I will write splunk spl queries to analyze and report your log data
About this Gig
Turn raw log data into clear, actionable SPL searches.
I write and optimize Splunk SPL queries to help you search, filter, and make sense of large volumes of log data, whether that's narrowing a huge dataset to specific events, extracting key fields, or building a reusable search for ongoing monitoring.
Example of my work: Using Windows Security event logs, I built a search to hunt for suspicious PowerShell activity, surfacing process execution events using encoded or hidden-window flags, a common technique used to hide malicious activity. It returned 18 relevant events out of thousands, cutting straight to what actually needs investigating.
What I can do:
- SPL queries tailored to your investigation or monitoring need
- Narrow large datasets to the events that matter
- Extract key fields (timestamps, hosts, users, IPs, processes, command lines)
- Searches for security investigation, threat hunting, or general log analysis
- Clean, reusable queries (Standard/Premium)
Before ordering, have ready:
- Splunk access or sample/exported log data
- What you're trying to find or monitor
- Any specific fields or indicators relevant to your case
Let's turn your logs into answers.
My Portfolio
FAQ
Do I need to give you access to my Splunk instance?
Yes, or you can send sample/exported log data instead
What log sources can you work with?
Most standard logs ingested into Splunk, security logs, system events, process activity, network logs, and more
Will the search work long-term, or is it one-time use?
Standard and Premium queries are built to be reusable, not just a one-off answer.
Can you write searches for threat hunting, not just basic filtering?
Yes, I can build searches around specific indicators, patterns, or suspicious behavior, like the PowerShell example in my gig.

