Module 5 (10 pts)
What you need:
- A Windows, Linux, or Mac computer
Splunk Online Course
In the Splunk online course, do Module 5.
Near the end, at step 28, you are viewing a stored job
that finds SSH login errors.
Capture a screen image, as shown below,
with these required elements:
- "Expires" date 7 days after "Created at" date
- Search criteria fail* AND password "port 22"
Saving a Screen Image
Capture a full-screen image.
YOU MUST SUBMIT A FULL-SCREEN IMAGE FOR FULL CREDIT!
Save the image with the filename "YOUR NAME Mod 5", replacing "YOUR NAME" with your real name.
Turning in your Project
Email the image
to firstname.lastname@example.org with the subject line:
Mod 5 from YOUR NAME.