back to day 18
WEEK_3 · DAY_18 · LAB
Lab 18 — Triage 5 Notables
The analyst's daily workspace
LAB PROGRESS0/4 steps · 0%
Lab Objectives
- ›Triage a Notable Event end-to-end
- ›Use the Adaptive Response menu
- ›Add events to an Investigation
- ›Manage status, owner, urgency, comments
Lab Instructions
- 1Open Splunk ES → Incident Review.
- 2Open each of the 5 pre-loaded Notable Events.
- 3For each: read the contributing SPL, write a triage note, decide escalate/close.
- 4Connect them — these 5 tell ONE attack story.