Splunk for Security Analysts

Learn SPL from your first search to mastery

Splunk's Search Processing Language, taught a rung at a time against a month of events from a company under attack. Every search runs in the page, every answer is checked, and nothing assumes you have written SPL before.

Included with Premium, from $19.99/month, or $179/year and save 25%. Preview the first module free, no account needed.
Practice included: graded Splunk drills, plus the Practice Hub.
View Pricing Take End of Course Exam → 40 CPE Credits

What you'll be able to do

✓Read, filter and shape any sourcetype in Splunk Enterprise and Splunk Cloud Platform
✓Count correctly: distinct counts, distributions, conditional counts, rates and the averages that mislead
✓Combine sources with lookups, subsearches, joins and stats, and count what each keeps and drops
✓Take text, JSON and multivalue fields apart, and build macros and knowledge objects a team can share
✓Put events in time and search data models with tstats, knowing what a model leaves out
✓Keep searches fast and answers right, including published and AI-written SPL
SEC405 | Premium tier | 10 teaching modules, an orientation and a Project | 36–40 hours at your own pace | 40 CPE credits

Course Syllabus

Every module and every lesson. The first three modules are open; the rest open on a click.

Download the full syllabus (PDF)

Orientation

Module 0Course OrientationCourse Preview

Splunk for Security Analysts: Splunk's Search Processing Language, taught against one month of an engineering company's events with several real attacks in them. What SPL is and where it runs, how Splunk stores events, the sourcetypes analysts search, Splunk Enterprise, Splunk Cloud Platform and SPL2, a first search, the practice lab, how the course climbs from basics to mastery, and a six-scenario check of whether it fits you.

Show 8 lessonsHide lessons
  1. 0.10.1 What SPL Is and Where It RunsPreview
  2. 0.20.2 How Splunk Stores EventsPreview
  3. 0.30.3 The Sourcetypes a Security Analyst SearchesPreview
  4. 0.40.4 Splunk Enterprise, Splunk Cloud Platform and SPL2Preview
  5. 0.50.5 Your First SearchPreview
  6. 0.60.6 The Practice Lab and the Sample MonthPreview
  7. 0.70.7 How to Learn SPL: the Mastery LadderPreview
  8. 0.80.8 What This Course BuildsPreview

Foundation

Module 1Search Structure and Fields

Module 1 of Splunk for Security Analysts: how a question becomes an SPL search, the search pipeline and command order, learning an unfamiliar sourcetype, field values and types, missing fields, checking a result, and reading a search you did not write.

Show 9 lessonsHide lessons
  1. 1.11.1 Turning a Question into SPL
  2. 1.21.2 The Search Pipeline
  3. 1.31.3 Command Order and Command Types
  4. 1.41.4 Learning a Sourcetype You Have Never Seen
  5. 1.51.5 Field Values and Types
  6. 1.61.6 Missing Fields and Nulls
  7. 1.71.7 Checking a Result Against Its Events
  8. 1.81.8 Reading a Search You Did Not Write
  9. 1.9Module Summary and Knowledge Check
Module 2Searching and Filtering

Module 2 of Splunk for Security Analysts: how the base search chooses events. Search terms and segments, field values and Boolean logic, wildcards, time ranges, search versus where, addresses and CIDR, fields inside JSON, and negative filters.

Show 9 lessonsHide lessons
  1. 2.12.1 Search Terms and the Index
  2. 2.22.2 Field Values and Boolean Logic
  3. 2.32.3 Wildcards and Matching
  4. 2.42.4 Time Ranges and Time Modifiers
  5. 2.52.5 search Versus where
  6. 2.62.6 Addresses and CIDR
  7. 2.72.7 Fields Inside JSON
  8. 2.82.8 Negative Filters
  9. 2.9Module Summary and Knowledge Check
Module 3Shaping Results

Module 3 of Splunk for Security Analysts: what a search does with the events it chose. eval expressions, if and case, text and time functions, table, fields and rename, sort, head and tail, dedup, and presenting a result.

Show 9 lessonsHide lessons
  1. 3.13.1 eval Expressions
  2. 3.23.2 if, case and Labels
  3. 3.33.3 Text Functions
  4. 3.43.4 Time Formats
  5. 3.53.5 table, fields and rename
  6. 3.63.6 sort, head and tail
  7. 3.73.7 dedup
  8. 3.83.8 Presenting a Result
  9. 3.9Module Summary and Knowledge Check

Intermediate

Module 4Statistics

Module 4 of Splunk for Security Analysts: summarizing events into numbers that mean something. stats, counting correctly, distributions and percentiles, conditional statistics, values and list, timechart, chart, xyseries and untable, and the rates and averages that mislead.

Show 9 lessonsHide lessons
  1. 4.14.1 The stats Command
  2. 4.24.2 Counting Correctly
  3. 4.34.3 Distributions and Percentiles
  4. 4.44.4 Conditional Statistics
  5. 4.54.5 values and list
  6. 4.64.6 timechart
  7. 4.74.7 chart, xyseries and untable
  8. 4.84.8 Rates and the Averages That Mislead
  9. 4.9Module Summary and Knowledge Check
Module 5Combining Data

Module 5 of Splunk for Security Analysts: bringing data together. Lookups and lookup tables, subsearches and their limits, join and its limits, append and appendcols, multisearch and union, correlating with stats instead of join, and correlating across time.

Show 9 lessonsHide lessons
  1. 5.15.1 Lookups
  2. 5.25.2 inputlookup and Lookup Tables
  3. 5.35.3 Subsearches and Their Limits
  4. 5.45.4 join and Its Limits
  5. 5.55.5 append and appendcols
  6. 5.65.6 multisearch and union
  7. 5.75.7 Correlating with stats
  8. 5.85.8 Correlating Across Time
  9. 5.9Module Summary and Knowledge Check
Module 6Text and Multivalue Data

Module 6 of Splunk for Security Analysts: working inside fields. rex and its sed mode, the regex command, spath and JSON, multivalue fields, makemv, split and mvexpand, multivalue functions, key-value data and decoding.

Show 9 lessonsHide lessons
  1. 6.16.1 rex
  2. 6.26.2 rex in sed Mode and the regex Command
  3. 6.36.3 spath and JSON
  4. 6.46.4 Multivalue Fields
  5. 6.56.5 makemv, split and mvexpand
  6. 6.66.6 Multivalue Functions
  7. 6.76.7 Key-Value Data
  8. 6.86.8 Decoding
  9. 6.9Module Summary and Knowledge Check

Advanced

Module 7Macros, Lookups and Knowledge Objects

Module 7 of Splunk for Security Analysts: logic written once and used everywhere. Search macros and macros with arguments, lookup definitions, field aliases and calculated fields, event types and tags, saved searches, foreach and reusable eval patterns.

Show 9 lessonsHide lessons
  1. 7.17.1 Search Macros
  2. 7.27.2 Macros with Arguments
  3. 7.37.3 Lookup Definitions
  4. 7.47.4 Field Aliases and Calculated Fields
  5. 7.57.5 Event Types and Tags
  6. 7.67.6 Saved Searches
  7. 7.77.7 foreach
  8. 7.87.8 Reusable eval Patterns
  9. 7.9Module Summary and Knowledge Check
Module 8Time and Sequence

Module 8 of Splunk for Security Analysts: events in time. bin and span, comparing periods, eventstats baselines, streamstats windows, delta and the previous event, transaction and sessions, first and last per entity, and running totals.

Show 9 lessonsHide lessons
  1. 8.18.1 bin and span
  2. 8.28.2 Comparing Periods
  3. 8.38.3 eventstats Baselines
  4. 8.48.4 streamstats Windows
  5. 8.58.5 delta and the Previous Event
  6. 8.68.6 transaction and Sessions
  7. 8.78.7 First and Last per Entity
  8. 8.88.8 Running Totals
  9. 8.9Module Summary and Knowledge Check
Module 9Data Models and tstats

Module 9 of Splunk for Security Analysts: the Common Information Model, data models and datasets, the datamodel command, tstats, summariesonly and acceleration, tstats with by and where, rewriting raw searches for data models, and checking when a data model answers differently.

Show 9 lessonsHide lessons
  1. 9.19.1 The Common Information Model
  2. 9.29.2 Data Models and Datasets
  3. 9.39.3 The datamodel Command
  4. 9.49.4 tstats
  5. 9.59.5 summariesonly and Acceleration
  6. 9.69.6 tstats with by and where
  7. 9.79.7 From Raw Search to Data Model Search
  8. 9.89.8 When a Data Model Answers Differently
  9. 9.9Module Summary and Knowledge Check

Mastery

Module 10Search Optimization and Validation

Module 10 of Splunk for Security Analysts: how a search runs, filtering first, command types and placement, transforming early, limits and truncation, reading and adapting public searches, checking the answer, checking AI-written SPL, and from SPL to SPL2.

Show 10 lessonsHide lessons
  1. 10.110.1 How a Search Runs
  2. 10.210.2 Filter First
  3. 10.310.3 Command Types and Placement
  4. 10.410.4 Transforming Early
  5. 10.510.5 Limits and Truncation
  6. 10.610.6 Reading and Adapting Public Searches
  7. 10.710.7 Checking the Answer
  8. 10.810.8 Checking AI-Written SPL
  9. 10.910.9 From SPL to SPL2
  10. 10.10Module Summary and Knowledge Check

Phase 0: Course Resources

ResourcesCheatsheets

One sheet per module of Splunk for Security Analysts, each entry a question, a search that answers it against the sample month, what to read and what the answer does not prove.

Show 11 lessonsHide lessons
  1. 1Sources and the Lab
  2. 2Search Structure and Fields
  3. 3Searching and Filtering
  4. 4Shaping Results
  5. 5Statistics
  6. 6Combining Data
  7. 7Text and Multivalue Data
  8. 8Macros, Lookups and Knowledge Objects
  9. 9Time and Sequence
  10. 10Data Models and tstats
  11. 11Optimization and Validation
ResourcesCookbooks

Procedures for the problems every SPL user meets: a search that returns nothing, a search that is too slow, and a source nobody has searched before.

Show 3 lessonsHide lessons
  1. 1A Search Returns Nothing
  2. 2A Search Is Too Slow
  3. 3Taking Apart an Unfamiliar Source
ResourcesLab Setup

The practice lab the course runs in, and how to get a Splunk of your own for the Project: an employer's deployment, Splunk Enterprise on its trial or Free license, or a Splunk Cloud Platform trial.

Show 2 lessonsHide lessons
  1. 1The Practice Lab
  2. 2Your Own Splunk
ResourcesWalkthroughs

Six searches from the course that ran cleanly and answered wrongly, each taken step by step to the right answer: a sort's limit, an early head, a missing field, a silent detection, a lookup's default and a ranking.

Show 6 lessonsHide lessons
  1. 1The Month That Was Twelve Days
  2. 2The Answer About Four Days
  3. 3The Field That Was Not There
  4. 4The Detection That Never Fired
  5. 5The Country Everyone Came From
  6. 6The Exfiltration That Ranked Third
ResourcesSearch Patterns

Six search patterns analysts reuse: first time seen, rare in the population, volume against its own normal, many accounts from one source, regular gaps, and success after failures. Each with a search that runs against the sample month.

Show 6 lessonsHide lessons
  1. 1First Time Seen
  2. 2Rare in the Population
  3. 3Volume Against Its Own Normal
  4. 4Many Accounts From One Source
  5. 5Regular Gaps
  6. 6Success After Failures
ResourcesPlayground

Resources for practicing SPL and using it at work: a free-run search console, two guided SPL drills, the detection library, response playbooks, and an open-source DFIR toolkit.

ResourcesOperational Reference

Every command, function, check and limit from Splunk for Security Analysts in one place, organized by the task in front of you and linked back to the section that explains it.

Show 1 lessonHide lessons
  1. 1Operational Reference
ResourcesReferences & Further Reading

The documentation behind Splunk for Security Analysts, arranged by the question it answers: the language, where searches run and their limits, getting a Splunk to practice on, and published detections.

Project

ResourcesProject: Your Own Search Library

The Splunk for Security Analysts project: a brief for a library of twenty searches you build on your own Splunk data, each answering a stated question, each checked, with its source's pitfalls and its cost noted, and one taken to the quality of a scheduled search. No submission, no grading.

Show 1 lessonHide lessons
  1. 1The Brief

Course Completion

CompletionCourse Exam

Splunk for Security Analysts end-of-course exam: twenty tasks, two per teaching module, each answered by writing SPL against the course's sample month and checked on the server.

Show 1 lessonHide lessons
  1. 1Course Completion. Splunk for Security Analysts

Course overview

SPL is how security analysts ask questions of Splunk: who signed in from where, which machine talked to which address, what an account did after it was compromised. This course teaches the language itself, from the shape of a first search to data models, time and sequence, and the checks that make an answer defensible, in Splunk Enterprise and Splunk Cloud Platform alike.

It is taught against one month of events from Northgate Engineering, an 810-person company whose month holds ordinary work and several real attacks: password guessing, a password spray, repeated multi-factor prompts, files taken from SharePoint, ransomware preparation, a beacon and data sent out through the firewall. The course finds them with the searches it teaches.

How this course works

Every search runs in the page. A practice lab built into each lesson holds the sample month in eleven indexes with real sourcetype names and fields, five lookup tables and seven data models. Change a search, run it, and see what changed.

Predict, then run. Many searches ask for your prediction before they show their result, so every search is a small test of your understanding.

Three exercises in every lesson. Complete a search, fix a broken one, and write one from a blank editor, each graded on the result it returns. Each module ends with a knowledge check and a challenge set of questions the lessons did not answer.

Check every answer. The course treats an empty result, a round number and a borrowed, published or AI-written search as things to verify before anyone relies on them, and teaches the checks that do it.

What you will learn

✓ Read, filter and shape any sourcetype, and know which sources hold which answers
✓ Count correctly: distinct counts, distributions, conditional counts, rates and the averages that mislead
✓ Combine sources with lookups, subsearches, joins and stats, and count what each one keeps and drops
✓ Take text, JSON and multivalue fields apart with rex, spath, makemv and mvexpand, and decode what attackers encode
✓ Build macros, lookup definitions, event types and saved searches a team can share
✓ Put events in time with bin, baselines, running windows, sessions and first-seen searches
✓ Search data models with tstats, and check what a model and its acceleration leave out
✓ Keep searches fast and answers right: filter first, know the limits that cut results short, and check published and AI-written SPL

Who this course is for

Anyone who needs to search security data in Splunk: SOC analysts, incident responders, detection engineers and threat hunters, and people moving into those roles. No experience with SPL or any other query language is assumed; every command is explained where it is first used.

Readers who already write SPL will find the later modules go well past the basics, and the Course Fit Check in the free orientation shows where you sit.

What you will build

✓ A search library of your own: twenty checked searches on your own data, each with its question, period, check and cost, built in the Project
✓ One search taken to the quality of a scheduled search, with a measured threshold and a tested known case
✓ The habits that make answers defensible: counting before trusting, stating what was checked, and saying what an answer does not prove

What this course does not cover

Splunk administration, Splunk Enterprise Security administration, and dashboard building each sit outside this course. Detection engineering as a program and threat hunting methodology have their own courses on the platform. This course teaches the language they all depend on.

Things you need to know

What are the prerequisites?

None. The course teaches SPL from first principles, and the free orientation module explains the language, how Splunk stores events and the sourcetypes an analyst searches before the first lesson.

What do I need to run the queries?

A device with a modern browser. Every search in the course runs in the practice lab built into the page. For the Project you search your own data, in a Splunk deployment you are allowed to use or one you install; the lab setup pages explain the routes and the licensing.

How is the course assessed?

By a search-based exam: twenty tasks, two per teaching module, each answered by writing SPL against the sample month and checked on the server. Passing at 70 earns the Splunk for Security Analysts certificate with CPE credit.

Usage rights and disclaimer

Course materials: Licensed for individual professional development. You may use the searches you write in your own environment. You may not redistribute course content or share account credentials.

Fictional environment: All scenarios use Northgate Engineering. Any resemblance to real organizations is coincidental.

COURSE ASSESSMENT

End of Course Exam

Complete the course, then write the searches: twenty tasks answered against the sample month, no time limit. Pass mark: 70. Earn your certificate with CPE credits.

20tasks
10modules
100points
Take End of Course Exam

Answers are checked on the server. Certificate issued on pass.