How I Built a Splunk Homelab for Splunk Certified Core User (SPLK-1001) — Installation, SPL Queries & Dashboard Practice

How I Built a Splunk Homelab for Splunk Certified Core User (SPLK-1001) — Installation, SPL Queries & Dashboard Practice

in

How I Built a Splunk Homelab for Splunk Certified Core User (SPLK-1001) — Installation, SPL Queries & Dashboard Practice

A step-by-step hands-on lab to practice Windows log ingestion, SPL commands, reporting and dashboard creation using Splunk Enterprise

1_RFU1NAREsIt9CbeWzD1GWg.jpg

Introduction

While preparing for the Splunk Certified Core User (SPLK-1001) certification, I built a small Splunk homelab to run my own instance and gain hands-on experience with key Splunk concepts.

This article describes my setup process and provides step-by-step practical exercises that can help anyone preparing for the exam or looking to strengthen their foundational Splunk skills.

My lab includes installing and configuring Splunk Enterprise and the Splunk Universal Forwarder, setting up Splunk to receive Windows logs from my workstation, and practicing SPL (Search Processing Language) queries. I also demonstrate how to use the Splunk web interface to create reports and dashboards based on real log data.

These exercises proved instrumental in my own preparation, and I am happy to say I successfully passed the SPLK-1001 exam.


Project Overview

In this section, I present a diagram that summarizes the setup and workflow of my Splunk homelab. This visual representation highlights the key components and how they interact within the environment, giving you a clearer understanding of how everything functions together.

1_5N9KPR-DL0OY62irv_AOAQ.jpg

Icon credits: The Chohands Brand, pojok d, Nikita Golubev, Syahrul Ramadhany, Febricon & Royyan Wijaya


Contents

  • Installation and Configuration
  • Splunk Queries and Creating Reports  Practical Exercises
    • Exercise 1: General Query
    • Exercise 2: Filtering Events and Using | stats count
    • Exercise 3: Time-Based Visualization with | timechart
    • Exercise 4: Creating a | table of Recent Failures
    • Exercise 5: Using | top to Identify Failure Reasons
    • Exercise 6: Single Value Visualization with Trend and Sparkline
  • Splunk Dashboard  Practical Exercises
    • Exercise 7: Creating a Dashboard
    • Exercise 8: Adding Panels
    • Exercise 9: Setting as Home Dashboard

Installation and Configuration

Below is a concise overview of the tasks performed to get my Splunk instance and Universal Forwarder up and running. Since this post focuses primarily on Splunk usage (interface, SPL commands, reports, and dashboards), I am not going into deep installation detail here.

1. Splunk Installation and Setup

  • I downloaded Splunk Enterprise and the Splunk Universal Forwarder and verified file integrity.
  • I installed Splunk and created the administrator account.
  • After installation, Splunk was accessible using the newly created administrator credentials.
  • In Settings > Forwarding and Receiving, I selected Configure Receiving and then + Add new.
  • I configured Splunk to listen on the default port 9997 and saved the configuration.

2. Forwarder Installation and Setup

  • I installed the Universal Forwarder using the option: An on-premises Splunk Enterprise instance.
  • I created the forwarder administrator account.
  • I configured it using the default values:
  • Deployment server: 127.0.0.1:8089
  • Listener: 127.0.0.1:9997
  • In Splunk, under Settings > Agent Management, my host details became available.

3. Receiving Data

  • In Settings > Add Data, I selected Forward data from a Splunk Forwarder.
  • In Select Forwarders, I created a New Server Class Name and selected it.
  • In Select Source, I chose Local Event Logs and selected:
  • Application
  • Security
  • System
  • In Input Settings, I created a new index called win_logs and selected it.
  • After reviewing the configuration, I clicked Submit.

For step-by-step screenshots and deeper explanations, I recommend:


Splunk Queries and Creating Reports  Practical Exercises

Exercise 1: General Query

Retrieve all events from the win_logs index:

index=win_logs

If the installation and configuration were successful, all indexed results should appear.

1_MOMltapubgQNYh_pi6ZY9g.jpg


Important Note About the Exercises

In most of these practical exercises, I use a general query that searches for events containing the key-value pair:

Keywords="Audit Failure"

The “Audit Failure” keyword indicates a failure in an audited operation, such as failed logon attempts (Event ID 4625), account lockouts, or access denials to a resource. When ingested into Splunk, these events typically include:

  • Failed user logons or authentication attempts
  • Privilege use denials or policy violations
  • Object access attempts blocked by permissions

This makes the dataset very practical for cybersecurity-oriented analysis, such as threat hunting or security investigations.


Exercise 2: Filtering Events and Using | stats count

Query:

index=win_logs Keywords="Audit Failure"
| stats count

This query counts all events containing "Audit Failure" in the Keywords field.

To analyze weekly activity, I set the Time Range picker to Last 7 days.

1_vjBnpe2BY6C17--5DCEitg.png

Then:

  • I selected Visualization > Single Value
  • Added a label under the value: Failures this week
  • Saved it as a Report using a clear naming convention: Group_Type_Description

Using consistent naming conventions helps maintain scalability and organization as dashboards grow.

1_uTPI2C1uKr2mt-pwDd29YA.png

1_i6y6istoIhHaWrKaLCmNkQ.png

1_mNpvR7WVml7UWQljfOz6Ew.png


Exercise 3: Time-Based Visualization with | timechart

index=win_logs LogName=Security
| timechart count(eval(Keywords="Audit Failure")) as "Failed Logins" by Account_Name

This query:

  • Counts failed logins
  • Splits results by Account_Name
  • Displays them over time

Using the Column Chart visualization allowed me to quickly identify:

  • Which users had the most failures
  • On which days activity peaked

This type of visualization is particularly useful for detecting abnormal authentication behavior.

1_4ZYvhzemj87Lq1k6zUd0pQ.jpg

1_2RN7D4vlfoJRdo9Hf0tvlw.jpg

1_cGat7YTG9oLtH_jFkJjnfw.png


Exercise 4: Creating a | table of Recent Failures

index=win_logs Keywords="Audit Failure"
| table _time Account_Name Logon_Process Logon_Type Failure_Reason Caller_Process_Name Source_Network_Address
| sort -_time

Here:

  • I manually selected fields in the order I wanted them displayed.
  • I included | sort -_time to explicitly sort results in descending chronological order.

Although Splunk sorts events in descending order by default, I prefer adding the sort command to make the search logic explicit and self-documented.

1_FkdyixSaH2RzuB72_H8pgw.jpg

1_e--UkkWhTNmAZnmO0Oqjzg.png


Exercise 5: Using | top to Identify Failure Reasons

index=win_logs Keywords="Audit Failure"
| top Failure_Reason

The | top command displays:

  • Count
  • Percentage
  • Top 10 results by default

1_kq2Hu-LzYnQRTX2lRwF1Kg.png

I customized the visualization using the Format menu and applied conditional coloring to emphasize the most frequent failure reasons.

This makes dashboards more visually intuitive and actionable.

1_gZSbHx8fjy1aNI8GYaLqBw.png

1_cpD63nBt-AKJuqYKFdXVdQ.png


Exercise 6: Single Value Visualization with Trend and Sparkline

index=win_logs Keywords="Audit Failure"
| timechart count

Then:

  • Selected Visualization > Single Value
  • Added the label Failures this week
  • Enabled:
  • Show Trend Indicator
  • Show Trend in Absolute
  • Show Sparkline

1_6lIHHqrIO26kUD2hdyEE4w.png

The result clearly shows the weekly trend and whether failures are increasing or decreasing.

1_r7N48Kn5NKBoo7UpekV2xg.png

Trend indicators are particularly useful in operational security monitoring.

1_qhsnQVjvCxytWde_-rNTHw.png


Splunk Dashboard Practical Exercises

After creating several reports, I wanted to visualize everything in one place.

Exercise 7: Creating a Dashboard

  • Navigated to Dashboards
  • Selected Create New Dashboard
  • Applied a consistent naming convention
  • Chose Classic Dashboard

1_Cp44XxVVor96VJC777xr-w.png

1_EKL7ugsQ6mbv8RpswacI-A.png

1_0kwEzyVlozbEznvCHjew9w.png


Exercise 8: Adding Panels

  • Enabled Dark Theme

1_VT9LLvJGas08gGJjmV5BVQ.png

  • Selected + Add Panel

1_0NVZF6HdKFiZcoVYvdnDnA.png

  • Added previously saved Reports as panels

1_k0csHRcTz6-sMGj5tGzjEw.png

Repeated each step as necessary until adding all desired reports as panels

  • Renamed each panel clearly

1_s2mQ-4K9b9Z-SlZmJs4Qyw.png

  • Arranged them using drag-and-drop

The final result was a centralized dashboard displaying:

  • Weekly failures
  • Failure trends
  • Top failure reasons
  • User-based breakdown
  • Detailed event tables

This created a practical authentication monitoring dashboard for my workstation.

1_x7Suh3-keeO54ds9nKOwSA.jpg

Final dashboard result

Don’t forget saving your changes at the end ;)

1_wKuT-kP9hl72L-BXn-XZPA.png


Exercise 9: Setting as Home Dashboard

  • In the Splunk Home screen, selected Dashboard

1_sd_d0oHlLdf6C0n0gzw-UA.png

  • Clicked Choose a home dashboard

1_GKzggKacxMAA98nJBquoFQ.png

  • Selected the newly created dashboard

1_ELuONb7Jt1a_PHBIgOiQTA.png

1_wIIdMzfSL-d8Qxa6u6qi9Q.png

  • Saved

Now, authentication monitoring data is visible immediately upon login.

1_TLdwC78Dvg-uYs4-BqIgAQ.jpg

Home dashboard, final result


Conclusion

Building this Splunk homelab significantly improved my understanding of the Splunk interface, SPL commands, reporting workflows, and dashboard design.

If you are preparing for the Splunk Certified Core User exam or want structured, hands-on practice with real Windows event logs, this lab provides a solid and practical foundation. Beyond certification preparation, it also introduces core concepts used in security monitoring and threat detection environments.

Hands-on experimentation remains one of the most effective ways to truly understand Splunk, an essential SIEM tool for any Defensive Security professional.

“Splunk is a key player in the field of cybersecurity, enabling users to visualize data in a meaningful way and respond to incidents faster” — Splunk Blog


Alternative Approaches

While the approach outlined in this guide provides a great starting point and serves its purpose as a practical exercise to prepare for the Splunk Certified Core User exam, there are many other ways to enhance your Splunk homelab. Here are a few alternative exercises:

Query Common Windows Security Events
Instead of querying the Keyword field, focus on Windows security events like:

  • 4624 (Successful logon)
  • 4625 (Failed logon)

And analyze logon types, such as:

  • 2 (Interactive)
  • 3 (Network)
  • 10 (Remote)

Integrate Sysmon for Detailed Event Logging
Install Sysmon to capture more granular system data and forward these logs to Splunk. Key Sysmon events include process creation, network connections, and file modifications.

Forward Logs from Other Machines
Expand your lab by collecting logs from other systems in your network. Set up forwarders to send logs from additional machines to Splunk for a more comprehensive analysis.

These approaches can deepen your knowledge and provide a broader view of your network’s security.