cyberguypr wrote: » Are you in an admin role or more of a power user?
veritas_libertas wrote: » Unfortunately I've found that Splunk is one of those tools you have to dive into in order to learn. I haven't seen much as far books, there are a few good blogs and web sites out there to help with writing queries.
veritas_libertas wrote: » Out of curiosity, are you in a security role?
xxxkaliboyxxx wrote: » Not sure what your role is, but I have watch some talks on YouTube about IR and threat hunting with Splunk. Just search for those terms on YT.
McxRisley wrote: » Network security team lead will be my official role title, but I will be mainly dealing with log monitoring and occasionally doing some offensive stuff. I've been pushing for them to finally let us do pentesting here but upper management is the issue with that happening. I was previously a pentester at my last company.