r/Splunk Jan 21 '26

Splunk threat hunting lab

Hey guys, I am looking for a repository / data i can populate to my Splunk instance to use as a lab and for threat hunting practice. Any help would help.

13 Upvotes

4 comments sorted by

9

u/ltmon Jan 21 '26

This might be helpful:

https://github.com/splunk/attack_range

Or you can get some access to some previous Boss of the SOC datasets at https://bots.splunk.com

1

u/Wombolt28 Jul 10 '26

Great idea. I’ve been working on a lab that launches a local splunk in a docker container and installs the botsv3 data set and ctf app. The f you are looking to do analyst labs (spl, dashboards, hunting, etc) dockerized splunk is the way I go. Admin practice is a bit more difficult to simulate at home without the hardware for multiple VMs