AWS & Splunk SOC Lab
AWSSplunkDockerSIEM
PROBLEM
AWS has built-in SIEM tooling, but many companies already run Splunk and may lack budget for a fully separate native stack. Wanted to prove the two could be bridged.
WHAT I DID
Ubuntu EC2 instance, Docker + DVWA exposed publicly, Splunk Universal Forwarder shipping JSON container logs to a locally hosted Splunk Enterprise instance. Validated with two real attacks: simulated directory traversal and path traversal, confirming logs landed and parsed correctly.
WHAT CAME OF IT
A confirmed, working log pipeline from a cloud-hosted vulnerable app to a locally hosted SIEM, validated end-to-end with two live, traceable attack types.