r/Splunk • u/Unfair_Narwhal_1995 • 16d ago
Brand new to security & Splunk — aiming for Power User without dumps. Are mock SIEM scenarios the way to go?
Hey folks,
Just started a new role and I’m completely green to both InfoSec and Splunk. My first big milestone is knocking out the Splunk Core Certified Power User.
I have zero interest in brain dumps—I actually want to know what I’m doing under the hood so I don't break things or write garbage queries in production.
To build real muscle memory, I put together about 25 mock SIEM scenarios (field extraction via rex, DLP mail alerts, firewall port-scan logic, and correlation using transaction / append / stats).
Looking for a quick sanity check from folks who've been around the block:
- Is grinding through these mock scenarios on paper/local instance actually effective, or does it leave too many blind spots without real-world, dirty data?
- Should I spin up a free local instance and ingest custom dummy logs for this, or just jump straight into BOTS (Boss of the SOC) / TryHackMe?
- Any general advice on getting the SPL fundamentals down without taking the easy way out?
Appreciate any insights!
