaker 1 (2026-04-13 08-52-50)
kind of the interface you'll be looking at.
5:19
S…
Speaker 1 (2026-04-13 08-52-50)
This is where you can have different applications loaded into Splunk,
5:23
S…
Speaker 1 (2026-04-13 08-52-50)
but the main component we're going to be concerned about when it comes to threat hunting
5:27
S…
Speaker 1 (2026-04-13 08-52-50)
is the search and reporting section here on the
5:31
S…
Speaker 1 (2026-04-13 08-52-50)
far left.
5:34
S…
Speaker 1 (2026-04-13 08-52-50)
So we go into the search and reporting section,
5:36
S…
Speaker 1 (2026-04-13 08-52-50)
and to start off with,
5:37
S…
Speaker 1 (2026-04-13 08-52-50)
it's very simple.
5:38
S…
Speaker 1 (2026-04-13 08-52-50)
We have our search box.
5:39
S…
Speaker 1 (2026-04-13 08-52-50)
We have some search history and some information here.
5:42
S…
Speaker 1 (2026-04-13 08-52-50)
One thing you can look at to see what kind of data
5:46
S…
Speaker 1 (2026-04-13 08-52-50)
you have in Splunk is the data summary.
5:49
S…
Speaker 1 (2026-04-13 08-52-50)
So if you click on the data summary,
5:51
S…
Speaker 1 (2026-04-13 08-52-50)
you can see exactly what kind of information you have in this
5:55
S…
Speaker 1 (2026-04-13 08-52-50)
system.
5:55
S…
Speaker 1 (2026-04-13 08-52-50)
So we have logs from three different sources here,
5:59
S…
Speaker 1 (2026-04-13 08-52-50)
three different hosts.
6:01
S…
Speaker 1 (2026-04-13 08-52-50)
We have different types,
6:03
S…
Speaker 1 (2026-04-13 08-52-50)
basically sources.
6:04
S…
Speaker 1 (2026-04-13 08-52-50)
So we have a lot of information from our Windows event logs,
6:07
S…
Speaker 1 (2026-04-13 08-52-50)
including things like PowerShell and Sysmon,
6:11
S…
Speaker 1 (2026-04-13 08-52-50)
as you can see right here.
6:12
S…
Speaker 1 (2026-04-13 08-52-50)
And then we have a source types as well.
6:16
S…
Speaker 1 (2026-04-13 08-52-50)
It's a different way of organizing the data.
6:19
S…
Speaker 1 (2026-04-13 08-52-50)
Now, when you are looking at Splunk and
6:23
S…
Speaker 1 (2026-04-13 08-52-50)
doing searches in Splunk,
6:24
S…
Speaker 1 (2026-04-13 08-52-50)
one of the key things you need to keep in mind is over
6:29
S…
Speaker 1 (2026-04-13 08-52-50)
here on the right -hand side,
6:30
S…
Speaker 1 (2026-04-13 08-52-50)
and I'll make that a little easier to see,
6:34
S…
Speaker 1 (2026-04-13 08-52-50)
the right -hand side right there where it says last 24 hours.
6:39
S…
Speaker 1 (2026-04-13 08-52-50)
The key you need to keep in mind there is to make sure whatever the
6:43
S…
Speaker 1 (2026-04-13 08-52-50)
time frame for the threat hunt you're performing,
6:46
S…
Speaker 1 (2026-04-13 08-52-50)
you have selected properly in here.
6:50
S…
Speaker 1 (2026-04-13 08-52-50)
There's a lot of presets you can use,
6:52
S…
Speaker 1 (2026-04-13 08-52-50)
including relative time information,
6:54
S…
Speaker 1 (2026-04-13 08-52-50)
and also one that just covers logs,
6:56
S…
Speaker 1 (2026-04-13 08-52-50)
all of the logs that are included in Splunk.
7:00
S…
Speaker 1 (2026-04-13 08-52-50)
You have real -time options for,
7:03
S…
Speaker 1 (2026-04-13 08-52-50)
you know, 24 hours ago.
7:04
S…
Speaker 1 (2026-04-13 08-52-50)
You can specify date ranges,
7:07
S…
Speaker 1 (2026-04-13 08-52-50)
date and time ranges,
7:08
S…
Speaker 1 (2026-04-13 08-52-50)
all kinds of things.
7:09
S…
Speaker 1 (2026-04-13 08-52-50)
So for the purposes of just kind of what we're looking at here,
7:13
S…
Speaker 1 (2026-04-13 08-52-50)
we're going to be looking at...
7:16
S…
Speaker 1 (2026-04-13 08-52-50)
all time just to make it simple to make sure we're including all
7:20
S…
Speaker 1 (2026-04-13 08-52-50)
of our logs here.
7:23
S…
Speaker 1 (2026-04-13 08-52-50)
I also mentioned earlier that Splunk is capable of doing things like
7:27
S…
Speaker 1 (2026-04-13 08-52-50)
real -time alerting,
7:28
S…
Speaker 1 (2026-04-13 08-52-50)
and that's where alerts would show up here in this alerts section.
7:31
S…
Speaker 2 (2026-04-13 08-52-50)
Of course,
7:32
S…
Speaker 1 (2026-04-13 08-52-50)
with the free version of Splunk,
7:34
S…
Speaker 1 (2026-04-13 08-52-50)
alerting is not included.
7:35
S…
Speaker 1 (2026-04-13 08-52-50)
You also have dashboards that can be configured in here,
7:38
S…
Speaker 1 (2026-04-13 08-52-50)
and there are some default dashboards that are included.
7:41
S…
Speaker 2 (2026-04-13 08-52-50)
But again,
7:42
S…
Speaker 1 (2026-04-13 08-52-50)
for the purposes of threat hunting,
7:45
S…
Speaker 1 (2026-04-13 08-52-50)
we're going to be looking primarily at just the searching.
7:49
S…
Speaker 1 (2026-04-13 08-52-50)
Now, we'll get into this when we start talking about SPL and how to construct
7:53
S…
Speaker 1 (2026-04-13 08-52-50)
different queries in Splunk.
7:55
S…
Speaker 1 (2026-04-13 08-52-50)
But one of the main things you have to keep in mind when you're making these searches,
7:59
S…
Speaker 1 (2026-04-13 08-52-50)
besides the time frame,
8:01
S…
Speaker 1 (2026-04-13 08-52-50)
which you can see as we switch screens at reset,
8:03
S…
Speaker 1 (2026-04-13 08-52-50)
we'll set it back to all time here,
8:05
S…
Speaker 1 (2026-04-13 08-52-50)
is that all data in Splunk is stored in an
8:09
S…
Speaker 1 (2026-04-13 08-52-50)
index.
8:09
S…
Speaker 1 (2026-04-13 08-52-50)
There are or can be multiple different indexes
8:14
S…
Speaker 1 (2026-04-13 08-52-50)
in any given Splunk installation.
8:17
S…
Speaker 1 (2026-04-13 08-52-50)
And that just depends on,
8:19
S…
Speaker 1 (2026-04-13 08-52-50)
you know, what the organization needs,
8:21
S…
Speaker 1 (2026-04-13 08-52-50)
how the organization wants to organize the logging information,
8:24
S…
Speaker 1 (2026-04-13 08-52-50)
things like that.
8:25
S…
Speaker 1 (2026-04-13 08-52-50)
There is a default index included in
8:30
S…
Speaker 1 (2026-04-13 08-52-50)
Splunk that's called main.
8:32
S…
Speaker 2 (2026-04-13 08-52-50)
Typically,
8:33
S…
Speaker 1 (2026-04-13 08-52-50)
best practices say to not put production data in
8:37
S…
Speaker 1 (2026-04-13 08-52-50)
that index and to use a custom index.
8:41
S…
Speaker 1 (2026-04-13 08-52-50)
For the purposes of this course and our labs,
8:44
S…
Speaker 1 (2026-04-13 08-52-50)
we will have an index called E -C -T -H -P.
8:48
S…
Speaker 1 (2026-04-13 08-52-50)
And that is how we're going to be starting all of
8:52
S…
Speaker 1 (2026-04-13 08-52-50)
our searches throughout this course when we're talking about Splunk.
8:56
S…
Speaker 1 (2026-04-13 08-52-50)
They will start with index equals E -C -T -H -P.
9:00
S…
Speaker 2 (2026-04-13 08-52-50)
We hit enter there,
9:01
S…
Speaker 1 (2026-04-13 08-52-50)
and we should get basically all the logs included in this
9:05
S…
Speaker 1 (2026-04-13 08-52-50)
lab.
9:06
S…
Speaker 1 (2026-04-13 08-52-50)
So we see here we have 4 ,156
9:11
S…
Speaker 1 (2026-04-13 08-52-50)
events recorded from that return,
9:16
S…
Speaker 1 (2026-04-13 08-52-50)
excuse me,
9:17
S…
Speaker 1 (2026-04-13 08-52-50)
from the search we just did.
9:20
S…
Speaker 1 (2026-04-13 08-52-50)
And again, we just did a search for index equals ecthp.
9:24
S…
Speaker 1 (2026-04-13 08-52-50)
which returns all of the data that is in
9:29
S…
Speaker 1 (2026-04-13 08-52-50)
that index because there's no other qualifiers,
9:31
S…
Speaker 1 (2026-04-13 08-52-50)
there's no other filters,
9:32
S…
Speaker 1 (2026-04-13 08-52-50)
there's nothing else that we specified in this search.
9:36
S…
Speaker 1 (2026-04-13 08-52-50)
So just a really quick introduction to Splunk,
9:41
S…
Speaker 1 (2026-04-13 08-52-50)
how Splunk is architected,
9:43
S…
Speaker 1 (2026-04-13 08-52-50)
and an introduction to what the interface looks like and
9:47
S…
Speaker 1 (2026-04-13 08-52-50)
how we're going to be starting off with searches.
9:49
S…
Speaker 1 (2026-04-13 08-52-50)
Again, as we progress through this course,
9:52
S…
Speaker 1 (2026-04-13 08-52-50)
We'll be diving into a lot more detail on how to create queries
9:57
S…
Speaker 1 (2026-04-13 08-52-50)
using SPL,
9:58
S…
Speaker 1 (2026-04-13 08-52-50)
the Splunk processing language,
10:00
S…
Speaker 1 (2026-04-13 08-52-50)
and more details of what we can look for,
10:04
S…
Speaker 1 (2026-04-13 08-52-50)
how we can adjust the results to kind of pivot throughout the threat
10:08
S…
Speaker 1 (2026-04-13 08-52-50)
hunt.
10:08
S…
Speaker 1 (2026-04-13 08-52-50)
But we'll be getting into more details as we go through this course in separate
10:13
S…
Speaker 1 (2026-04-13 08-52-50)
videos.
Dës Transkriptioun gouf vun AI (automatesch Sproocherkennung) generéiert. Et kann Feeler enthalen - iwwerpréift mat dem originelle Audio fir kritesch Benotzung. Politik
Zesummenfassung
D'Resultat ass eng synchroniséiert Transkriptioun vun der Transkriptiouns-Iwwersetzung.
Zesummenfaassung...
D'Lëscht vun de lëtzebuergesche Transkriptiounen
Et gëtt verschidden Aarte vu Referenzen, déi et och gëtt.