Wondering how to find the baddies in huge volumes of data? Work with Splunk & Windows event Log Monitoring – refer to table of event codes in NSA paper.
Send data to Splunk w/o a forwarder using HEC (HTTP Event Collector); Perfect for log data over HTTP or IoT. Install Nginx with HTTPS support, then configure.
Learn ways to estimate what size Splunk license you need. How to estimate how much data you have, asking admins, add a buffer, and try a free Splunk trial.