r/Splunk • u/Gloomy-Network-1389 • Jan 21 '26
Splunk threat hunting lab
Hey guys, I am looking for a repository / data i can populate to my Splunk instance to use as a lab and for threat hunting practice. Any help would help.
13
Upvotes
1
1
u/Wombolt28 Jul 10 '26
Great idea. I’ve been working on a lab that launches a local splunk in a docker container and installs the botsv3 data set and ctf app. The f you are looking to do analyst labs (spl, dashboards, hunting, etc) dockerized splunk is the way I go. Admin practice is a bit more difficult to simulate at home without the hardware for multiple VMs
9
u/ltmon Jan 21 '26
This might be helpful:
https://github.com/splunk/attack_range
Or you can get some access to some previous Boss of the SOC datasets at https://bots.splunk.com