⌂ HOME← ALL PROJECTS

AWS & Splunk SOC Lab

AWSSplunkDockerSIEM

AWS has built-in SIEM tooling, but many companies already run Splunk and may lack budget for a fully separate native stack. Wanted to prove the two could be bridged.

Ubuntu EC2 instance, Docker + DVWA exposed publicly, Splunk Universal Forwarder shipping JSON container logs to a locally hosted Splunk Enterprise instance. Validated with two real attacks: simulated directory traversal and path traversal, confirming logs landed and parsed correctly.

A confirmed, working log pipeline from a cloud-hosted vulnerable app to a locally hosted SIEM, validated end-to-end with two live, traceable attack types.