Splunk is the language of the SOC, and like any language, you only get fluent by using it on real traffic. This Cover6 Community session runs live queries against real attack traffic from Cover6 infrastructure, builds the searches an analyst leans on every shift, and walks the full triage workflow — from an alert firing to the decision to escalate.
Use this post as your read-ahead, then come back to it as a reference for the query shapes and the mindset.
The analyst’s job, in one sentence
A SOC analyst turns a flood of events into a short list of things that matter. Logs come in from everywhere — firewalls, endpoints, authentication systems, web servers — and the job is to decide, quickly and defensibly, what’s normal, what’s suspicious, and what gets handed up the chain. The tool most teams use to do that is a SIEM, and in a huge number of shops that SIEM is Splunk.
SPL: the searches you’ll actually use
Search Processing Language (SPL) is how you ask Splunk questions. You don’t need all of it to be useful — you need a handful of patterns and the instinct for which one to reach for.
Start by scoping to a source and counting what’s there:
index=firewall action=blocked
| stats count by src_ip
| sort - count
That single pattern — filter, then stats count by, then sort — answers a huge share of real questions. Who’s hitting us most? What’s failing most? Where is this coming from?
Failed logins are the classic starting point for catching brute force:
index=auth action=failure
| stats count by user, src_ip
| where count > 10
And the move that actually catches an attacker is pairing failure with success — many failures followed by one success, from the same source, is a login that worked after a lot of guessing:
index=auth
| stats count(eval(action="failure")) as fails count(eval(action="success")) as wins by src_ip, user
| where fails > 10 AND wins > 0
The point isn’t to memorize these. It’s to internalize the shape: narrow to the right data, aggregate, then filter to the anomaly.
Correlation searches and dashboards
Two ideas turn ad-hoc searching into a working SOC:
- Correlation searches are saved searches that run on a schedule and raise an alert when a condition is met (like that failure-then-success pattern). They’re how detection happens while no one is staring at the screen.
- Dashboards are the at-a-glance view: the panels an analyst scans at the top of a shift to see the shape of the day — top blocked sources, authentication failures over time, new hosts, spikes. A good dashboard answers “is anything on fire?” in about five seconds.
Security Onion rounds out the picture with its own detection dashboards, giving you a second, open-source lens on the same traffic.
The triage workflow: alert to escalation
When an alert fires, the work is a loop, not a verdict:
- Scope it. What fired, on which host, for which user, and when? Pull the surrounding events, not just the one that alerted.
- Investigate. Is this real or is it noise? Pivot across log sources — the auth log says one thing, the endpoint log confirms or contradicts it. Build the timeline.
- Decide. Benign (tune the rule so it doesn’t cry wolf again), or real (escalate with the timeline and the evidence attached).
- Escalate cleanly. The next person should be able to pick up your investigation without redoing it. The write-up is the deliverable.
That’s the analyst mindset: every alert gets the same disciplined pass, and the output is always something someone else can act on.
Work your first shift, free
Reading SPL is one thing; working an alert queue is another. First Watch drops you into a live Splunk lab with real data and gives you your first SOC shift — free, in your browser, nothing to install.
👉 Start here, free: https://www.cover6solutions.com/product/cover6-first-watch-free-access/
As you work it, run the loop from this post: scope the alert, pivot across sources, build the timeline, decide.
Where this path leads
SIEM and incident response are the core of the SOC Analyst lane on Chrysalus. Build your free profile and add your First Watch investigation as a project.
- Read the SOC Analyst Roadmap 2026.
- Want the deeper version? The SOC Analyst Prep Labs take this from fundamentals to job-ready.
- Use the Cover6 Field Manual as a free reference, and browse every Cover6 course.
- Join The 6, our free newsletter, to catch the next session.
Watch the replay
We ran this live in the Cover6 Community, with real queries against real attack traffic. Planning to attend a future meetup? Use this post as your read-ahead, and catch the replay above.
