Webinar: How Enterprises like AWS are Closing the Spreadsheet Security Gap

05.26.2026

Spunk SIEM Log Analysis

Large DatasetsSecurity Operations
Spunk SIEM Log Analysis

About This Dataset

The Splunk sample dataset contains 800,000 rows of simulated enterprise security telemetry spanning a 90-day period (February–May 2025). It mirrors the types of data your Splunk SIEM would export via CSV for offline analysis, war-gaming, or reporting.

Data Sources Included

  • Firewall logs (25% of events) — allow, deny, drop, reject decisions
  • Authentication events (20%) — success, failure, lockout, MFA, logout
  • Endpoint telemetry (15%) — process creation, file operations, registry modifications
  • IDS/IPS alerts (15%) — signature-based detections with threat intel enrichment
  • DNS logs (10%) — queries, NXDOMAIN, refused responses
  • Web proxy logs (8%) — HTTP traffic with URL, method, and user-agent
  • VPN/remote access (5%) — connect, disconnect, auth failures
  • Cloud audit logs (2%) — API calls, IAM changes, resource events

Key Fields Reference

FieldTypeDescription
bytes_inIntegerInbound bytes
bytes_outIntegerOutbound bytes
duration_secFloatConnection duration in seconds
usernameStringUser account associated with event
hostnameStringDevice name generating the event
domainStringDomain or URL destination
countryStringSource country (ISO 2-letter code)
session_idStringSession or connection identifier
signatureStringIDS/IPS detection signature (IDS events only)
process_nameStringProcess name (endpoint events only)
file_pathStringFile path affected (endpoint events only)
registry_keyStringRegistry key modified (endpoint events only)
mitre_tacticStringMITRE ATT&CK tactic (high/critical events)
mitre_techniqueStringMITRE ATT&CK technique ID
threat_intel_matchBooleanKnown malicious IP or signature match
response_actionStringAction taken on high/critical events
rule_idStringDetection rule that fired
event_idStringUnique event identifier
timestampDateTimeEvent time
source_typeStringLog source category
severityStringRisk level of the event
actionStringWhat was done
src_ipIPSource IP address
dst_ipIPDestination IP address
src_portIntegerSource port number
dst_portIntegerDestination port number
protocolStringNetwork protocol

Complete Dataset Summary

The Complete Dataset Summary prompt was used on this dataset to build the SIEM Analysis workbook that includes data tables and the following charts. It establishes baseline volumes and surfaces the most important metrics at a glance.

Security Events by Source type
Security Events by Source type
Security Events by Severity
Security Events by Severity
Security Events by Action
Security Events by Action


Prompt 2 — Event Timeline (Daily Volume)

The Daily Breakdown workbook in this dataset was built using the Daily Event Timeline prompt. The output will produce data tables for the following charts: Understand event distribution over time. Spikes in daily volume often indicate attack campaigns, scanning activity, or misconfigured alerting.

Daily Total Security Event Volume
Daily Total Security Event Volume
Daily Security Events by Severity
Daily Security Events by Severity
Daily Threat Intel Match Count
Daily Threat Intel Match Count



Prompt 3 — Source Type Health Check

The Source Type Health Check prompt was used on this dataset to build the Log Coverage workbook that includes data tables and the following charts. Validate that all log sources are reporting consistently. Gaps or sudden drops in a source type can indicate logging failures, agent outages, or an attacker disabling sensors.

Total Security Events by Source Type
Total Security Events by Source Type
Average Events Per Day by Source Type
Average Events Per Day by Source Type
Daily Security Event Volume by Source Type
Daily Security Event Volume by Source Type
Daily Security Event Trends per Source Type
Daily Security Event Trends per Source Type



Keep exploring

Latest datasets

Explore all datasets
Freight Analysis Framework
04.24.2026

Freight Analysis Framework

Explore the Freight Analysis Framework in a large spreadsheet. Row Zero is a powerful spreadsheet that works like Excel but supports much larger datasets.

View dataset

Get started with Row Zero

Ready to upgrade your spreadsheets?