Splunk-Presentation

© 2020 SPLUNK INC.
The
Data-to-Everything
Platform
During the course of this presentation, we may make forward‐looking statements
regarding future events or plans of the company. We caution you that such statements
reflect our current expectations and estimates based on factors currently known to us
and that actual events or results may differ materially. The forward-looking statements
made in the this presentation are being made as of the time and date of its live
presentation. If reviewed after its live presentation, it may not contain current or
accurate information. We do not assume any obligation to update
any forward‐looking statements made herein.
In addition, any information about our roadmap outlines our general product direction
and is subject to change at any time without notice. It is for informational purposes only,
and shall not be incorporated into any contract or other commitment. Splunk undertakes
no obligation either to develop the features or functionalities described or to include any
such feature or functionality in a future release.
Splunk, Splunk>, Data-to-Everything, D2E and Turn Data Into Doing are trademarks and registered trademarks of Splunk Inc. in the
United States and other countries. All other brand names, product names or trademarks belong to their respective owners. © 2020
Splunk Inc. All rights reserved.
Forward-
Looking
Statements
© 2020 SPLUNK INC.
© 2019 SPLUNK INC.
Splunk Platform Overview
© 2019 SPLUNK INC.
Every Company Has a
Universe of Real-time Data
Creating More Opportunities and
Threats than Ever Before
Inventory
RFID’S
Databases
Warehous
e
Utilization
Systems
New
Devices
Control
Units
Business
Apps
Networks
Assembly
Robots
New
Technolog
y
New Data
Streams
© 2019 SPLUNK INC.
© 2020 SPLUNK INC.
Turning
Real-time
Data Into
Action
is Hard
© 2020 SPLUNK INC.
Data Lakes
Data Silos
Point Data
Management
Solutions
Master Data
Management
ETL
© 2020 SPLUNK INC.
Why Do
Organizations
Struggle to Answer
Critical Questions? How Are Your
Customer Apps
Performing?
Are You
Secure?
How Do You
Prevent This
Problem from
Happening
Again?
Do You
Know
What’s
Happening
In Your
Business?
Are Your
Systems
Performing?
Why Did This
Problem
Occur?
How Do I
Use Data
More
Efficiently?
© 2020 SPLUNK INC.
Data
Lakes
Master Data
Management
ETL
Point Data
Management
Solutions
Data
Silos
Any Structure
Any Source
Any Time Scale
ACT
INVESTIGATE
ANALYZE
MONITOR
© 2020 SPLUNK INC.
© 2020 SPLUNK INC.
Data
Lakes
Master Data
Management
ETL
Point Data
Management
Solutions
Data
Silos
Business
Processes
The
Data-to-Everything
Platform
IT
Security
DevOps
© 2019 SPLUNK INC.
Splunk Data-
To- Everything
Platform
Differentiated Capabilities
Real-Time Action
AI & ML
Powered
Analytics
Multiple Use
Cases
Expansive
Data Access
Investigation
© 2019 SPLUNK INC.
Splunk Portfolio
Data Sources
Premium
Solutions
Platform
Products
AppDev
Security
IT
Stream
Processing
Federated
Search
Cloud + On
Prem
Developer Tools
Data Stream Processor Data Fabric Search
App for Infrastructure Business Flow
AI & ML — Machine Learning Toolkit Connected Experiences — Mobile, AR, VR, Natural Language
Platform
© 2019 SPLUNK INC.
We Are Witness to
the Cloud Revolution
Splunk Cloud frees teams to do more
interesting work – from administering IT to
turning data into value
© 2019 SPLUNK INC.
Splunk Cloud
Service Excellence Maximize Value from
Limited Resources
Fast and Flexible
© 2019 SPLUNK INC.
Splunk Cloud
Confidently Navigate Sensitive Data and Maintain Compliance
Regulatory
Compliance
▶ Splunk Cloud meets the industry’s most stringent
compliance regulations: SOC 2 Type 2, ISO 27001,
PCI, HIPAA, FedRAMP (Moderate Impact Level)
▶ Encryption in-transit and optionally at rest
(encryption at rest is mandatory for Splunk Cloud FedRAMP)
▶ Each customer has a dedicated cloud environment
© 2020 SPLUNK INC.
Go Faster with Our Welcoming
Community
& Ecosystem
2000+
Partners
1900+
Apps on
Splunkbase
125+
User Groups
102K+
Questions
answered
© 2019 SPLUNK INC.
Splunk Connected Experiences
Delivering contextual insights seamlessly for better, faster decisions
Stay connected with on-
the-go visibility
Empower non-technical
users to access data
Provide contextual insights
that inspire action
© 2 0 1 9 S P L U N K I N C .
Splunk Security Operations
Suite
Make Your SOC Work Smarter, Not Harder with Splunk
© 2020 SPLUNK INC.
Powering
the Modern
SOC
© 2 0 1 9 S P L U N K I N C .
Shifting Focus and Role for SOCs
Situational Awareness
LEGACY
Operation / Monitoring Center
Human Authored
Human Speed Operations
Analysis and Decision-Making
REQUIRED
Nerve Center / Command Center
Human — Machine Learning
Machine-Speed Cycle Times
© 2 0 1 9 S P L U N K I N C .
Act
Security Nerve Center
Endpoints
Threat
Intelligence
Network
Web Proxy
Firewall
Identity and Access
WAF and
App Security
Cloud
Security
Mobile
SOAR
SIEM
Analyze
Monitor
Investigate
© 2 0 1 9 S P L U N K I N C .
The only integrated suite with
industry-leading SIEM, UEBA and
SOAR solutions that utilize a market-
proven, scalable big data platform,
continually augmented with actionable
use case content.
Splunk modernizes security operations
by acting as their security nerve
center, turning data into detections,
and insights into actions, across all
security use cases, teams, and
functions.
Splunk drives the Data, Analytics, and
Operations layers for the SOC to
enable security teams to function at its
highest level of performance.
AOF
Data Sources
Content
Splunk
Enterprise
Security
Splunk
User Behavior
Analytics
Splunk
Phantom
+
Splunk Security
Operations Suite
Modernize your security operations
AOF = Adaptive Operations Framework - our
ecosystem of apps and security partner integrations.
Content = Pre-packaged security content (searches,
detection models, automation playbooks) from the
Splunk Research Team. Stay current with latest
threat landscape.
© 2 0 1 9 S P L U N K I N C .
Identity and
Access
Internal Network
Security
Endpoints
Orchestration
WAF & App
Security
Threat
Intelligence
Network
Web Proxy
Firewall
+
Splunk
Adaptive
Operations
Framework
© 2 0 1 9 S P L U N K I N C .
Security Content Updates
▪ Pre-packaged Searches
▪ Algorithms
▪ Dashboards
▪ Playbooks
▪ …and more!
Available for:
Splunk
Enterprise Security
Splunk
User Behavior Analytics
Splunk
Phantom
© 2019 SPLUNK INC.
Splunk Enterprise
Security
Cloud-based, analytics-driven SIEM
© 2019 SPLUNK INC.
Legacy
SIEMs fail
to address
Security
Challenges
1) Limited Security Data Types
2) Inability to Effectively Ingest Data
3) Slow Investigations
4) Instability and Scalability Issues
5) End-of-Live or Uncertain Roadmap
6) Closed Ecosystem – Transparency
7) Inflexible Deployment Options
© 2 0 1 9 S P L U N K I N C .
Splunk Enterprise Security (ES)
Analytics-Driven Security Information Event Management (SIEM)
▪ Know Your Security Posture
▪ Investigate with Speed and
Flexibility
▪ Scale to Petabytes of Data
© 2019 SPLUNK INC.
Analytics-Driven SIEM
MONITOR RESPOND
DETECT
FUNCTIONS INVESTIGATE
Review Determine
1 2 3 4
Decide Act & Adapt
PROCESS
Prioritize incidents
Decide of what is most
important to follow up or
investigate
SOLUTION Respond in a timely manner
Do each step as fast as possible, with as
little people as possible
Effectively analyze
Each bit of data needs context
and relationship to all others
Analytics-Driven SIEM
© 2019 SPLUNK INC.
Use Cases
© 2019 SPLUNK INC.
• Stay ahead of compliance mandates with an
analytics-driven approach
• Quickly gain real-time posture and insights
across all IT resources and security controls
to clear compliance
• Pass audits with minimal effort, regardless of
mandate or regulatory framework.
• Real-time state of risk, alerts, and compliance
• Full and continuous monitoring of critical
assets
• Full visibility into vulnerabilities, asset/devices,
context of threats and alerting
• Don't miss a thing with continuous and
automated security monitoring that lets you
respond 24/7
Compliance Security Monitoring
© 2019 SPLUNK INC.
• Detect compromised hosts and users
• Find activities associated with accounts and
attackers involved in attacks
• Determine scope of user activities
• Find indicators and artifacts associated with
compromised user hosts
• Identify real incidents and full-scope
• Gain investigation capability across all security
relevant data
• Get context from popular Enterprise SaaS
apps, correlate across SaaS and on-premises
sources
• Gain thorough understanding on options to
remediate a breach
Advanced Threat Detection Incident Investigation & Forensics
© 2019 SPLUNK INC.
• Shorten investigation cycles - prioritize,
confirm and take actions on higher priority
threat.
• Use Investigation Workbench to investigate
notable events that may represent a threat
• Leverage integration with existing capabilities -
collaborate and track the investigation
• Quickly launch a response to critical incidents
• Centrally automate retrieval, sharing and
response actions resulting in improved
detection, investigation and remediation times
• Improve operational efficiency using
workflow-based context with automated and
human-assisted decisions
• Extract new insight by leveraging context,
sharing data and taking automated actions
between ES and partners using Adaptive
Response
Incident Response SOC Automation
© 2020 SPLUNK INC.
Customers Turn Data Into Outcomes
with Splunk
90%
Faster incident
detection,
investigation
and response
90%
Faster development
82%
Reduction in
negative business
impact from shorter
and fewer incidents
70%
Lower risk of
data breach,
IP theft and fraud
50%
Improvement
in time to market
for apps
*Splunk’s Customer Value Assessments Worldwide
© 2 0 1 9 S P L U N K I N C .
*Gartner and Forrester are all trademarks from their respective companies.
*Gartner, Magic Quadrant for Security Information and Event Management, Kelly Kavanagh | Toby Bussa, Dec. 4, 2017. Gartner does not endorse any vendor, product or service depicted in its research publications, and does not advise
technology users to select only those vendors with the highest ratings or other designation. Gartner research publications consist of the opinions of Gartner’s research organization and should not be construed as statements of fact. Gartner
disclaims all warranties, expressed or implied, with respect to this research, including any warranties of merchantability or fitness for a particular purpose. GARTNER is a registered trademark and service mark of Gartner, Inc. and/or its affiliates
in the U.S. and internationally, and is used herein with permission. All rights reserved.
*The Gartner Peer Insights Customer Choice Logo is a trademark and service mark of Gartner, Inc., and/or its affiliates, and is used herein with permission. All rights reserved. Gartner Peer Insights Customer Choice Awards are determined by the
subjective opinions of individual end-user customers based on their own experiences, the number of published reviews on Gartner Peer Insights and overall ratings for a given vendor in the market, as further described
here http://www.gartner.com/reviews-pages/peer-insights-customer-choice-awards/ and are not intended in any way to represent the views of Gartner or its affiliates.
By Industry Analysts
Named a Leader in Gartner’s Magic
Quadrant for Security Information
and Event Management
Designated a 2018 Customer’s
Choice for Security Information
and Event Management
By End Users
© 2020 SPLUNK INC.
Trusted by Organizations with the World’s
Highest Security Standards
Technology Travel & Transportation
Telecommunications
Retail
Education Energy & Utilities Financial Services
Cloud & Online Services
Manufacturing
Government Healthcare Media & Entertainment
© 2020 SPLUNK INC.
“In tight collaboration with Splunk, the team deployed this
big data solution in just 5 weeks and immediately started
realizing benefits.”
— Sr. Solution Architect, Information Security, Intel
With Splunk and Apache Kafka, they developed a new
Cyber Intelligence Platform that is transforming its
information security by:
• Speeding data analysis and reducing time to detect and respond
to advanced threats in minutes
• Enabling a collaborative organization with a common language
and work surface
• Providing streams processing and machine learning tools
that deliver business value
Intel Transforms Security
with Data Intelligence
Thank You
© 2020 SPLUNK INC.
1 de 35

Recomendados

Splunk OverviewSplunk Overview
Splunk OverviewSplunk
1.8K visualizações57 slides
Splunk OverviewSplunk Overview
Splunk OverviewSplunk
45.2K visualizações41 slides
Splunk Enterprise SecuritySplunk Enterprise Security
Splunk Enterprise SecuritySplunk
5K visualizações58 slides
SplunkLive 2011 Beginners SessionSplunkLive 2011 Beginners Session
SplunkLive 2011 Beginners SessionSplunk
8.7K visualizações41 slides
SplunkSplunk
SplunkDouglas Bernardini
1.1K visualizações23 slides
Splunk for IT OperationsSplunk for IT Operations
Splunk for IT OperationsSplunk
1.6K visualizações29 slides

Mais conteúdo relacionado

Mais procurados

Splunk overviewSplunk overview
Splunk overviewDaniel Hernandez
724 visualizações31 slides
Getting Started with Splunk (Hands-On) Getting Started with Splunk (Hands-On)
Getting Started with Splunk (Hands-On) Splunk
1.2K visualizações17 slides
PPT-Splunk-LegacySIEM-101_FINALPPT-Splunk-LegacySIEM-101_FINAL
PPT-Splunk-LegacySIEM-101_FINALRisi Avila
967 visualizações43 slides
Security Automation & OrchestrationSecurity Automation & Orchestration
Security Automation & OrchestrationSplunk
1.4K visualizações53 slides
dlux - Splunk Technical Overviewdlux - Splunk Technical Overview
dlux - Splunk Technical OverviewDavid Lutz
7.4K visualizações41 slides

Mais procurados(20)

Splunk overviewSplunk overview
Splunk overview
Daniel Hernandez724 visualizações
Getting Started with Splunk (Hands-On) Getting Started with Splunk (Hands-On)
Getting Started with Splunk (Hands-On)
Splunk1.2K visualizações
PPT-Splunk-LegacySIEM-101_FINALPPT-Splunk-LegacySIEM-101_FINAL
PPT-Splunk-LegacySIEM-101_FINAL
Risi Avila967 visualizações
Security Automation & OrchestrationSecurity Automation & Orchestration
Security Automation & Orchestration
Splunk1.4K visualizações
dlux - Splunk Technical Overviewdlux - Splunk Technical Overview
dlux - Splunk Technical Overview
David Lutz7.4K visualizações
.conf Go Zurich 2022 - Platform Session.conf Go Zurich 2022 - Platform Session
.conf Go Zurich 2022 - Platform Session
Splunk97 visualizações
Getting started with SplunkGetting started with Splunk
Getting started with Splunk
Splunk2.8K visualizações
Splunk Architecture overviewSplunk Architecture overview
Splunk Architecture overview
Alex Fok4.3K visualizações
Splunk for ITOpsSplunk for ITOps
Splunk for ITOps
Splunk1.6K visualizações
Getting Started with Splunk EnterpriseGetting Started with Splunk Enterprise
Getting Started with Splunk Enterprise
Splunk693 visualizações
Splunk Phantom SOAR RoundtableSplunk Phantom SOAR Roundtable
Splunk Phantom SOAR Roundtable
Splunk6.3K visualizações
SplunkLive 2011 Advanced SessionSplunkLive 2011 Advanced Session
SplunkLive 2011 Advanced Session
Splunk4.6K visualizações
SplunkLive! Splunk for SecuritySplunkLive! Splunk for Security
SplunkLive! Splunk for Security
Splunk12.6K visualizações
Splunk Enterprise Security Splunk Enterprise Security
Splunk Enterprise Security
Md Mofijul Haque175 visualizações

Similar a Splunk-Presentation (20)

December Bengaluru Splunk User Group MeetupDecember Bengaluru Splunk User Group Meetup
December Bengaluru Splunk User Group Meetup
kamlesh2410130 visualizações
IoT Analytics @ splunkIoT Analytics @ splunk
IoT Analytics @ splunk
Splunk597 visualizações
Getting Started with Splunk EnterpriseGetting Started with Splunk Enterprise
Getting Started with Splunk Enterprise
Splunk710 visualizações
Building an Analytics Enables SOCBuilding an Analytics Enables SOC
Building an Analytics Enables SOC
Splunk4.2K visualizações

Último(20)

Advanced API Mocking TechniquesAdvanced API Mocking Techniques
Advanced API Mocking Techniques
Dimpy Adhikary17 visualizações
Topic 1 What is Evolutionary Prototyping.pptxTopic 1 What is Evolutionary Prototyping.pptx
Topic 1 What is Evolutionary Prototyping.pptx
AHMADAIMAN778 visualizações
DevsRankDevsRank
DevsRank
devsrank78610 visualizações
Citi TechTalk Session 2: Kafka Deep DiveCiti TechTalk Session 2: Kafka Deep Dive
Citi TechTalk Session 2: Kafka Deep Dive
confluent16 visualizações
SUGCON ANZ Presentation V2.1 Final.pptxSUGCON ANZ Presentation V2.1 Final.pptx
SUGCON ANZ Presentation V2.1 Final.pptx
Jack Spektor21 visualizações
Neo4j y GenAI Neo4j y GenAI
Neo4j y GenAI
Neo4j27 visualizações
Headless JS UG Presentation.pptxHeadless JS UG Presentation.pptx
Headless JS UG Presentation.pptx
Jack Spektor5 visualizações
LAVADORA ROLO.docxLAVADORA ROLO.docx
LAVADORA ROLO.docx
SamuelRamirez835247 visualizações
Create Roku ChannelsCreate Roku Channels
Create Roku Channels
Roshan Dwivedi5 visualizações
Cycleops - Automate deployments on top of bare metal.pptxCycleops - Automate deployments on top of bare metal.pptx
Cycleops - Automate deployments on top of bare metal.pptx
Thanassis Parathyras29 visualizações
Software testing company in India.pptxSoftware testing company in India.pptx
Software testing company in India.pptx
SakshiPatel827 visualizações

Splunk-Presentation

  • 1. © 2020 SPLUNK INC. The Data-to-Everything Platform
  • 2. During the course of this presentation, we may make forward‐looking statements regarding future events or plans of the company. We caution you that such statements reflect our current expectations and estimates based on factors currently known to us and that actual events or results may differ materially. The forward-looking statements made in the this presentation are being made as of the time and date of its live presentation. If reviewed after its live presentation, it may not contain current or accurate information. We do not assume any obligation to update any forward‐looking statements made herein. In addition, any information about our roadmap outlines our general product direction and is subject to change at any time without notice. It is for informational purposes only, and shall not be incorporated into any contract or other commitment. Splunk undertakes no obligation either to develop the features or functionalities described or to include any such feature or functionality in a future release. Splunk, Splunk>, Data-to-Everything, D2E and Turn Data Into Doing are trademarks and registered trademarks of Splunk Inc. in the United States and other countries. All other brand names, product names or trademarks belong to their respective owners. © 2020 Splunk Inc. All rights reserved. Forward- Looking Statements © 2020 SPLUNK INC.
  • 3. © 2019 SPLUNK INC. Splunk Platform Overview
  • 4. © 2019 SPLUNK INC. Every Company Has a Universe of Real-time Data Creating More Opportunities and Threats than Ever Before Inventory RFID’S Databases Warehous e Utilization Systems New Devices Control Units Business Apps Networks Assembly Robots New Technolog y New Data Streams © 2019 SPLUNK INC.
  • 5. © 2020 SPLUNK INC. Turning Real-time Data Into Action is Hard © 2020 SPLUNK INC. Data Lakes Data Silos Point Data Management Solutions Master Data Management ETL
  • 6. © 2020 SPLUNK INC. Why Do Organizations Struggle to Answer Critical Questions? How Are Your Customer Apps Performing? Are You Secure? How Do You Prevent This Problem from Happening Again? Do You Know What’s Happening In Your Business? Are Your Systems Performing? Why Did This Problem Occur? How Do I Use Data More Efficiently?
  • 7. © 2020 SPLUNK INC. Data Lakes Master Data Management ETL Point Data Management Solutions Data Silos Any Structure Any Source Any Time Scale ACT INVESTIGATE ANALYZE MONITOR © 2020 SPLUNK INC.
  • 8. © 2020 SPLUNK INC. Data Lakes Master Data Management ETL Point Data Management Solutions Data Silos Business Processes The Data-to-Everything Platform IT Security DevOps
  • 9. © 2019 SPLUNK INC. Splunk Data- To- Everything Platform Differentiated Capabilities Real-Time Action AI & ML Powered Analytics Multiple Use Cases Expansive Data Access Investigation
  • 10. © 2019 SPLUNK INC. Splunk Portfolio Data Sources Premium Solutions Platform Products AppDev Security IT Stream Processing Federated Search Cloud + On Prem Developer Tools Data Stream Processor Data Fabric Search App for Infrastructure Business Flow AI & ML — Machine Learning Toolkit Connected Experiences — Mobile, AR, VR, Natural Language Platform
  • 11. © 2019 SPLUNK INC. We Are Witness to the Cloud Revolution Splunk Cloud frees teams to do more interesting work – from administering IT to turning data into value
  • 12. © 2019 SPLUNK INC. Splunk Cloud Service Excellence Maximize Value from Limited Resources Fast and Flexible
  • 13. © 2019 SPLUNK INC. Splunk Cloud Confidently Navigate Sensitive Data and Maintain Compliance Regulatory Compliance ▶ Splunk Cloud meets the industry’s most stringent compliance regulations: SOC 2 Type 2, ISO 27001, PCI, HIPAA, FedRAMP (Moderate Impact Level) ▶ Encryption in-transit and optionally at rest (encryption at rest is mandatory for Splunk Cloud FedRAMP) ▶ Each customer has a dedicated cloud environment
  • 14. © 2020 SPLUNK INC. Go Faster with Our Welcoming Community & Ecosystem 2000+ Partners 1900+ Apps on Splunkbase 125+ User Groups 102K+ Questions answered
  • 15. © 2019 SPLUNK INC. Splunk Connected Experiences Delivering contextual insights seamlessly for better, faster decisions Stay connected with on- the-go visibility Empower non-technical users to access data Provide contextual insights that inspire action
  • 16. © 2 0 1 9 S P L U N K I N C . Splunk Security Operations Suite Make Your SOC Work Smarter, Not Harder with Splunk
  • 17. © 2020 SPLUNK INC. Powering the Modern SOC
  • 18. © 2 0 1 9 S P L U N K I N C . Shifting Focus and Role for SOCs Situational Awareness LEGACY Operation / Monitoring Center Human Authored Human Speed Operations Analysis and Decision-Making REQUIRED Nerve Center / Command Center Human — Machine Learning Machine-Speed Cycle Times
  • 19. © 2 0 1 9 S P L U N K I N C . Act Security Nerve Center Endpoints Threat Intelligence Network Web Proxy Firewall Identity and Access WAF and App Security Cloud Security Mobile SOAR SIEM Analyze Monitor Investigate
  • 20. © 2 0 1 9 S P L U N K I N C . The only integrated suite with industry-leading SIEM, UEBA and SOAR solutions that utilize a market- proven, scalable big data platform, continually augmented with actionable use case content. Splunk modernizes security operations by acting as their security nerve center, turning data into detections, and insights into actions, across all security use cases, teams, and functions. Splunk drives the Data, Analytics, and Operations layers for the SOC to enable security teams to function at its highest level of performance. AOF Data Sources Content Splunk Enterprise Security Splunk User Behavior Analytics Splunk Phantom + Splunk Security Operations Suite Modernize your security operations AOF = Adaptive Operations Framework - our ecosystem of apps and security partner integrations. Content = Pre-packaged security content (searches, detection models, automation playbooks) from the Splunk Research Team. Stay current with latest threat landscape.
  • 21. © 2 0 1 9 S P L U N K I N C . Identity and Access Internal Network Security Endpoints Orchestration WAF & App Security Threat Intelligence Network Web Proxy Firewall + Splunk Adaptive Operations Framework
  • 22. © 2 0 1 9 S P L U N K I N C . Security Content Updates ▪ Pre-packaged Searches ▪ Algorithms ▪ Dashboards ▪ Playbooks ▪ …and more! Available for: Splunk Enterprise Security Splunk User Behavior Analytics Splunk Phantom
  • 23. © 2019 SPLUNK INC. Splunk Enterprise Security Cloud-based, analytics-driven SIEM
  • 24. © 2019 SPLUNK INC. Legacy SIEMs fail to address Security Challenges 1) Limited Security Data Types 2) Inability to Effectively Ingest Data 3) Slow Investigations 4) Instability and Scalability Issues 5) End-of-Live or Uncertain Roadmap 6) Closed Ecosystem – Transparency 7) Inflexible Deployment Options
  • 25. © 2 0 1 9 S P L U N K I N C . Splunk Enterprise Security (ES) Analytics-Driven Security Information Event Management (SIEM) ▪ Know Your Security Posture ▪ Investigate with Speed and Flexibility ▪ Scale to Petabytes of Data
  • 26. © 2019 SPLUNK INC. Analytics-Driven SIEM MONITOR RESPOND DETECT FUNCTIONS INVESTIGATE Review Determine 1 2 3 4 Decide Act & Adapt PROCESS Prioritize incidents Decide of what is most important to follow up or investigate SOLUTION Respond in a timely manner Do each step as fast as possible, with as little people as possible Effectively analyze Each bit of data needs context and relationship to all others Analytics-Driven SIEM
  • 27. © 2019 SPLUNK INC. Use Cases
  • 28. © 2019 SPLUNK INC. • Stay ahead of compliance mandates with an analytics-driven approach • Quickly gain real-time posture and insights across all IT resources and security controls to clear compliance • Pass audits with minimal effort, regardless of mandate or regulatory framework. • Real-time state of risk, alerts, and compliance • Full and continuous monitoring of critical assets • Full visibility into vulnerabilities, asset/devices, context of threats and alerting • Don't miss a thing with continuous and automated security monitoring that lets you respond 24/7 Compliance Security Monitoring
  • 29. © 2019 SPLUNK INC. • Detect compromised hosts and users • Find activities associated with accounts and attackers involved in attacks • Determine scope of user activities • Find indicators and artifacts associated with compromised user hosts • Identify real incidents and full-scope • Gain investigation capability across all security relevant data • Get context from popular Enterprise SaaS apps, correlate across SaaS and on-premises sources • Gain thorough understanding on options to remediate a breach Advanced Threat Detection Incident Investigation & Forensics
  • 30. © 2019 SPLUNK INC. • Shorten investigation cycles - prioritize, confirm and take actions on higher priority threat. • Use Investigation Workbench to investigate notable events that may represent a threat • Leverage integration with existing capabilities - collaborate and track the investigation • Quickly launch a response to critical incidents • Centrally automate retrieval, sharing and response actions resulting in improved detection, investigation and remediation times • Improve operational efficiency using workflow-based context with automated and human-assisted decisions • Extract new insight by leveraging context, sharing data and taking automated actions between ES and partners using Adaptive Response Incident Response SOC Automation
  • 31. © 2020 SPLUNK INC. Customers Turn Data Into Outcomes with Splunk 90% Faster incident detection, investigation and response 90% Faster development 82% Reduction in negative business impact from shorter and fewer incidents 70% Lower risk of data breach, IP theft and fraud 50% Improvement in time to market for apps *Splunk’s Customer Value Assessments Worldwide
  • 32. © 2 0 1 9 S P L U N K I N C . *Gartner and Forrester are all trademarks from their respective companies. *Gartner, Magic Quadrant for Security Information and Event Management, Kelly Kavanagh | Toby Bussa, Dec. 4, 2017. Gartner does not endorse any vendor, product or service depicted in its research publications, and does not advise technology users to select only those vendors with the highest ratings or other designation. Gartner research publications consist of the opinions of Gartner’s research organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this research, including any warranties of merchantability or fitness for a particular purpose. GARTNER is a registered trademark and service mark of Gartner, Inc. and/or its affiliates in the U.S. and internationally, and is used herein with permission. All rights reserved. *The Gartner Peer Insights Customer Choice Logo is a trademark and service mark of Gartner, Inc., and/or its affiliates, and is used herein with permission. All rights reserved. Gartner Peer Insights Customer Choice Awards are determined by the subjective opinions of individual end-user customers based on their own experiences, the number of published reviews on Gartner Peer Insights and overall ratings for a given vendor in the market, as further described here http://www.gartner.com/reviews-pages/peer-insights-customer-choice-awards/ and are not intended in any way to represent the views of Gartner or its affiliates. By Industry Analysts Named a Leader in Gartner’s Magic Quadrant for Security Information and Event Management Designated a 2018 Customer’s Choice for Security Information and Event Management By End Users
  • 33. © 2020 SPLUNK INC. Trusted by Organizations with the World’s Highest Security Standards Technology Travel & Transportation Telecommunications Retail Education Energy & Utilities Financial Services Cloud & Online Services Manufacturing Government Healthcare Media & Entertainment
  • 34. © 2020 SPLUNK INC. “In tight collaboration with Splunk, the team deployed this big data solution in just 5 weeks and immediately started realizing benefits.” — Sr. Solution Architect, Information Security, Intel With Splunk and Apache Kafka, they developed a new Cyber Intelligence Platform that is transforming its information security by: • Speeding data analysis and reducing time to detect and respond to advanced threats in minutes • Enabling a collaborative organization with a common language and work surface • Providing streams processing and machine learning tools that deliver business value Intel Transforms Security with Data Intelligence
  • 35. Thank You © 2020 SPLUNK INC.