Splunk Docker Container for CloudTrail Analysis

Опубликовано: 17 Апрель 2026
на канале: 0xdf
1,440
67

When it comes to analysis of a large set of log files, it can be super useful to have an instance of Splunk available to work with. Getting Splunk set up can be intimidating, but it doesn't have to be. I'll show how to stand up a Splunk Docker container and load AWS Cloudtrail logs into it.

Splunk Docker: https://docs.splunk.com/Documentation...
HackTheBox Nublium-1: https://app.hackthebox.com/sherlocks/...

☕ Buy Me A Coffee: https://www.buymeacoffee.com/0xdf

[00:00] Introduction
[00:55] Data overview
[02:12] Creating Splunk container
[05:50] Loading data from folder
[08:28] Showing issue with data
[10:41] Creating single file without Records
[12:30] Clearing Splunk
[13:10] Uploading as _json
[14:14] Issues with _json
[19:38] Loading with custom source type
[22:55] Conclusion

#dfir #ctf #splunk #cloudtrail