SlideShare uma empresa Scribd logo
1 de 51
© 2019 SPLUNK INC.© 2019 SPLUNK INC.
Clear the Mist from your Clouds
with Splunk
SplunkLive London - June 2019
Yuval Tenenbaum
Director – SE Architects EMEA
© 2017 SPLUNK INC.
Migration To
Cloud & Hybrid
Cloud Insights
is Top Of Mind
© 2019 SPLUNK INC.
► Enables Least privileged model at the highest operational control
► Mitigates Risk – lower the ‘blast radius’ of impactful events
► Achieve Agility- deploy & run environments programmatically at scale
► Cost optimisation- clear ‘line of sight’ into the cost of running workloads
Hybrid Cloud – Think Differently
Legacy
Model Least
privileged
© 2019 SPLUNK INC.
► Split Investment may slow down your cloud adoption – Spreading your
resources across multiple clouds means that you may not get critical mass or a
fast ROI
► Portability - How many of us will actually move workloads around?
► Cloud Broker concept – Putting a “bloatware” between you and your cloud api’s
instead of working natively with these cloud API’s
Is it Really All Good Stuff?
I used to be
indecisive now I’m
definitely going multi-
cloud
© 2019 SPLUNK INC.
Cloud - Same Challenges-Different Environments
► Security
• Are we firewalled correctly?
• Do we use all necessary security features?
► Compliance
• Are we following all published standards?
► Networking
• Placed servers on the correct network?
► Financial
• Stayed within budget?
► Capacity Planning
• Used resources optimally?
And all of that in a
decentralized Model…
© 2019 SPLUNK INC.
Customer experience???
SAAS
Hybrid Everything - What happens when we stack
them?
ON PREMISES
Legacy systems
(Mainframe…)
Facilities
Dev/PreProd
Storage
Backup
Archive
DR
Security
VMs
Containers Micro
services
AWS (Application 1)Access / Security
Database
StorageDev
Compute
Containers
App engine
GCP
(Big Data project 1)
Dataflow
AWS
(Archive) Azure (Application 1)
VMs
Database
VM sets
Traffic mger
© 2017 SPLUNK INC.
So How Can Splunk Clear
up this Cloudy Mist?
Know your Clouds…..
© 2019 SPLUNK INC.
► Splunk has working relationships with AWS, Azure, and GCP
► We have customers successfully running Splunk Enterprise BYOL within AWS,
Azure, and GCP
► We have proven strategies to get data in from AWS, Azure, and GCP
Cloud Vendor Relationships
© 2017 SPLUNK INC.
Splunk’s Approach to Hybrid Cloud
One Consolidated
Solution
Manage Hybrid
Infrastructure
Cost, Capacity and
Resource Management
Cloud Migration
Splunk takes the place of the
multitude of monitoring tools
because sometimes one is
better than many.
Deploy Splunk in Hybrid
setup (on-prem, saas, byol)
and deal with Hybrid
infrastructure complex
monitoring
Understand how your
resources are performing –
and how many are being
used – then optimize
utilization and billing.
Get visibility at all stages of
the migration process
(landing zones)– whether
before, during or long after.
© 2017 SPLUNK INC.
In the Beginning……
Cloud Migration
© 2019 SPLUNK INC.
What Customers Want To Achieve When Migrating to
the Cloud
► Build - Differentiate yourself by
building unique and valuable services
► Move Fast - From initial idea to a
service which can be monetized
► Stay Secure - Make sure that what
we build is secure and compliant
▶ Manage Cost – Control what you
spend and gain visibility into future
cost
© 2019 SPLUNK INC.
Path To Successful Cloud Migration
Measure the baseline user
experience and performance,
as well as define acceptable
post-migration levels.
Security assessment – build a
well architected and compliant
landing zones
Performance metrics should
be closely monitored &
compared to the baseline.
Throughout the migration,
end-to-end monitoring can
help SecOps teams stay
ahead of any potential risks.
Continuous monitoring
should be used to measure
acceptable metrics and
success.
Leverage a platform that
shows insights into cost,
shared services, monitoring,
Security & compliance
BEFORE DURING AFTER
© 2019 SPLUNK INC.
Challenges With Building & Maintaining Landing
Zones
▶ Define & maintain an Account
structure
▶ Define your network architecture and
monitor it continuously
▶ Define & maintain a security
governance and compliance baseline Migrate Land Operate &
Optimize
© 2019 SPLUNK INC.
Additional Considerations
▶ Define & maintain centralized logging
▶ Define & maintain Cost Allocation
© 2019 SPLUNK INC.
How Can Splunk Help (1)?
▶ Tell you who is accessing
your accounts, from where
and what are they doing?
© 2019 SPLUNK INC.
How Can Splunk Help (2)?
▶ Tell you if anyone is breaking your security policies?
• Is encryption used everywhere
• Has the root account has MFA enabled
• Suspicious AWS S3 Activities
• IAM Password policies are kept as you defined in your security
baseline?
© 2019 SPLUNK INC.
How Can Splunk Help (3)?
▶ Help you understand your network topology and gain
visibility into who is trying to access it
▶ Help you gain visibility into performance & right sizing
of your key workloads
▶ Help you understand historic and future cost
© 2019 SPLUNK INC.
AWS Analytic Stories - ES Content Updates
© 2019 SPLUNK INC.
Migration Dashboards
© 2017 SPLUNK INC.
So How Do We
Collect Cloud Data to
do this Hybrid
Monitoring?
© 2017 SPLUNK INC.
Getting Data In
Cloud Patterns
© 2017 SPLUNK INC.
General Getting Data In Routes
Pull or Push, Add-Ons or Serverless
Poll/Request API
Data
Data
Cloud
Serverless
Code
Add-On
HEC “Push”
© 2017 SPLUNK INC.
GDI : AWS
© 2019 SPLUNK INC.
It May Look a Bit Complicated
© 2019 SPLUNK INC.
► AWS Config can be pulled with a Splunk Heavy Forwarder with the SQS Based
S3. Anything via CloudWatch Logs or CW events, can be pushed with Kinesis
Firehose to Splunk
AWS Pull vs. Push
Config Events
SNS
Topic
Notification
SQS
Subscription
Notification
Pulls Event from S3 Bucket
Splunk Pull
SQS Notification
HEC
PushPull
CloudWatch
Logs
© 2019 SPLUNK INC.
AWS Source Matrix
There are many options to GDI in AWS but Splunk can help
Data Type Recommended Input Type
Billing Billing
CloudWatch CloudWatch
CloudFront Access Logs SQS based S3
Config SQS based S3
Config Rules Config Rules
Description Description
ELB Access Logs SQS based S3
Inspector Inspector
CloudTrail SQS Based S3
S3 access logs SQS Based S3
VPC Flow Logs (CW Logs) Kinesis
With SQS Based S3 you can
scale out data collection by
configuring multiple inputs to
ingest logs from the same S3
bucket without creating duplicate
data.
Kinesis Firehose is
recommended for CloudWatch
Logs data collection
© 2017 SPLUNK INC.
GDI : Azure & O365
© 2019 SPLUNK INC.
3 Log Types in Azure
1) Control/Management, 2) Data Plane, 3) Processed Events
Control: System Configuration and Management
Data Plane: Provisioned Service and Diagnostic Data
Processed Events: Alerts & Recommendations
© 2019 SPLUNK INC.
{ REST }
Storage Event Hub
© 2019 SPLUNK INC.
► Splunk can pull data from Azure using a Heavy Forwarder and collect data from
either the MS Blob or a REST API using the modular input. Azure can push data
using the Event Hub to Azure Functions which can be sent to Splunk’s HEC.
Azure Pull vs. Push
MSBlob
HEC
PushPull
Splunk Indexers
Activity Monitor Event Hub Azure Function
Event Hub
© 2019 SPLUNK INC.
Azure Add-on Landscape
© 2019 SPLUNK INC.
Getting O365 Data In
Azure Active Directory
Application
OAUTH2
REST
Splunk Add-on for
Microsoft O365
Office 365
© 2017 SPLUNK INC.
GDI : Google Cloud
© 2019 SPLUNK INC.
Getting GCP Data In
REST
Splunk Add-on for
Google Cloud Platform
Billing
PubSub
Monitoring
StackDriver
© 2019 SPLUNK INC.
► Initial:
• Most customers will generate around 1-10GB when they are setting up their Public Cloud
deployments and enabling services.
• As they mature - 10-50GB.
► More instances and deployed apps in Cloud, 50-200GB.
► Most customers are 100-200GB / day of Public Cloud data.
► All-in Cloud Companies : 500GB-1TB range.
► Less common >1TB
► O365 - ~400 to 500 KB per user per day (50K users = 25 GB/day)
► Best way to analyze the amount of data is to spin-off a test environment and look
at the numbers.
How Much Data?
© 2017 SPLUNK INC.
Collection
Deployment
Architectures
© 2019 SPLUNK INC.
► Central Splunk Instance
• One Instance to manage – lower “Instance/Storage” costs
• Data egress cost considerations (data transfers from each cloud)
• Local or Distributed Heavy Forwarders
► Splunk Instance per Cloud, 1 “Master” view
• One Instance in each Cloud – potential higher “Instance/Storage” cost
• Management of Splunk in each Cloud
• “Master” Search Head needed for Hybrid Search – latency impact
• Lower egress cost
► Hybrid
• Mix of both options balancing out Costs/Hybrid Search
Deployment Architecture
3 Patterns
© 2019 SPLUNK INC.
Option 1
Public/Private Cloud /
Splunk Cloud
Single Splunk InstanceHeavy Forwarder (Add-On)
Heavy Forwarder (Add-On)
Heavy Forwarder (Add-On)
Note Options for Serverless/HEC input direct
to Central Instance
Cloud Data
© 2019 SPLUNK INC.
Option 2
Public/Private Cloud
Distributed Hybrid SearchSplunk Indexer(s)
Splunk Indexer(s)
Splunk Indexer(s)
Search Head
Search Results
© 2019 SPLUNK INC.
Option 3
Distributed Search
Splunk Indexer(s) &
Master Search
Splunk Indexer(s)
Heavy Forwarder (Add-On)
Cloud Data
Search Results
© 2019 SPLUNK INC.© 2017 SPLUNK INC.
© 2017 SPLUNK INC.
OUR MISSION
….Including Cloud data!
© 2019 SPLUNK INC.
Hybrid Monitoring
Collect & store machine data generated by on-premises IT sources and public cloud
sources simultaneously, and can correlate across both to monitor, alert, analyse,
troubleshoot and investigate.
© 2017 SPLUNK INC.
Pulling it all together:
Example Cloud Innovation,
Integration and Use Case
AWS Security Hub + Splunk Phantom Bi-Directional Integration
© 2019 SPLUNK INC.
AWS Security Hub - Findings
© 2019 SPLUNK INC.
Phantom - EC2 Instance- Investigate & Notify
© 2019 SPLUNK INC.
Geo Location & IP Reputation
© 2019 SPLUNK INC.
Prompting The Analyst- Quarantine Instance
© 2019 SPLUNK INC.
Phantom- Isolate ES2 Instance Playbook
© 2019 SPLUNK INC.
© 2019 SPLUNK INC.
Back To AWS Security Hub
© 2019 SPLUNK INC.© 2019 SPLUNK INC.
Don't forget to rate this session
in the .conf18 mobile app
Thank You.

Mais conteúdo relacionado

Mais procurados

Splunk Architecture | Splunk Tutorial For Beginners | Splunk Training | Splun...
Splunk Architecture | Splunk Tutorial For Beginners | Splunk Training | Splun...Splunk Architecture | Splunk Tutorial For Beginners | Splunk Training | Splun...
Splunk Architecture | Splunk Tutorial For Beginners | Splunk Training | Splun...Edureka!
 
Splunk Distributed Management Console
Splunk Distributed Management Console                                         Splunk Distributed Management Console
Splunk Distributed Management Console Splunk
 
PPT-Splunk-LegacySIEM-101_FINAL
PPT-Splunk-LegacySIEM-101_FINALPPT-Splunk-LegacySIEM-101_FINAL
PPT-Splunk-LegacySIEM-101_FINALRisi Avila
 
Splunk for IT Operations
Splunk for IT OperationsSplunk for IT Operations
Splunk for IT OperationsSplunk
 
Splunk Enterprise Security
Splunk Enterprise Security Splunk Enterprise Security
Splunk Enterprise Security Md Mofijul Haque
 
Splunk for Enterprise Security and User Behavior Analytics
 Splunk for Enterprise Security and User Behavior Analytics Splunk for Enterprise Security and User Behavior Analytics
Splunk for Enterprise Security and User Behavior AnalyticsSplunk
 
Taking Splunk to the Next Level - Architecture
Taking Splunk to the Next Level - ArchitectureTaking Splunk to the Next Level - Architecture
Taking Splunk to the Next Level - ArchitectureSplunk
 
Presentation cisco iron port email & web security
Presentation   cisco iron port email & web securityPresentation   cisco iron port email & web security
Presentation cisco iron port email & web securityxKinAnx
 
Getting Started with Splunk Enterprise
Getting Started with Splunk EnterpriseGetting Started with Splunk Enterprise
Getting Started with Splunk EnterpriseSplunk
 
Introducing log analysis to your organization
Introducing log analysis to your organization Introducing log analysis to your organization
Introducing log analysis to your organization Sematext Group, Inc.
 
Splunk Overview
Splunk OverviewSplunk Overview
Splunk OverviewSplunk
 
Stream processing and managing real-time data
Stream processing and managing real-time dataStream processing and managing real-time data
Stream processing and managing real-time dataAmazon Web Services
 
Real-time Data Pipelines with SAP and Apache Kafka
Real-time Data Pipelines with SAP and Apache KafkaReal-time Data Pipelines with SAP and Apache Kafka
Real-time Data Pipelines with SAP and Apache KafkaCarole Gunst
 
Splunk Webinar: Full-Stack End-to-End SAP-Monitoring mit Splunk
Splunk Webinar: Full-Stack End-to-End SAP-Monitoring mit SplunkSplunk Webinar: Full-Stack End-to-End SAP-Monitoring mit Splunk
Splunk Webinar: Full-Stack End-to-End SAP-Monitoring mit SplunkSplunk
 
SplunkSummit 2015 - A Quick Guide to Search Optimization
SplunkSummit 2015 - A Quick Guide to Search OptimizationSplunkSummit 2015 - A Quick Guide to Search Optimization
SplunkSummit 2015 - A Quick Guide to Search OptimizationSplunk
 
Splunk Ninjas: New Features and Search Dojo
Splunk Ninjas: New Features and Search DojoSplunk Ninjas: New Features and Search Dojo
Splunk Ninjas: New Features and Search DojoSplunk
 
Splunk Architecture overview
Splunk Architecture overviewSplunk Architecture overview
Splunk Architecture overviewAlex Fok
 
Analytics Driven SIEM Workshop
Analytics Driven SIEM WorkshopAnalytics Driven SIEM Workshop
Analytics Driven SIEM WorkshopSplunk
 
Getting Started with Splunk (Hands-On)
Getting Started with Splunk (Hands-On) Getting Started with Splunk (Hands-On)
Getting Started with Splunk (Hands-On) Splunk
 

Mais procurados (20)

Splunk Architecture | Splunk Tutorial For Beginners | Splunk Training | Splun...
Splunk Architecture | Splunk Tutorial For Beginners | Splunk Training | Splun...Splunk Architecture | Splunk Tutorial For Beginners | Splunk Training | Splun...
Splunk Architecture | Splunk Tutorial For Beginners | Splunk Training | Splun...
 
Splunk Distributed Management Console
Splunk Distributed Management Console                                         Splunk Distributed Management Console
Splunk Distributed Management Console
 
Splunk Architecture
Splunk ArchitectureSplunk Architecture
Splunk Architecture
 
PPT-Splunk-LegacySIEM-101_FINAL
PPT-Splunk-LegacySIEM-101_FINALPPT-Splunk-LegacySIEM-101_FINAL
PPT-Splunk-LegacySIEM-101_FINAL
 
Splunk for IT Operations
Splunk for IT OperationsSplunk for IT Operations
Splunk for IT Operations
 
Splunk Enterprise Security
Splunk Enterprise Security Splunk Enterprise Security
Splunk Enterprise Security
 
Splunk for Enterprise Security and User Behavior Analytics
 Splunk for Enterprise Security and User Behavior Analytics Splunk for Enterprise Security and User Behavior Analytics
Splunk for Enterprise Security and User Behavior Analytics
 
Taking Splunk to the Next Level - Architecture
Taking Splunk to the Next Level - ArchitectureTaking Splunk to the Next Level - Architecture
Taking Splunk to the Next Level - Architecture
 
Presentation cisco iron port email & web security
Presentation   cisco iron port email & web securityPresentation   cisco iron port email & web security
Presentation cisco iron port email & web security
 
Getting Started with Splunk Enterprise
Getting Started with Splunk EnterpriseGetting Started with Splunk Enterprise
Getting Started with Splunk Enterprise
 
Introducing log analysis to your organization
Introducing log analysis to your organization Introducing log analysis to your organization
Introducing log analysis to your organization
 
Splunk Overview
Splunk OverviewSplunk Overview
Splunk Overview
 
Stream processing and managing real-time data
Stream processing and managing real-time dataStream processing and managing real-time data
Stream processing and managing real-time data
 
Real-time Data Pipelines with SAP and Apache Kafka
Real-time Data Pipelines with SAP and Apache KafkaReal-time Data Pipelines with SAP and Apache Kafka
Real-time Data Pipelines with SAP and Apache Kafka
 
Splunk Webinar: Full-Stack End-to-End SAP-Monitoring mit Splunk
Splunk Webinar: Full-Stack End-to-End SAP-Monitoring mit SplunkSplunk Webinar: Full-Stack End-to-End SAP-Monitoring mit Splunk
Splunk Webinar: Full-Stack End-to-End SAP-Monitoring mit Splunk
 
SplunkSummit 2015 - A Quick Guide to Search Optimization
SplunkSummit 2015 - A Quick Guide to Search OptimizationSplunkSummit 2015 - A Quick Guide to Search Optimization
SplunkSummit 2015 - A Quick Guide to Search Optimization
 
Splunk Ninjas: New Features and Search Dojo
Splunk Ninjas: New Features and Search DojoSplunk Ninjas: New Features and Search Dojo
Splunk Ninjas: New Features and Search Dojo
 
Splunk Architecture overview
Splunk Architecture overviewSplunk Architecture overview
Splunk Architecture overview
 
Analytics Driven SIEM Workshop
Analytics Driven SIEM WorkshopAnalytics Driven SIEM Workshop
Analytics Driven SIEM Workshop
 
Getting Started with Splunk (Hands-On)
Getting Started with Splunk (Hands-On) Getting Started with Splunk (Hands-On)
Getting Started with Splunk (Hands-On)
 

Semelhante a Clear the Mist from your Clouds with Splunk

Splunk und Multi-Cloud
Splunk und Multi-CloudSplunk und Multi-Cloud
Splunk und Multi-CloudSplunk
 
Splunk and Multicloud
Splunk and MulticloudSplunk and Multicloud
Splunk and MulticloudSplunk
 
Splunk and Multicloud
Splunk and Multicloud Splunk and Multicloud
Splunk and Multicloud Splunk
 
Securing the Enterprise/Cloud with Splunk at the Centre
Securing the Enterprise/Cloud with Splunk at the CentreSecuring the Enterprise/Cloud with Splunk at the Centre
Securing the Enterprise/Cloud with Splunk at the CentreHarry McLaren
 
What's New with the Latest Splunk Platform Release
What's New with the Latest Splunk Platform ReleaseWhat's New with the Latest Splunk Platform Release
What's New with the Latest Splunk Platform ReleaseSplunk
 
Splunk Cloud and Splunk Enterprise 7.2
Splunk Cloud and Splunk Enterprise 7.2 Splunk Cloud and Splunk Enterprise 7.2
Splunk Cloud and Splunk Enterprise 7.2 Splunk
 
Splunk Cloud and Splunk Enterprise 7.2
Splunk Cloud and Splunk Enterprise 7.2 Splunk Cloud and Splunk Enterprise 7.2
Splunk Cloud and Splunk Enterprise 7.2 Splunk
 
Splunk Cloud and Splunk Enterprise 7.2
Splunk Cloud and Splunk Enterprise 7.2Splunk Cloud and Splunk Enterprise 7.2
Splunk Cloud and Splunk Enterprise 7.2Splunk
 
Encontro anual para apresentação das novidades da .conf23
Encontro anual para apresentação das novidades da .conf23Encontro anual para apresentação das novidades da .conf23
Encontro anual para apresentação das novidades da .conf23Rafael Santos
 
Alle Neuigkeiten im letzten Plattform Release
Alle Neuigkeiten im letzten Plattform ReleaseAlle Neuigkeiten im letzten Plattform Release
Alle Neuigkeiten im letzten Plattform ReleaseSplunk
 
.conf Go Zurich 2022 - Platform Session
.conf Go Zurich 2022 - Platform Session.conf Go Zurich 2022 - Platform Session
.conf Go Zurich 2022 - Platform SessionSplunk
 
Splunk .conf18 Updates, Config Add-on, SplDevOps
Splunk .conf18 Updates, Config Add-on, SplDevOpsSplunk .conf18 Updates, Config Add-on, SplDevOps
Splunk .conf18 Updates, Config Add-on, SplDevOpsHarry McLaren
 
Best Practices for Splunk Deployments
Best Practices for Splunk DeploymentsBest Practices for Splunk Deployments
Best Practices for Splunk DeploymentsSplunk
 
SplunkLive! London 2017 - DevOps Powered by Splunk
SplunkLive! London 2017 - DevOps Powered by SplunkSplunkLive! London 2017 - DevOps Powered by Splunk
SplunkLive! London 2017 - DevOps Powered by SplunkSplunk
 
ABD208_Cox Automotive Empowered to Scale with Splunk Cloud & AWS and Explores...
ABD208_Cox Automotive Empowered to Scale with Splunk Cloud & AWS and Explores...ABD208_Cox Automotive Empowered to Scale with Splunk Cloud & AWS and Explores...
ABD208_Cox Automotive Empowered to Scale with Splunk Cloud & AWS and Explores...Amazon Web Services
 
How to Get on Top of Your Cloud Strategy
How to Get on Top of Your Cloud StrategyHow to Get on Top of Your Cloud Strategy
How to Get on Top of Your Cloud StrategyComcast Business
 
TechWiseTV Workshop: Cisco Hybrid Cloud Platform for Google Cloud
TechWiseTV Workshop:  Cisco Hybrid Cloud Platform for Google CloudTechWiseTV Workshop:  Cisco Hybrid Cloud Platform for Google Cloud
TechWiseTV Workshop: Cisco Hybrid Cloud Platform for Google CloudRobb Boyd
 
Splunk Discovery Day Milwaukee 9-14-17
Splunk Discovery Day Milwaukee 9-14-17Splunk Discovery Day Milwaukee 9-14-17
Splunk Discovery Day Milwaukee 9-14-17Splunk
 
Splunk Phantom, the Endpoint Data Model & Splunk Security Essentials App!
Splunk Phantom, the Endpoint Data Model & Splunk Security Essentials App!Splunk Phantom, the Endpoint Data Model & Splunk Security Essentials App!
Splunk Phantom, the Endpoint Data Model & Splunk Security Essentials App!Harry McLaren
 
SplunkLive! Zurich 2017 - Data Obfuscation in Splunk Enterprise
SplunkLive! Zurich 2017 - Data Obfuscation in Splunk EnterpriseSplunkLive! Zurich 2017 - Data Obfuscation in Splunk Enterprise
SplunkLive! Zurich 2017 - Data Obfuscation in Splunk EnterpriseSplunk
 

Semelhante a Clear the Mist from your Clouds with Splunk (20)

Splunk und Multi-Cloud
Splunk und Multi-CloudSplunk und Multi-Cloud
Splunk und Multi-Cloud
 
Splunk and Multicloud
Splunk and MulticloudSplunk and Multicloud
Splunk and Multicloud
 
Splunk and Multicloud
Splunk and Multicloud Splunk and Multicloud
Splunk and Multicloud
 
Securing the Enterprise/Cloud with Splunk at the Centre
Securing the Enterprise/Cloud with Splunk at the CentreSecuring the Enterprise/Cloud with Splunk at the Centre
Securing the Enterprise/Cloud with Splunk at the Centre
 
What's New with the Latest Splunk Platform Release
What's New with the Latest Splunk Platform ReleaseWhat's New with the Latest Splunk Platform Release
What's New with the Latest Splunk Platform Release
 
Splunk Cloud and Splunk Enterprise 7.2
Splunk Cloud and Splunk Enterprise 7.2 Splunk Cloud and Splunk Enterprise 7.2
Splunk Cloud and Splunk Enterprise 7.2
 
Splunk Cloud and Splunk Enterprise 7.2
Splunk Cloud and Splunk Enterprise 7.2 Splunk Cloud and Splunk Enterprise 7.2
Splunk Cloud and Splunk Enterprise 7.2
 
Splunk Cloud and Splunk Enterprise 7.2
Splunk Cloud and Splunk Enterprise 7.2Splunk Cloud and Splunk Enterprise 7.2
Splunk Cloud and Splunk Enterprise 7.2
 
Encontro anual para apresentação das novidades da .conf23
Encontro anual para apresentação das novidades da .conf23Encontro anual para apresentação das novidades da .conf23
Encontro anual para apresentação das novidades da .conf23
 
Alle Neuigkeiten im letzten Plattform Release
Alle Neuigkeiten im letzten Plattform ReleaseAlle Neuigkeiten im letzten Plattform Release
Alle Neuigkeiten im letzten Plattform Release
 
.conf Go Zurich 2022 - Platform Session
.conf Go Zurich 2022 - Platform Session.conf Go Zurich 2022 - Platform Session
.conf Go Zurich 2022 - Platform Session
 
Splunk .conf18 Updates, Config Add-on, SplDevOps
Splunk .conf18 Updates, Config Add-on, SplDevOpsSplunk .conf18 Updates, Config Add-on, SplDevOps
Splunk .conf18 Updates, Config Add-on, SplDevOps
 
Best Practices for Splunk Deployments
Best Practices for Splunk DeploymentsBest Practices for Splunk Deployments
Best Practices for Splunk Deployments
 
SplunkLive! London 2017 - DevOps Powered by Splunk
SplunkLive! London 2017 - DevOps Powered by SplunkSplunkLive! London 2017 - DevOps Powered by Splunk
SplunkLive! London 2017 - DevOps Powered by Splunk
 
ABD208_Cox Automotive Empowered to Scale with Splunk Cloud & AWS and Explores...
ABD208_Cox Automotive Empowered to Scale with Splunk Cloud & AWS and Explores...ABD208_Cox Automotive Empowered to Scale with Splunk Cloud & AWS and Explores...
ABD208_Cox Automotive Empowered to Scale with Splunk Cloud & AWS and Explores...
 
How to Get on Top of Your Cloud Strategy
How to Get on Top of Your Cloud StrategyHow to Get on Top of Your Cloud Strategy
How to Get on Top of Your Cloud Strategy
 
TechWiseTV Workshop: Cisco Hybrid Cloud Platform for Google Cloud
TechWiseTV Workshop:  Cisco Hybrid Cloud Platform for Google CloudTechWiseTV Workshop:  Cisco Hybrid Cloud Platform for Google Cloud
TechWiseTV Workshop: Cisco Hybrid Cloud Platform for Google Cloud
 
Splunk Discovery Day Milwaukee 9-14-17
Splunk Discovery Day Milwaukee 9-14-17Splunk Discovery Day Milwaukee 9-14-17
Splunk Discovery Day Milwaukee 9-14-17
 
Splunk Phantom, the Endpoint Data Model & Splunk Security Essentials App!
Splunk Phantom, the Endpoint Data Model & Splunk Security Essentials App!Splunk Phantom, the Endpoint Data Model & Splunk Security Essentials App!
Splunk Phantom, the Endpoint Data Model & Splunk Security Essentials App!
 
SplunkLive! Zurich 2017 - Data Obfuscation in Splunk Enterprise
SplunkLive! Zurich 2017 - Data Obfuscation in Splunk EnterpriseSplunkLive! Zurich 2017 - Data Obfuscation in Splunk Enterprise
SplunkLive! Zurich 2017 - Data Obfuscation in Splunk Enterprise
 

Mais de Splunk

.conf Go 2023 - Data analysis as a routine
.conf Go 2023 - Data analysis as a routine.conf Go 2023 - Data analysis as a routine
.conf Go 2023 - Data analysis as a routineSplunk
 
.conf Go 2023 - How KPN drives Customer Satisfaction on IPTV
.conf Go 2023 - How KPN drives Customer Satisfaction on IPTV.conf Go 2023 - How KPN drives Customer Satisfaction on IPTV
.conf Go 2023 - How KPN drives Customer Satisfaction on IPTVSplunk
 
.conf Go 2023 - Navegando la normativa SOX (Telefónica)
.conf Go 2023 - Navegando la normativa SOX (Telefónica).conf Go 2023 - Navegando la normativa SOX (Telefónica)
.conf Go 2023 - Navegando la normativa SOX (Telefónica)Splunk
 
.conf Go 2023 - Raiffeisen Bank International
.conf Go 2023 - Raiffeisen Bank International.conf Go 2023 - Raiffeisen Bank International
.conf Go 2023 - Raiffeisen Bank InternationalSplunk
 
.conf Go 2023 - På liv og død Om sikkerhetsarbeid i Norsk helsenett
.conf Go 2023 - På liv og død Om sikkerhetsarbeid i Norsk helsenett .conf Go 2023 - På liv og død Om sikkerhetsarbeid i Norsk helsenett
.conf Go 2023 - På liv og død Om sikkerhetsarbeid i Norsk helsenett Splunk
 
.conf Go 2023 - Many roads lead to Rome - this was our journey (Julius Bär)
.conf Go 2023 - Many roads lead to Rome - this was our journey (Julius Bär).conf Go 2023 - Many roads lead to Rome - this was our journey (Julius Bär)
.conf Go 2023 - Many roads lead to Rome - this was our journey (Julius Bär)Splunk
 
.conf Go 2023 - Das passende Rezept für die digitale (Security) Revolution zu...
.conf Go 2023 - Das passende Rezept für die digitale (Security) Revolution zu....conf Go 2023 - Das passende Rezept für die digitale (Security) Revolution zu...
.conf Go 2023 - Das passende Rezept für die digitale (Security) Revolution zu...Splunk
 
.conf go 2023 - Cyber Resilienz – Herausforderungen und Ansatz für Energiever...
.conf go 2023 - Cyber Resilienz – Herausforderungen und Ansatz für Energiever....conf go 2023 - Cyber Resilienz – Herausforderungen und Ansatz für Energiever...
.conf go 2023 - Cyber Resilienz – Herausforderungen und Ansatz für Energiever...Splunk
 
.conf go 2023 - De NOC a CSIRT (Cellnex)
.conf go 2023 - De NOC a CSIRT (Cellnex).conf go 2023 - De NOC a CSIRT (Cellnex)
.conf go 2023 - De NOC a CSIRT (Cellnex)Splunk
 
conf go 2023 - El camino hacia la ciberseguridad (ABANCA)
conf go 2023 - El camino hacia la ciberseguridad (ABANCA)conf go 2023 - El camino hacia la ciberseguridad (ABANCA)
conf go 2023 - El camino hacia la ciberseguridad (ABANCA)Splunk
 
Splunk - BMW connects business and IT with data driven operations SRE and O11y
Splunk - BMW connects business and IT with data driven operations SRE and O11ySplunk - BMW connects business and IT with data driven operations SRE and O11y
Splunk - BMW connects business and IT with data driven operations SRE and O11ySplunk
 
Splunk x Freenet - .conf Go Köln
Splunk x Freenet - .conf Go KölnSplunk x Freenet - .conf Go Köln
Splunk x Freenet - .conf Go KölnSplunk
 
Splunk Security Session - .conf Go Köln
Splunk Security Session - .conf Go KölnSplunk Security Session - .conf Go Köln
Splunk Security Session - .conf Go KölnSplunk
 
Data foundations building success, at city scale – Imperial College London
 Data foundations building success, at city scale – Imperial College London Data foundations building success, at city scale – Imperial College London
Data foundations building success, at city scale – Imperial College LondonSplunk
 
Splunk: How Vodafone established Operational Analytics in a Hybrid Environmen...
Splunk: How Vodafone established Operational Analytics in a Hybrid Environmen...Splunk: How Vodafone established Operational Analytics in a Hybrid Environmen...
Splunk: How Vodafone established Operational Analytics in a Hybrid Environmen...Splunk
 
SOC, Amore Mio! | Security Webinar
SOC, Amore Mio! | Security WebinarSOC, Amore Mio! | Security Webinar
SOC, Amore Mio! | Security WebinarSplunk
 
.conf Go 2022 - Observability Session
.conf Go 2022 - Observability Session.conf Go 2022 - Observability Session
.conf Go 2022 - Observability SessionSplunk
 
.conf Go Zurich 2022 - Keynote
.conf Go Zurich 2022 - Keynote.conf Go Zurich 2022 - Keynote
.conf Go Zurich 2022 - KeynoteSplunk
 
.conf Go Zurich 2022 - Security Session
.conf Go Zurich 2022 - Security Session.conf Go Zurich 2022 - Security Session
.conf Go Zurich 2022 - Security SessionSplunk
 
Inside SecOps at bet365
Inside SecOps at bet365 Inside SecOps at bet365
Inside SecOps at bet365 Splunk
 

Mais de Splunk (20)

.conf Go 2023 - Data analysis as a routine
.conf Go 2023 - Data analysis as a routine.conf Go 2023 - Data analysis as a routine
.conf Go 2023 - Data analysis as a routine
 
.conf Go 2023 - How KPN drives Customer Satisfaction on IPTV
.conf Go 2023 - How KPN drives Customer Satisfaction on IPTV.conf Go 2023 - How KPN drives Customer Satisfaction on IPTV
.conf Go 2023 - How KPN drives Customer Satisfaction on IPTV
 
.conf Go 2023 - Navegando la normativa SOX (Telefónica)
.conf Go 2023 - Navegando la normativa SOX (Telefónica).conf Go 2023 - Navegando la normativa SOX (Telefónica)
.conf Go 2023 - Navegando la normativa SOX (Telefónica)
 
.conf Go 2023 - Raiffeisen Bank International
.conf Go 2023 - Raiffeisen Bank International.conf Go 2023 - Raiffeisen Bank International
.conf Go 2023 - Raiffeisen Bank International
 
.conf Go 2023 - På liv og død Om sikkerhetsarbeid i Norsk helsenett
.conf Go 2023 - På liv og død Om sikkerhetsarbeid i Norsk helsenett .conf Go 2023 - På liv og død Om sikkerhetsarbeid i Norsk helsenett
.conf Go 2023 - På liv og død Om sikkerhetsarbeid i Norsk helsenett
 
.conf Go 2023 - Many roads lead to Rome - this was our journey (Julius Bär)
.conf Go 2023 - Many roads lead to Rome - this was our journey (Julius Bär).conf Go 2023 - Many roads lead to Rome - this was our journey (Julius Bär)
.conf Go 2023 - Many roads lead to Rome - this was our journey (Julius Bär)
 
.conf Go 2023 - Das passende Rezept für die digitale (Security) Revolution zu...
.conf Go 2023 - Das passende Rezept für die digitale (Security) Revolution zu....conf Go 2023 - Das passende Rezept für die digitale (Security) Revolution zu...
.conf Go 2023 - Das passende Rezept für die digitale (Security) Revolution zu...
 
.conf go 2023 - Cyber Resilienz – Herausforderungen und Ansatz für Energiever...
.conf go 2023 - Cyber Resilienz – Herausforderungen und Ansatz für Energiever....conf go 2023 - Cyber Resilienz – Herausforderungen und Ansatz für Energiever...
.conf go 2023 - Cyber Resilienz – Herausforderungen und Ansatz für Energiever...
 
.conf go 2023 - De NOC a CSIRT (Cellnex)
.conf go 2023 - De NOC a CSIRT (Cellnex).conf go 2023 - De NOC a CSIRT (Cellnex)
.conf go 2023 - De NOC a CSIRT (Cellnex)
 
conf go 2023 - El camino hacia la ciberseguridad (ABANCA)
conf go 2023 - El camino hacia la ciberseguridad (ABANCA)conf go 2023 - El camino hacia la ciberseguridad (ABANCA)
conf go 2023 - El camino hacia la ciberseguridad (ABANCA)
 
Splunk - BMW connects business and IT with data driven operations SRE and O11y
Splunk - BMW connects business and IT with data driven operations SRE and O11ySplunk - BMW connects business and IT with data driven operations SRE and O11y
Splunk - BMW connects business and IT with data driven operations SRE and O11y
 
Splunk x Freenet - .conf Go Köln
Splunk x Freenet - .conf Go KölnSplunk x Freenet - .conf Go Köln
Splunk x Freenet - .conf Go Köln
 
Splunk Security Session - .conf Go Köln
Splunk Security Session - .conf Go KölnSplunk Security Session - .conf Go Köln
Splunk Security Session - .conf Go Köln
 
Data foundations building success, at city scale – Imperial College London
 Data foundations building success, at city scale – Imperial College London Data foundations building success, at city scale – Imperial College London
Data foundations building success, at city scale – Imperial College London
 
Splunk: How Vodafone established Operational Analytics in a Hybrid Environmen...
Splunk: How Vodafone established Operational Analytics in a Hybrid Environmen...Splunk: How Vodafone established Operational Analytics in a Hybrid Environmen...
Splunk: How Vodafone established Operational Analytics in a Hybrid Environmen...
 
SOC, Amore Mio! | Security Webinar
SOC, Amore Mio! | Security WebinarSOC, Amore Mio! | Security Webinar
SOC, Amore Mio! | Security Webinar
 
.conf Go 2022 - Observability Session
.conf Go 2022 - Observability Session.conf Go 2022 - Observability Session
.conf Go 2022 - Observability Session
 
.conf Go Zurich 2022 - Keynote
.conf Go Zurich 2022 - Keynote.conf Go Zurich 2022 - Keynote
.conf Go Zurich 2022 - Keynote
 
.conf Go Zurich 2022 - Security Session
.conf Go Zurich 2022 - Security Session.conf Go Zurich 2022 - Security Session
.conf Go Zurich 2022 - Security Session
 
Inside SecOps at bet365
Inside SecOps at bet365 Inside SecOps at bet365
Inside SecOps at bet365
 

Último

Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FMESafe Software
 
Deploy with confidence: VMware Cloud Foundation 5.1 on next gen Dell PowerEdg...
Deploy with confidence: VMware Cloud Foundation 5.1 on next gen Dell PowerEdg...Deploy with confidence: VMware Cloud Foundation 5.1 on next gen Dell PowerEdg...
Deploy with confidence: VMware Cloud Foundation 5.1 on next gen Dell PowerEdg...Principled Technologies
 
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...Neo4j
 
Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024The Digital Insurer
 
2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...Martijn de Jong
 
Artificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and MythsArtificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and MythsJoaquim Jorge
 
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot TakeoffStrategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoffsammart93
 
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024The Digital Insurer
 
Manulife - Insurer Innovation Award 2024
Manulife - Insurer Innovation Award 2024Manulife - Insurer Innovation Award 2024
Manulife - Insurer Innovation Award 2024The Digital Insurer
 
🐬 The future of MySQL is Postgres 🐘
🐬  The future of MySQL is Postgres   🐘🐬  The future of MySQL is Postgres   🐘
🐬 The future of MySQL is Postgres 🐘RTylerCroy
 
Strategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a FresherStrategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a FresherRemote DBA Services
 
TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data DiscoveryTrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data DiscoveryTrustArc
 
Artificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : UncertaintyArtificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : UncertaintyKhushali Kathiriya
 
HTML Injection Attacks: Impact and Mitigation Strategies
HTML Injection Attacks: Impact and Mitigation StrategiesHTML Injection Attacks: Impact and Mitigation Strategies
HTML Injection Attacks: Impact and Mitigation StrategiesBoston Institute of Analytics
 
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024The Digital Insurer
 
Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)wesley chun
 
Exploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone ProcessorsExploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone Processorsdebabhi2
 
MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024MIND CTI
 
Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024The Digital Insurer
 

Último (20)

Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
 
Deploy with confidence: VMware Cloud Foundation 5.1 on next gen Dell PowerEdg...
Deploy with confidence: VMware Cloud Foundation 5.1 on next gen Dell PowerEdg...Deploy with confidence: VMware Cloud Foundation 5.1 on next gen Dell PowerEdg...
Deploy with confidence: VMware Cloud Foundation 5.1 on next gen Dell PowerEdg...
 
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
 
Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024
 
2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...
 
Artificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and MythsArtificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and Myths
 
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot TakeoffStrategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
 
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
 
Manulife - Insurer Innovation Award 2024
Manulife - Insurer Innovation Award 2024Manulife - Insurer Innovation Award 2024
Manulife - Insurer Innovation Award 2024
 
🐬 The future of MySQL is Postgres 🐘
🐬  The future of MySQL is Postgres   🐘🐬  The future of MySQL is Postgres   🐘
🐬 The future of MySQL is Postgres 🐘
 
Strategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a FresherStrategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a Fresher
 
TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data DiscoveryTrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
 
Artificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : UncertaintyArtificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : Uncertainty
 
HTML Injection Attacks: Impact and Mitigation Strategies
HTML Injection Attacks: Impact and Mitigation StrategiesHTML Injection Attacks: Impact and Mitigation Strategies
HTML Injection Attacks: Impact and Mitigation Strategies
 
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
 
Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)
 
Exploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone ProcessorsExploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone Processors
 
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
 
MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024
 
Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024
 

Clear the Mist from your Clouds with Splunk

  • 1. © 2019 SPLUNK INC.© 2019 SPLUNK INC. Clear the Mist from your Clouds with Splunk SplunkLive London - June 2019 Yuval Tenenbaum Director – SE Architects EMEA
  • 2. © 2017 SPLUNK INC. Migration To Cloud & Hybrid Cloud Insights is Top Of Mind
  • 3. © 2019 SPLUNK INC. ► Enables Least privileged model at the highest operational control ► Mitigates Risk – lower the ‘blast radius’ of impactful events ► Achieve Agility- deploy & run environments programmatically at scale ► Cost optimisation- clear ‘line of sight’ into the cost of running workloads Hybrid Cloud – Think Differently Legacy Model Least privileged
  • 4. © 2019 SPLUNK INC. ► Split Investment may slow down your cloud adoption – Spreading your resources across multiple clouds means that you may not get critical mass or a fast ROI ► Portability - How many of us will actually move workloads around? ► Cloud Broker concept – Putting a “bloatware” between you and your cloud api’s instead of working natively with these cloud API’s Is it Really All Good Stuff? I used to be indecisive now I’m definitely going multi- cloud
  • 5. © 2019 SPLUNK INC. Cloud - Same Challenges-Different Environments ► Security • Are we firewalled correctly? • Do we use all necessary security features? ► Compliance • Are we following all published standards? ► Networking • Placed servers on the correct network? ► Financial • Stayed within budget? ► Capacity Planning • Used resources optimally? And all of that in a decentralized Model…
  • 6. © 2019 SPLUNK INC. Customer experience??? SAAS Hybrid Everything - What happens when we stack them? ON PREMISES Legacy systems (Mainframe…) Facilities Dev/PreProd Storage Backup Archive DR Security VMs Containers Micro services AWS (Application 1)Access / Security Database StorageDev Compute Containers App engine GCP (Big Data project 1) Dataflow AWS (Archive) Azure (Application 1) VMs Database VM sets Traffic mger
  • 7. © 2017 SPLUNK INC. So How Can Splunk Clear up this Cloudy Mist? Know your Clouds…..
  • 8. © 2019 SPLUNK INC. ► Splunk has working relationships with AWS, Azure, and GCP ► We have customers successfully running Splunk Enterprise BYOL within AWS, Azure, and GCP ► We have proven strategies to get data in from AWS, Azure, and GCP Cloud Vendor Relationships
  • 9. © 2017 SPLUNK INC. Splunk’s Approach to Hybrid Cloud One Consolidated Solution Manage Hybrid Infrastructure Cost, Capacity and Resource Management Cloud Migration Splunk takes the place of the multitude of monitoring tools because sometimes one is better than many. Deploy Splunk in Hybrid setup (on-prem, saas, byol) and deal with Hybrid infrastructure complex monitoring Understand how your resources are performing – and how many are being used – then optimize utilization and billing. Get visibility at all stages of the migration process (landing zones)– whether before, during or long after.
  • 10. © 2017 SPLUNK INC. In the Beginning…… Cloud Migration
  • 11. © 2019 SPLUNK INC. What Customers Want To Achieve When Migrating to the Cloud ► Build - Differentiate yourself by building unique and valuable services ► Move Fast - From initial idea to a service which can be monetized ► Stay Secure - Make sure that what we build is secure and compliant ▶ Manage Cost – Control what you spend and gain visibility into future cost
  • 12. © 2019 SPLUNK INC. Path To Successful Cloud Migration Measure the baseline user experience and performance, as well as define acceptable post-migration levels. Security assessment – build a well architected and compliant landing zones Performance metrics should be closely monitored & compared to the baseline. Throughout the migration, end-to-end monitoring can help SecOps teams stay ahead of any potential risks. Continuous monitoring should be used to measure acceptable metrics and success. Leverage a platform that shows insights into cost, shared services, monitoring, Security & compliance BEFORE DURING AFTER
  • 13. © 2019 SPLUNK INC. Challenges With Building & Maintaining Landing Zones ▶ Define & maintain an Account structure ▶ Define your network architecture and monitor it continuously ▶ Define & maintain a security governance and compliance baseline Migrate Land Operate & Optimize
  • 14. © 2019 SPLUNK INC. Additional Considerations ▶ Define & maintain centralized logging ▶ Define & maintain Cost Allocation
  • 15. © 2019 SPLUNK INC. How Can Splunk Help (1)? ▶ Tell you who is accessing your accounts, from where and what are they doing?
  • 16. © 2019 SPLUNK INC. How Can Splunk Help (2)? ▶ Tell you if anyone is breaking your security policies? • Is encryption used everywhere • Has the root account has MFA enabled • Suspicious AWS S3 Activities • IAM Password policies are kept as you defined in your security baseline?
  • 17. © 2019 SPLUNK INC. How Can Splunk Help (3)? ▶ Help you understand your network topology and gain visibility into who is trying to access it ▶ Help you gain visibility into performance & right sizing of your key workloads ▶ Help you understand historic and future cost
  • 18. © 2019 SPLUNK INC. AWS Analytic Stories - ES Content Updates
  • 19. © 2019 SPLUNK INC. Migration Dashboards
  • 20. © 2017 SPLUNK INC. So How Do We Collect Cloud Data to do this Hybrid Monitoring?
  • 21. © 2017 SPLUNK INC. Getting Data In Cloud Patterns
  • 22. © 2017 SPLUNK INC. General Getting Data In Routes Pull or Push, Add-Ons or Serverless Poll/Request API Data Data Cloud Serverless Code Add-On HEC “Push”
  • 23. © 2017 SPLUNK INC. GDI : AWS
  • 24. © 2019 SPLUNK INC. It May Look a Bit Complicated
  • 25. © 2019 SPLUNK INC. ► AWS Config can be pulled with a Splunk Heavy Forwarder with the SQS Based S3. Anything via CloudWatch Logs or CW events, can be pushed with Kinesis Firehose to Splunk AWS Pull vs. Push Config Events SNS Topic Notification SQS Subscription Notification Pulls Event from S3 Bucket Splunk Pull SQS Notification HEC PushPull CloudWatch Logs
  • 26. © 2019 SPLUNK INC. AWS Source Matrix There are many options to GDI in AWS but Splunk can help Data Type Recommended Input Type Billing Billing CloudWatch CloudWatch CloudFront Access Logs SQS based S3 Config SQS based S3 Config Rules Config Rules Description Description ELB Access Logs SQS based S3 Inspector Inspector CloudTrail SQS Based S3 S3 access logs SQS Based S3 VPC Flow Logs (CW Logs) Kinesis With SQS Based S3 you can scale out data collection by configuring multiple inputs to ingest logs from the same S3 bucket without creating duplicate data. Kinesis Firehose is recommended for CloudWatch Logs data collection
  • 27. © 2017 SPLUNK INC. GDI : Azure & O365
  • 28. © 2019 SPLUNK INC. 3 Log Types in Azure 1) Control/Management, 2) Data Plane, 3) Processed Events Control: System Configuration and Management Data Plane: Provisioned Service and Diagnostic Data Processed Events: Alerts & Recommendations
  • 29. © 2019 SPLUNK INC. { REST } Storage Event Hub
  • 30. © 2019 SPLUNK INC. ► Splunk can pull data from Azure using a Heavy Forwarder and collect data from either the MS Blob or a REST API using the modular input. Azure can push data using the Event Hub to Azure Functions which can be sent to Splunk’s HEC. Azure Pull vs. Push MSBlob HEC PushPull Splunk Indexers Activity Monitor Event Hub Azure Function Event Hub
  • 31. © 2019 SPLUNK INC. Azure Add-on Landscape
  • 32. © 2019 SPLUNK INC. Getting O365 Data In Azure Active Directory Application OAUTH2 REST Splunk Add-on for Microsoft O365 Office 365
  • 33. © 2017 SPLUNK INC. GDI : Google Cloud
  • 34. © 2019 SPLUNK INC. Getting GCP Data In REST Splunk Add-on for Google Cloud Platform Billing PubSub Monitoring StackDriver
  • 35. © 2019 SPLUNK INC. ► Initial: • Most customers will generate around 1-10GB when they are setting up their Public Cloud deployments and enabling services. • As they mature - 10-50GB. ► More instances and deployed apps in Cloud, 50-200GB. ► Most customers are 100-200GB / day of Public Cloud data. ► All-in Cloud Companies : 500GB-1TB range. ► Less common >1TB ► O365 - ~400 to 500 KB per user per day (50K users = 25 GB/day) ► Best way to analyze the amount of data is to spin-off a test environment and look at the numbers. How Much Data?
  • 36. © 2017 SPLUNK INC. Collection Deployment Architectures
  • 37. © 2019 SPLUNK INC. ► Central Splunk Instance • One Instance to manage – lower “Instance/Storage” costs • Data egress cost considerations (data transfers from each cloud) • Local or Distributed Heavy Forwarders ► Splunk Instance per Cloud, 1 “Master” view • One Instance in each Cloud – potential higher “Instance/Storage” cost • Management of Splunk in each Cloud • “Master” Search Head needed for Hybrid Search – latency impact • Lower egress cost ► Hybrid • Mix of both options balancing out Costs/Hybrid Search Deployment Architecture 3 Patterns
  • 38. © 2019 SPLUNK INC. Option 1 Public/Private Cloud / Splunk Cloud Single Splunk InstanceHeavy Forwarder (Add-On) Heavy Forwarder (Add-On) Heavy Forwarder (Add-On) Note Options for Serverless/HEC input direct to Central Instance Cloud Data
  • 39. © 2019 SPLUNK INC. Option 2 Public/Private Cloud Distributed Hybrid SearchSplunk Indexer(s) Splunk Indexer(s) Splunk Indexer(s) Search Head Search Results
  • 40. © 2019 SPLUNK INC. Option 3 Distributed Search Splunk Indexer(s) & Master Search Splunk Indexer(s) Heavy Forwarder (Add-On) Cloud Data Search Results
  • 41. © 2019 SPLUNK INC.© 2017 SPLUNK INC. © 2017 SPLUNK INC. OUR MISSION ….Including Cloud data!
  • 42. © 2019 SPLUNK INC. Hybrid Monitoring Collect & store machine data generated by on-premises IT sources and public cloud sources simultaneously, and can correlate across both to monitor, alert, analyse, troubleshoot and investigate.
  • 43. © 2017 SPLUNK INC. Pulling it all together: Example Cloud Innovation, Integration and Use Case AWS Security Hub + Splunk Phantom Bi-Directional Integration
  • 44. © 2019 SPLUNK INC. AWS Security Hub - Findings
  • 45. © 2019 SPLUNK INC. Phantom - EC2 Instance- Investigate & Notify
  • 46. © 2019 SPLUNK INC. Geo Location & IP Reputation
  • 47. © 2019 SPLUNK INC. Prompting The Analyst- Quarantine Instance
  • 48. © 2019 SPLUNK INC. Phantom- Isolate ES2 Instance Playbook
  • 50. © 2019 SPLUNK INC. Back To AWS Security Hub
  • 51. © 2019 SPLUNK INC.© 2019 SPLUNK INC. Don't forget to rate this session in the .conf18 mobile app Thank You.