-1

I am setting up HOME SIEM lab using SPLUNK. I am looking for sources which can provide different logs for various devices but not limited for below ones.

  • Windows Logs
  • IIS Logs
  • IDS/IPS Logs

Based on the logs i am planning to build search queries for various events and further using the same to build the rules.

2 Answers2

0

It is not clear why you need logs when you can generate these? For example you can set up a VM with Windows Server and install an agent like NXLog (or any log collection agent that can send logs forwarded via TCP, UDP, TLS, or HTTP) for log collection to Splunk.

NASAhorse
  • 103
  • 2
0

Checkout the Montgomery County Data Portal. It's free

https://data.montgomerycountymd.gov/

You could also connect to a crypto exchange API and have lots of data flow in real-time

skoelpin
  • 212
  • 1
  • 5