This document provides an agenda and overview of a Splunk Enterprise security workshop focusing on web attacks, lateral movement, and DNS exfiltration. The agenda includes introductions, demonstrations of SQL injection detection using regular expressions, detecting lateral movement through abnormal network traffic patterns, and using Shannon entropy and subdomain length to identify DNS exfiltration. Hands-on exercises are provided to allow attendees to search pre-loaded machine data and gain experience detecting these common security incidents.