Skip to content

AdamsCodeAndProjects/splunk-siem-failed-logins

Folders and files

NameName
Last commit message
Last commit date

Latest commit

Β 

History

2 Commits
Β 
Β 

Repository files navigation

splunk-siem-failed-logins

Home lab SIEM project using Splunk to detect failed login attempts

🧠 Splunk SIEM Home Lab – Detecting Failed Logins

πŸ“Œ Project Overview

This home lab simulates a real-world SIEM setup using Splunk to detect and alert on failed login attempts. I generated custom log data and used dashboards to visualize suspicious behavior, demonstrating basic detection engineering and log analysis skills.


Tools Used

  • πŸ–₯️ Splunk (Free version, installed locally)
  • πŸͺŸ Windows 10 VM (Simulated attacker machine)
  • βš™οΈ Manual data upload or log ingestion (via Splunk web UI)
  • πŸ“¦ VirtualBox (for virtual machine management)

What I Did

  1. Installed and configured Splunk in a virtual environment
  2. Simulated multiple failed login attempts on a Windows VM
  3. Uploaded or ingested logs into Splunk
  4. Used Splunk Search Processing Language (SPL) to find failed login events
  5. Built a dashboard to visualize login failure patterns
  6. Analyzed log entries to identify login behavior and potential brute force attempts

πŸ“Έ Screenshots

Splunk Dashboard Log Sample
SIEM

πŸ“š Key Skills Demonstrated

  • SIEM setup and log ingestion
  • Log parsing and dashboard creation
  • Detection engineering (MITRE ATT&CK mapping)
  • Basic threat simulation in a safe lab environment

How To Recreate This Lab Instructions coming soon...


LinkedIn Post https://www.linkedin.com/feed/update/urn:li:activity:7345527308415340545/

About

Home lab SIEM project using Splunk to detect failed login attempts

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published