soc30 / lms
connected
splunk>enterprise
Administrator ▾Settings ▾
ES
Enterprise Security
Splunk App for Enterprise Security · v7.3.0
DAY 1 LAB · LAB 1 — TOUR THE SOC PLATFORM· week 1
Tour the Splunk ES console — your daily workspace as a SOC analyst.
  • Click each top-level tab: Posture, Incident Review, Investigations, Sec Intelligence, Sec Domains, Audit, Search, Configure.
  • Open one Notable Event in Incident Review.
  • Note which views you'd use every shift.
Hint: Every tab here is a real Splunk ES view. Posture is exec-level; Incident Review is your home.

Security Posture

Key Security Indicators · click a tile to drill into Incident Review
Notable Events By Urgency
critical3
high4
medium2
low1
informational0
Notable Events Over Time
Top Notable Events
rule_namecount
Brute Force - Failed Logins1
Suspicious PowerShell EncodedCommand1
Threat Match - Network1
Lateral Movement - PsExec1
Mass File Encryption1
Phishing URL Clicked1
Top Sources
srccount
10.4.12.503
10.4.12.913
203.0.113.421
10.2.7.1101
Toronto/Berlin1