Splunk for Security Analysts
Learn SPL from your first search to mastery
Splunk's Search Processing Language, taught a rung at a time against a month of events from a company under attack. Every search runs in the page, every answer is checked, and nothing assumes you have written SPL before.
What you'll be able to do
Course Syllabus
Every module and every lesson. The first three modules are open; the rest open on a click.
Download the full syllabus (PDF)
Orientation
Splunk for Security Analysts: Splunk's Search Processing Language, taught against one month of an engineering company's events with several real attacks in them. What SPL is and where it runs, how Splunk stores events, the sourcetypes analysts search, Splunk Enterprise, Splunk Cloud Platform and SPL2, a first search, the practice lab, how the course climbs from basics to mastery, and a six-scenario check of whether it fits you.
Show 8 lessonsHide lessons
- 0.10.1 What SPL Is and Where It RunsPreview
- 0.20.2 How Splunk Stores EventsPreview
- 0.30.3 The Sourcetypes a Security Analyst SearchesPreview
- 0.40.4 Splunk Enterprise, Splunk Cloud Platform and SPL2Preview
- 0.50.5 Your First SearchPreview
- 0.60.6 The Practice Lab and the Sample MonthPreview
- 0.70.7 How to Learn SPL: the Mastery LadderPreview
- 0.80.8 What This Course BuildsPreview
Foundation
Module 1 of Splunk for Security Analysts: how a question becomes an SPL search, the search pipeline and command order, learning an unfamiliar sourcetype, field values and types, missing fields, checking a result, and reading a search you did not write.
Show 9 lessonsHide lessons
- 1.11.1 Turning a Question into SPL
- 1.21.2 The Search Pipeline
- 1.31.3 Command Order and Command Types
- 1.41.4 Learning a Sourcetype You Have Never Seen
- 1.51.5 Field Values and Types
- 1.61.6 Missing Fields and Nulls
- 1.71.7 Checking a Result Against Its Events
- 1.81.8 Reading a Search You Did Not Write
- 1.9Module Summary and Knowledge Check
Module 2 of Splunk for Security Analysts: how the base search chooses events. Search terms and segments, field values and Boolean logic, wildcards, time ranges, search versus where, addresses and CIDR, fields inside JSON, and negative filters.
Show 9 lessonsHide lessons
Module 3 of Splunk for Security Analysts: what a search does with the events it chose. eval expressions, if and case, text and time functions, table, fields and rename, sort, head and tail, dedup, and presenting a result.
Intermediate
Module 4 of Splunk for Security Analysts: summarizing events into numbers that mean something. stats, counting correctly, distributions and percentiles, conditional statistics, values and list, timechart, chart, xyseries and untable, and the rates and averages that mislead.
Show 9 lessonsHide lessons
Module 5 of Splunk for Security Analysts: bringing data together. Lookups and lookup tables, subsearches and their limits, join and its limits, append and appendcols, multisearch and union, correlating with stats instead of join, and correlating across time.
Module 6 of Splunk for Security Analysts: working inside fields. rex and its sed mode, the regex command, spath and JSON, multivalue fields, makemv, split and mvexpand, multivalue functions, key-value data and decoding.
Advanced
Module 7 of Splunk for Security Analysts: logic written once and used everywhere. Search macros and macros with arguments, lookup definitions, field aliases and calculated fields, event types and tags, saved searches, foreach and reusable eval patterns.
Module 8 of Splunk for Security Analysts: events in time. bin and span, comparing periods, eventstats baselines, streamstats windows, delta and the previous event, transaction and sessions, first and last per entity, and running totals.
Module 9 of Splunk for Security Analysts: the Common Information Model, data models and datasets, the datamodel command, tstats, summariesonly and acceleration, tstats with by and where, rewriting raw searches for data models, and checking when a data model answers differently.
Show 9 lessonsHide lessons
- 9.19.1 The Common Information Model
- 9.29.2 Data Models and Datasets
- 9.39.3 The datamodel Command
- 9.49.4 tstats
- 9.59.5 summariesonly and Acceleration
- 9.69.6 tstats with by and where
- 9.79.7 From Raw Search to Data Model Search
- 9.89.8 When a Data Model Answers Differently
- 9.9Module Summary and Knowledge Check
Mastery
Module 10 of Splunk for Security Analysts: how a search runs, filtering first, command types and placement, transforming early, limits and truncation, reading and adapting public searches, checking the answer, checking AI-written SPL, and from SPL to SPL2.
Show 10 lessonsHide lessons
- 10.110.1 How a Search Runs
- 10.210.2 Filter First
- 10.310.3 Command Types and Placement
- 10.410.4 Transforming Early
- 10.510.5 Limits and Truncation
- 10.610.6 Reading and Adapting Public Searches
- 10.710.7 Checking the Answer
- 10.810.8 Checking AI-Written SPL
- 10.910.9 From SPL to SPL2
- 10.10Module Summary and Knowledge Check
Phase 0: Course Resources
One sheet per module of Splunk for Security Analysts, each entry a question, a search that answers it against the sample month, what to read and what the answer does not prove.
Procedures for the problems every SPL user meets: a search that returns nothing, a search that is too slow, and a source nobody has searched before.
Show 3 lessonsHide lessons
The practice lab the course runs in, and how to get a Splunk of your own for the Project: an employer's deployment, Splunk Enterprise on its trial or Free license, or a Splunk Cloud Platform trial.
Show 2 lessonsHide lessons
Six searches from the course that ran cleanly and answered wrongly, each taken step by step to the right answer: a sort's limit, an early head, a missing field, a silent detection, a lookup's default and a ranking.
Six search patterns analysts reuse: first time seen, rare in the population, volume against its own normal, many accounts from one source, regular gaps, and success after failures. Each with a search that runs against the sample month.
Resources for practicing SPL and using it at work: a free-run search console, two guided SPL drills, the detection library, response playbooks, and an open-source DFIR toolkit.
Every command, function, check and limit from Splunk for Security Analysts in one place, organized by the task in front of you and linked back to the section that explains it.
Show 1 lessonHide lessons
The documentation behind Splunk for Security Analysts, arranged by the question it answers: the language, where searches run and their limits, getting a Splunk to practice on, and published detections.
Project
The Splunk for Security Analysts project: a brief for a library of twenty searches you build on your own Splunk data, each answering a stated question, each checked, with its source's pitfalls and its cost noted, and one taken to the quality of a scheduled search. No submission, no grading.
Show 1 lessonHide lessons
Course Completion
Splunk for Security Analysts end-of-course exam: twenty tasks, two per teaching module, each answered by writing SPL against the course's sample month and checked on the server.
Show 1 lessonHide lessons
Course overview
SPL is how security analysts ask questions of Splunk: who signed in from where, which machine talked to which address, what an account did after it was compromised. This course teaches the language itself, from the shape of a first search to data models, time and sequence, and the checks that make an answer defensible, in Splunk Enterprise and Splunk Cloud Platform alike.
It is taught against one month of events from Northgate Engineering, an 810-person company whose month holds ordinary work and several real attacks: password guessing, a password spray, repeated multi-factor prompts, files taken from SharePoint, ransomware preparation, a beacon and data sent out through the firewall. The course finds them with the searches it teaches.
How this course works
Every search runs in the page. A practice lab built into each lesson holds the sample month in eleven indexes with real sourcetype names and fields, five lookup tables and seven data models. Change a search, run it, and see what changed.
Predict, then run. Many searches ask for your prediction before they show their result, so every search is a small test of your understanding.
Three exercises in every lesson. Complete a search, fix a broken one, and write one from a blank editor, each graded on the result it returns. Each module ends with a knowledge check and a challenge set of questions the lessons did not answer.
Check every answer. The course treats an empty result, a round number and a borrowed, published or AI-written search as things to verify before anyone relies on them, and teaches the checks that do it.
What you will learn
Who this course is for
Anyone who needs to search security data in Splunk: SOC analysts, incident responders, detection engineers and threat hunters, and people moving into those roles. No experience with SPL or any other query language is assumed; every command is explained where it is first used.
Readers who already write SPL will find the later modules go well past the basics, and the Course Fit Check in the free orientation shows where you sit.
What you will build
What this course does not cover
Splunk administration, Splunk Enterprise Security administration, and dashboard building each sit outside this course. Detection engineering as a program and threat hunting methodology have their own courses on the platform. This course teaches the language they all depend on.
Things you need to know
What are the prerequisites?
None. The course teaches SPL from first principles, and the free orientation module explains the language, how Splunk stores events and the sourcetypes an analyst searches before the first lesson.
What do I need to run the queries?
A device with a modern browser. Every search in the course runs in the practice lab built into the page. For the Project you search your own data, in a Splunk deployment you are allowed to use or one you install; the lab setup pages explain the routes and the licensing.
How is the course assessed?
By a search-based exam: twenty tasks, two per teaching module, each answered by writing SPL against the sample month and checked on the server. Passing at 70 earns the Splunk for Security Analysts certificate with CPE credit.
Usage rights and disclaimer
Course materials: Licensed for individual professional development. You may use the searches you write in your own environment. You may not redistribute course content or share account credentials.
Fictional environment: All scenarios use Northgate Engineering. Any resemblance to real organizations is coincidental.
End of Course Exam
Complete the course, then write the searches: twenty tasks answered against the sample month, no time limit. Pass mark: 70. Earn your certificate with CPE credits.
Answers are checked on the server. Certificate issued on pass.