• Save
SplunkLive! Customer Presentation - Hurricane Labs
 

Like this? Share it with your network

Share

SplunkLive! Customer Presentation - Hurricane Labs

on

  • 999 views

 

Statistics

Views

Total Views
999
Views on SlideShare
987
Embed Views
12

Actions

Likes
0
Downloads
0
Comments
0

1 Embed 12

https://twitter.com 12

Accessibility

Categories

Upload Details

Uploaded via as Adobe PDF

Usage Rights

© All Rights Reserved

Report content

Flagged as inappropriate Flag as inappropriate
Flag as inappropriate

Select your reason for flagging this presentation as inappropriate.

Cancel
  • Full Name Full Name Comment goes here.
    Are you sure you want to
    Your message goes here
    Processing…
Post Comment
Edit your comment

SplunkLive! Customer Presentation - Hurricane Labs Presentation Transcript

  • 1. Director of Security ServicesHurricane LabsManaged Security ProviderCleveland, OHAvid Cleveland sports cynic•••Matt Yonchak
  • 2. What Hurricane Labs DoesSecurity Monitoring andAnalysisPerformance MonitoringVulnerability ManagementSplunk MSSP••••
  • 3. Security Monitoring and Analysis
  • 4. Typical Security DataIPSProxyFirewallWAF••••
  • 5. Non-Typical Data(but still relevant to security)Web Application DataVoice andCommunicationEmailPerformance MonitoringID ManagementExternal Data Sources••••••
  • 6. PerformanceMonitoringComprised of different areas:System Resources Up / Down Monitoring System Processes Bandwidth Utilization
  • 7. Performance monitoring
  • 8. Vulnerability ManagementPenetration testingand lots of it
  • 9. More frequent = more data.Clients given a scoreSplunk pulls in pen test data.•••Vulnerability Management
  • 10. Hurricane LabsBig Data Problem
  • 11. Our Big DataProblemStatistics onHL big data
  • 12. IcingaCactiPentest resultsTicketsChangelogsIDS/IPS eventsHIDSVulnerabilityScannersPort ScannersEvent LogsSyslogsFirewall eventsAudit eventsPCI eventsWhat Goes Into the HDportal Splunk Instance?(Its ALOT)
  • 13. How we filter down so many eventsto provide security intelligence:Making 246 Million EventsWork For YouProper tuning(not just turning stuff off)
  • 14. Gives a broader security pictureCorrelation across clientsWarn of industry attack trends•••Capabilities that SplunkProvides to the HD Services
  • 15. Capabilities that SplunkProvides to the HD PortalFlexible Reporting Searchable Log Data Correlation
  • 16. Digital interface withour clientsHow we showtransparencyAllows our clients tointeract with their bigdataA way to see theservice side vs. thetechnical side••••Hurricane Defense Portal
  • 17. What makes the HD portal tick?
  • 18. Why the SplunkSDK Is So Great"Makes things more Pythonic" – yes thats a quoteAllows for faster development times and faster versionreleases of the portalHelped us to develop a custom UI••
  • 19. Splunk DrivenDashboard Data Reports Monitoring Trends
  • 20. Splunk Helped TameOur Big Data
  • 21. In Closing
  • 22. Questions?Contact Me:Call @ 888-276-4106 x106E-mail @ matt@hurricanelabs.comThank you for your time!