Top Banner
© 2016, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Kelvin Yeung, Senior Architect, Splunk June 17, 2016 Cloud Is a Journey. Make Splunk Your Partner
29

Partner Solutions: Splunk - Cloud Is a Journey. Make Splunk Your Partner

Jan 09, 2017

Download

Technology

Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: Partner Solutions: Splunk - Cloud Is a Journey. Make Splunk Your Partner

© 2016, Amazon Web Services, Inc. or its Affiliates. All rights reserved.

Kelvin Yeung, Senior Architect, Splunk

June 17, 2016

Cloud Is a Journey. Make Splunk Your Partner

Page 2: Partner Solutions: Splunk - Cloud Is a Journey. Make Splunk Your Partner

SplunkCompanyOverview

2

Company

•  GlobalHQs:-  SanFrancisco-  London-  HongKong

•  2,100+employeesglobally•  AnnualRevenue:$668.4M(YoY+49%)

•  NASDAQ:SPLK

Products

•  Freetrialtomassivescale•  Splunkproducts:

-  SplunkEnterprise-  SplunkCloud-  Hunk-  SplunkLight-  SplunkMINT-  PremiumSoluWons

Customers

•  11,000+customers•  Across110+countries•  SmalltolargeorganizaWons

•  Morethan80oftheFortune100

•  Largestlicense:-  1+Petabytes/day

Page 3: Partner Solutions: Splunk - Cloud Is a Journey. Make Splunk Your Partner

GartnerTechnologyPriori<esforCIOsin2016

3

1.BI/Analy<cs

2.Cloud

3.Mobile

4.Digi<za<on/DigitalMarke<ng

5.Infrastructure&DataCentre

6.ERP

7.Security

8.IndustrySpecificApplica<ons

9.CRM

10.Networking/Voice/DataCommunica<ons

Page 4: Partner Solutions: Splunk - Cloud Is a Journey. Make Splunk Your Partner

CloudMigra<on

SERVERS STORAGE NETWORKING

VIRTUALIZATION

INFRASTRUCTUREAPPLICATIONS

PACKAGEDAPPLICATIONS

CUSTOMAPPLICATIONS

IdenWty

VPN

IPPhone

HR

Email

Finance

AppSvr

DB

WebSvr

Page 5: Partner Solutions: Splunk - Cloud Is a Journey. Make Splunk Your Partner

CloudMigra<on:Considera<ons

SERVERS STORAGE NETWORKING

VIRTUALIZATION

INFRASTRUCTUREAPPLICATIONS

PACKAGEDAPPLICATIONS

CUSTOMAPPLICATIONS

IdenWty

VPN

IPPhone

HR

Email

Finance

AppSvr

DB

WebSvr

Security&Compliance

ApplicaWonPerformance&SLAs OperaWonalVisibility

Page 6: Partner Solutions: Splunk - Cloud Is a Journey. Make Splunk Your Partner

YourApplica<onandTechnologyStackspanacrossCloud&OnPremise

CloudMigra<on:Challenges

Applica<on-BasedSilos

Apps

Servers

Network

Storage

ZonesofVirtualiza<on PrivateCloud HybridCloud

Page 7: Partner Solutions: Splunk - Cloud Is a Journey. Make Splunk Your Partner

IndustryLeadingPla]ormForMachineDataoverHybridCloudEnvironment

MachineData:AnyLoca<on,Type,Volume

Pla]ormSupport(Apps/API/SDKs)

EnterpriseScalability

UniversalIndexing

AnswerAnyQ

ues<on

Customdashboards

Reportandanalyze

Monitorandalert

Adhocsearch

OnlineServices Web

Services

ServersSecurity GPS

LocaWon

StorageDesktops

Networks

PackagedApplicaWons

CustomApplicaWonsMessaging

TelecomsOnline

ShoppingCart

WebClickstreams

Databases

EnergyMeters

CallDetailRecords

SmartphonesandDevices

RFID

On-Premises

PrivateCloud

PublicCloud

Page 8: Partner Solutions: Splunk - Cloud Is a Journey. Make Splunk Your Partner

PlaeormforOperaWonalIntelligence

SplunkAsYourCloudPartner

RichEcosystemofApps&Add-Ons

MainframeData

RelaWonalDatabasesMobileForwarders Syslog/TCP IoT

DevicesNetworkWireData

Hadoop

SplunkEnterpriseSecurity

SplunkITServiceIntelligence

SplunkPremiumSolu<ons

SplunkAppforAWS

Page 9: Partner Solutions: Splunk - Cloud Is a Journey. Make Splunk Your Partner

PlaeormforOperaWonalIntelligence

Security&Compliance

RichEcosystemofApps&Add-Ons

MainframeData

RelaWonalDatabasesMobileForwarders Syslog/TCP IoT

DevicesNetworkWireData

Hadoop

SplunkAppforAWSSplunkEnterpriseSecurity

SplunkITServiceIntelligence

SplunkPremiumSolu<ons

Page 10: Partner Solutions: Splunk - Cloud Is a Journey. Make Splunk Your Partner

SplunkforEnterpriseSecurity

Define rules to detect advanced threats

Unlimited context enrichment to qualify incidents fast

Tailored to analyze & investigate incidents

Enterprise-wide coordination & response

DETECT

INVESTIGATE RESPONSE

ENRICH INFORMATION

Simple solution for sophisticated enterprise scale security operations platform

Page 11: Partner Solutions: Splunk - Cloud Is a Journey. Make Splunk Your Partner

MONITOR RESPOND DETECT FUNCTIONS INVESTIGATE

Splunk’sApproachtoSecurityChallenges

Review Determine 1 2 3 4Decide Act & Adapt

Report Ad hoc "Search

Analyze Collect Store

PROCESS

Notable Events

SECURITY WORKFLOW SUPPORT

Search Management

EVENT CORRELATIONS

SECURITY ENRICHED CONTEXT

KEY FEATURES

Asset, Identity, Others

Threat Info Management

THREAT INTELLIGENCE

Risk Scoring Framework

RISK BASED ANALYTICS

OUT-OF-BOX SECURITY CONTENTS

Views / Reports / Rules

Page 12: Partner Solutions: Splunk - Cloud Is a Journey. Make Splunk Your Partner

SplunkThreatIntelligenceFramework

“Ifyouknowyourselfbutnottheenemy,foreveryvictorygainedyouwillalsosufferadefeat.”

TheArtofWar–SunTzu

Inordertosucceedinthecyberwar

CriWcaltoUnderstandtheHackingTechniquesUsedbyAhackersandtheInforma<ononGlobalThreats

Page 13: Partner Solutions: Splunk - Cloud Is a Journey. Make Splunk Your Partner

SplunkThreatIntelligenceFrameworkFinding hidden IOCs using comprehensive threat intelligence mappings

•  Multiple"sources

•  Multiple transmission"types

•  Multiple"transports

•  Multiple data formats

1.  IP 2.  Emails 3.  URLs 4.  Files names/

hashes 5.  Processes names 6.  Services 7.  Registry entries 8.  X509 Certificates 9.  Users

Manage / Audit threat sources

•  List status •  List mgmt. •  List location

COLLECT MANAGE CATEGORIZE CORRELATE SEARCH INTEL SOURCES

Index, Extract, Categorize

Match all IOCs in existing log data

Generate alert for any matches

KSI and trends

Ad-hoc search, analyze,

investigate, prioritizeC

Data Management Security Dashboard

Correlation Data / Notable Events

Data Search

Page 14: Partner Solutions: Splunk - Cloud Is a Journey. Make Splunk Your Partner

Threat intel indicator overview Shows overall posture of threat activities to understand quickly the changes in the detected threat activities status.

Threat intel trending overview Shows trend changes of threat activities including the changes in the type of threats.

Detailed threat type activities Shows detailed active threat types and associated assets to understand, what kind of threats are active in network.

Active threat sources Shows how different threat sources are active to understand and calibrate threat intel enhancements.

ES THREAT INTELLIGENCE FRAMEWORK

Splunk Inc. 2016 © - Page 14

Page 15: Partner Solutions: Splunk - Cloud Is a Journey. Make Splunk Your Partner

SecurityIntelligenceUseCases

SECURITY&COMPLIANCEREPORTING

REAL-TIMEMONITORINGOFKNOWNTHREATS

DETECTINGUNKNOWNTHREATS

INCIDENTINVESTIGATIONS&FORENSICS

FRAUDDETECTION

INSIDERTHREAT

ComprehensiveSecurityIntelligencePla]orm15

Page 16: Partner Solutions: Splunk - Cloud Is a Journey. Make Splunk Your Partner

PlaeormforOperaWonalIntelligence

Applica<onPerformance&SLAs

RichEcosystemofApps&Add-Ons

MainframeData

RelaWonalDatabasesMobileForwarders Syslog/TCP IoT

DevicesNetworkWireData

Hadoop

SplunkAppforAWSSplunkEnterpriseSecurity

SplunkITServiceIntelligence

SplunkPremiumSolu<ons

Page 17: Partner Solutions: Splunk - Cloud Is a Journey. Make Splunk Your Partner

EndtoEndServiceMonitoringisRequiredforCloud

17

Component-levelHealthwithoutServiceContext(“BigPicture”)

The”BigPictures”withoutCorrela<ontoComponent-leveldetails

Page 18: Partner Solutions: Splunk - Cloud Is a Journey. Make Splunk Your Partner

SplunkITServiceIntelligenceData-drivenservicemonitoringandanaly<cs

18

SPLUNKITSERVICEINTELLIGENCE

Time-SeriesIndex

PlaeormforMachineData

DynamicServiceModels

Schema-on-Read DataModel CommonInforma<onModel

At-a-GlanceProblemAnalysis

EarlyWarningonDeviaWons

SimplifiedIncidentWorkflows

Page 19: Partner Solutions: Splunk - Cloud Is a Journey. Make Splunk Your Partner

AchieveServiceVisibilityFasterServiceAnalyzerHigh-levelviewofservicesandcompositehealthscores

GlassTablesPersonalizedvisualizaWonsofyourservices

DeepDivesOrganizedviewofperformanceindicatorsacrosssilos

Mul<KPIAlertsCorrelaWonrulestogeneratenotableevents

NotableEventsEasy-to-understandreportonresultsofcorrelaWonsearches

AnomalyDetec<onandAdap<veThresholdsMachinelearningtobaselinenormaloperaWonsandidenWfyanomalousbehavior

19

Page 20: Partner Solutions: Splunk - Cloud Is a Journey. Make Splunk Your Partner

DataCentricApproach

  Hard-codedcreatesfalseposiWve(ForExample:>85%CPUUWlizaWon=NotNormalalways)

  Collect,ingesthistoricalandcurrentdatatolearntheNormalofyourbusiness

20

Page 21: Partner Solutions: Splunk - Cloud Is a Journey. Make Splunk Your Partner
Page 22: Partner Solutions: Splunk - Cloud Is a Journey. Make Splunk Your Partner
Page 23: Partner Solutions: Splunk - Cloud Is a Journey. Make Splunk Your Partner
Page 24: Partner Solutions: Splunk - Cloud Is a Journey. Make Splunk Your Partner

PlaeormforOperaWonalIntelligence

Opera<onalVisibility

RichEcosystemofApps&Add-Ons

MainframeData

RelaWonalDatabasesMobileForwarders Syslog/TCP IoT

DevicesNetworkWireData

Hadoop

SplunkAppforAWSSplunkEnterpriseSecurity

SplunkITServiceIntelligence

SplunkPremiumSolu<ons

Page 25: Partner Solutions: Splunk - Cloud Is a Journey. Make Splunk Your Partner

25

SplunkAppforAWSEC2

EMR

Kinesis

R53

VPC

ELB

S3

CloudFront

CloudTrail

CloudWatch

Redshift SNS

API Gateway

Config

RDS

CF

IAM

Lambda

Explore Analyze Dashboard Alert Act

AWSDataSources

ComprehensiveAWSVisibility

Page 26: Partner Solutions: Splunk - Cloud Is a Journey. Make Splunk Your Partner

SplunkAppforAWS:TheData

26

•  AWSCloudtrail–  ServicethatdeliverslogsofadminacWvityonAWS

infrastructure–  Examples:

ê  Start/Stop/Createinstanceê  ChangeofUserroles/rightsê  ModificaWonofNetworkConfiguraWon

–  Deliverslogfilestocustomers;noUI,display,analysis,search

•  AWSConfig–  Providesresourceinventory–  ProvidesconfiguraWonhistory&changeinformaWon–  Enablessecurity&governance

•  AmazonCloudwatchMetrics–  IPtrafficinformaWonto/fromVPCnetworkinterfaces–  DatastoredandaccessiblefromAWSCloudwatchLogs

•  AmazonCloudwatchVPCFlowLogs–  IPtrafficinformaWonto/fromVPCnetwork

interfaces–  DatastoredandaccessiblefromAWSCloudwatch

Logs•  AWSAccessLogs

–  ElasWcLoadBalancing(ELB)–  CloudfrontCDN–  S3

•  AWSBilling–  CurrentMonthviaCloudwatchmetrics–  MonthlyDetailedBilling

Page 27: Partner Solutions: Splunk - Cloud Is a Journey. Make Splunk Your Partner

SplunkAppforAWS:TheValue

27

•  IncreasevisibilityintoAWSresourceuWlizaWon&useracWvity•  Ensureadherencetosecurityandcompliancestandardswithafullaudittrail•  UnderstandAWSenvironmentaldependenciesthroughtopologyviews

•  MonitorVPCtrafficu<liza<onforaddiWonalsecurityinsights•  CostOp<miza<onthroughMonthlyandDetailedBillingDashboards

Page 28: Partner Solutions: Splunk - Cloud Is a Journey. Make Splunk Your Partner

SplunkAppforAWSDemo

Page 29: Partner Solutions: Splunk - Cloud Is a Journey. Make Splunk Your Partner