📺 Livestream Timestamp: 30:00 — Home Lab Setup

SIEM, Log Analysis & Threat Detection

Overview

Adding a SIEM to your home lab is one of the highest-value upgrades you can make. A SIEM — Security Information and Event Management platform — collects logs from every machine in your environment, correlates events across sources, and surfaces alerts when something suspicious happens. Learning to use one in your lab prepares you for what you will encounter in every enterprise SOC.

Splunk in the Home Lab

Splunk is the most widely deployed commercial SIEM in enterprise environments. Splunk Free allows up to 500MB of data ingestion per day — more than enough for a home lab. Install Splunk on a dedicated Ubuntu VM, configure your other lab machines to forward their logs via the Splunk Universal Forwarder, and you have a functional SIEM in your own environment.

Once logs are flowing, you can write searches in SPL (Splunk Processing Language) to detect specific behaviors: failed login attempts, new user account creation, unusual process execution, lateral movement indicators. These are the same searches SOC analysts run in production environments.

What to Log

In your lab, configure log forwarding from your Ubuntu target (syslog, auth.log), your Kali machine (bash history, connection logs), and your Windows VMs (Security event log). When you attack your target and then pivot to Splunk, you should be able to find every step of the attack in the logs — which is exactly the exercise that First Watch is built around.

Key Takeaways

You do not need a job to learn Splunk. You need a lab. Install it, break things intentionally, and then find what you broke in the logs. That workflow — attack, detect, investigate — is the SOC analyst’s daily reality. Building it in your home lab makes you ready for it on day one.


Part of the free Intro to Cyber course by Cover6 Solutions.