Splunk is the dominant commercial SIEM and log analytics platform. Its Search Processing Language (SPL) is one of the most expressive query languages in the industry, and CySA+ questions frequently quote SPL snippets.
What to know:
- Universal Forwarder vs Heavy Forwarder vs Indexer vs Search Head architecture.
- Data models, CIM, accelerated searches for Enterprise Security.
- SPL fundamentals:
index= ... | search ... | stats count by ... | sort - count. - Splunk ES correlation searches, notable events, and risk-based alerting.