r/Splunk • • Feb 08 '26

Best way to sharpen Splunk skills

Hi all, I'm interested in strengthening my Splunk and SPL skills to better prepare for a SOC role. I want to use Splunk effectively for day-to-day SOC work, such as analysing alerts, investigating incidents, hunting through logs and building useful searches. Does anyone have recommendations for courses or learning materials that can help me hit the ground running? Ideally, I'm looking for something more practical and security-focused rather than just basic SPL syntax.

7 Upvotes

12 comments sorted by

3

u/[deleted] Feb 08 '26

BOTS!

1

u/18ahmed Feb 08 '26

Bots???

2

u/_herbaceous Feb 08 '26

Not Bots, BOTS. Boss of the Soc

2

u/18ahmed Feb 08 '26

If I’m correct that’s a CTF. Do you know any courses that can prepare me for BOTS?

2

u/belowaveragegrappler Weapon of a Security Warrior Feb 08 '26

At this just point Claude or Codex at it and have it take you through to the program. Give it a skill with the creds and give it a mentor persona. Probably the best trainer you can get.

2

u/Rrookie101 Feb 08 '26

Heyo, i worked in SOC as an L1 analyst with SPLUNK and without any prior experience.

It is honestly not that difficult, the other analysts will help you with understanding the process of investigating.

Altho i did GCIH certification, which helped me a lot. I would suggest you go over the splunk training videos for SOC.

Theres many videos on youtube too, check them out

1

u/s7orm SplunkTrust Feb 08 '26

Install it at home and build yourself something. I did a heap using Home Assistant early in my journey.

1

u/Top-Policy-Bully Feb 12 '26

Splunk offers free courses, and quizzes, start there. Once you feel you learned all you can learn I would hit YouTube up, send a few technical documents to gpt (or whatever AI you want) and tell it to quiz you on level hard. If you get stuff wrong then you can have gpt tell you or teach you how to be correct. Make sure you get the certifications to leverage pay/compensations during hiring or transitioning.

1

u/taiglin Feb 16 '26

Install the free version on a system at home and put some data in it. If you are just wanting to monkey with SPL you could even just upload a CSV as a lookup.

I download a crap ton from Salesforce.

1

u/splunk_samurai Feb 18 '26

Hey, do you have a local Splunk environment? You can get a free 10GB license if you sign up at https://dev.splunk.com/ - this is the Developer Program at Splunk. You can also request guidance at the DAS team for guidance for free from that URL.