Skip to main content
DFIRLab
ResearchUse CasesCompare
Intel BriefingsThreat Actors
IOC CheckFile AnalyzerPhishing CheckDomain LookupExposure ScannerPrivacy Check
Log → SplunkLog → Sentinel
WikiAbout
PlatformNew
DFIRLab

Security research, threat intelligence, and free DFIR tools.

Tools

Phishing CheckerExposure ScannerDomain LookupFile AnalyzerPrivacy CheckLog → SplunkLog → SentinelAPI Playground

Use Cases

SOC Phishing TriageIR IOC EnrichmentMSSP Exposure Monitoringn8n AutomationSee all use cases →

Compare

vs VirusTotalvs Shodanvs TheHiveSee all 8 →

Resources

DFIR WikiIntel BriefingsAboutPlatformAPI Docs

Legal

Privacy PolicyRSS FeedSitemap

© 2026 DFIR Lab. All rights reserved.

Free Tool

Turn a log line into Splunk SPL

Paste a raw log → get an AI-suggested search, explained.

Paste a raw log line and get an AI-suggested Splunk search. The query uses your log's own fields — verify it in your environment before relying on it.

⌘/Ctrl + Enter
Try:

The SPL is AI-suggested — a starting point. It uses your log's own field names and a <your_index> sourcetype you confirm. Always verify before running it in production.

What This Does

What it does
  • Detects the log format from the line
  • Extracts the log's own fields (rex/spath)
  • Suggests a SPL search to find similar events
  • Adds broad + precise alternative queries
  • Pulls out IOCs and a pivot time window
What it can't do
  • Know your real sourcetype — it's a labeled guess
  • Confirm your sourcetype — verify it against your data
  • Guarantee the SPL is correct or complete
  • See your environment's parsed fields
Always verify
  • Run the discovery query first
  • Confirm the guessed sourcetype
  • Test in a non-production search
Your logs stay privateEphemeral

Nothing is stored or logged. Indicators (IPs — including internal ranges — domains, URLs, hashes, emails, CVE IDs, and usernames/hostnames in labeled fields) are detected on our server with deterministic pattern-matching before the model is called — no AI is used for that step. The full line is then sent to the AI model to build the SPL search and is not saved — there are no share URLs and no account is required.

How It Works
Step 01

Paste a raw log line

A single syslog line, a Windows 4625 event, an Apache access line, a Cisco ASA deny, a JSON or CEF record. The format is detected automatically.

Step 02

AI drafts the SPL

The model extracts the fields the log actually contains and builds a primary search plus broad and precise alternatives — grounded in those field names.

Step 03

Verify in your environment

Run the included discovery query to list your real sourcetypes, confirm the guessed sourcetype, and validate the search before relying on it.

Related Tools

Log → Microsoft Sentinel (KQL)

Same tool for Microsoft Sentinel: paste a raw log and get an AI-suggested KQL search, explained.

IOC Reputation Checker

Check any IP, domain, hash, or URL extracted from your log against 14+ threat intelligence sources.

All Free Tools

Browse the full set of free DFIR tools — IOC checks, domain lookups, phishing analysis, and more.

Building detections at scale?

The DFIR Platform adds private enrichment, detection-rule management, and API access — results never leave your workspace. Free tier includes credits to get started.

Sign up freeView Docs