Splunk: Setting up a SOC lab

8000

./bin/splunk search coffely

8089

syslog

6

/etc/group

8000

3

Local Event Logs

C:\Program Files\Splunk UniversalForwarder

9997

5

An account was successfully logged on

{COffely_Is_Best_iN_TOwn}