Write and run real SPL against a Splunk-shaped projection of the Northgate estate: CIM-normalised fields and Sysmon event codes across azure:aad:signin, WinEventLog:Security and Sysmon Operational. Every exercise gives you an editor, runs your query against the data and grades the result, so you practise finding the evidence rather than reading about it.
Multi-phase scenarios at full analyst depth, triage, investigate across the data, decide containment. Scored end to end.
Single-query exercises to build one SPL skill at a time. Start here.
Prevalence analysis, time bucketing and multi-stage aggregation, where the discriminator has to be earned rather than filtered for.