Network Forensics
for Splunkers
Matt Walmsley, EMEA Marketing
Tom Jones, Sales Engineer
Emulex, Endace Division
Today’s Topics

Time to
Resolution
Splunk
Connector
2

Network
Recording

Q&A

Emulex Confidential - © 2013 Emulex Corpora...
The Networking Wheel of Life!

APM
NPM
IPS / IDS

Firewall
WAN Op
QoS

3

Recording &
Forensics

Analysis &
Intervention

...
# Events

Time is… Money / Safety / Advantage / Reputation

• Reduce Slow To Fix Items
• Identify Root Cause & Fix

Saving...
The 3 E of Great Interventions

Skills & Knowledge

Experience & Context

Evidence

Understanding

• Efficient
• Economic
...
Collecting Evidence - Recording Evolution

Interesting Vs. Important

6

Specialised Vs. Generalised

Emulex Confidential ...
Intelligent Network Recording

Generalised
Enterprise
Banking &
Trading

National
Security

Specialised
7

Emulex Confiden...
Endace – The Packet Capture Experts

World leader in network
recording
10+ years selling security
solutions to global clie...
Intelligent Network Recording - Use Cases
Application
Performance
Management

Custom

Security
Operations

Legal
Intercept...
Intelligent Network Recording - Deployment

Intelligent Network Recorder “Probe”

Network Traffic Analysis App

• High Spe...
Endace Network Recording - Infrastructure

EndaceProbe™
INR

EndaceAccess™

Endace Open
Hosting Platform(ODE)

High Perfor...
How Much Network Visibility Do You Need?

High Definition – Endace Vision
•

See microbursts

•

Know exactly what data
ha...
EndaceVision - Actionable Insight

Bandwidth Over
Time

TCP/IP
Conversations

Traffic over time

13

Traffic breakdown
and...
EndaceVision - Integrated and Open

APM

NPM

IDS

HFT

EndaceFusion
EndaceProbe

Integration with “best of breed” solutio...
Endace Solution - Key Features
• Market Leading Performance
• 100% High fidelity packet capture
• 10/100/1G/10G/40G/100GbE...
Splunk & Endace – Macro and Micro

Log lines are a summary or
interpretation of an event
Packets are the ground truth
from...
Feeding and Enabling Splunk

EndaceProbe
INR Generated
Logs and Netflow
Events

17

Splunk Generated
Enquiries

Emulex Con...
Optimising Event Management Workflow

Event Occurrence

18

Splunk Alert

Click to Traffic
Search
Request

Emulex Confiden...
Example Case – Finance / Trading Solution

Context
• Network performance is critical to
$ services
• Latency and outage in...
Real World Feedback

“While consolidating network monitoring and security tools was the primary
need for the EndaceProbe I...
Endace Helps You Enable the “3 E”
Understand
macro and
micro
situation

Reduce Time
to Resolution

Efficient
Economic
Effe...
Which Means You Get…

Less stress, improved results
Uninterrupted weekends and
evenings
Happy family, boss and
stakeholder...
Resources & Info

www.emulex.com

Video

23

Solution Brief

Blog

www.marquest.com

Emulex Confidential - © 2013 Emulex C...
Questions?
Thank you for your attention
25

Emulex Confidential - © 2013 Emulex Corporation
Upcoming SlideShare
Loading in …5
×

Network Forensics for Splunk, an Emulex presentation

1,707 views

Published on

These slides were recently presented at a partner event held by Marquest Ltd.

Published in: Technology
0 Comments
0 Likes
Statistics
Notes
  • Be the first to comment

  • Be the first to like this

No Downloads
Views
Total views
1,707
On SlideShare
0
From Embeds
0
Number of Embeds
13
Actions
Shares
0
Downloads
45
Comments
0
Likes
0
Embeds 0
No embeds

No notes for slide
  • The Endace product line consists of three hardware products (EndaceProbe INR, Endace NGA, EndaceODE) that provide network traffic capture capabilities. The EndaceAccess product allows for recording of 40GbE and 100GbE network traffic by breaking up the network stream across multiple INRs. EndaceVision is a software tool that provides visibility and visualization of network traffic that has been captured and recorded by the Endace hardware products. These products are powered by our Endace DAG card technology, which we also sell to large government and telecom customers.We also integrate with a variety of tools. These include:EndaceProbe Intelligent Packet Recorder: Integrates through RESTful API with Splunk and Compuware today.Endace Netflow Generator Appliance (NGA): Integrates with SevOne and Arbor Networks NetOps analysis tools, and with Lancope security analysis tool.Roughly 20% of the Endace product line’s overall revenue comes from DAG card sales. These sales are generally to large government security agencies and to telecom carriers. Of the non-DAG card revenue, the vast bulk of it (~70%) comes from the EndaceProbe INR. The Endace NGA is a new product that represented 10% of our total revenue last quarter, which we expect to grow over time.
  • Complete and accurate network visibility is critical to today’s enterprises. This chart (from the EndaceVision tool) graphically demonstrates the difference in visibility between low-res (sampling) network recorders and high-res (100% capture) network recorders from Emulex. Here you can see that the low-res tool did not provide the user with visibility into microbursts that were occurring that were at or near full network bandwidth. Without that visibility, it would be impossible to identify which applications and/or users were causing these microbursts, which could adversely impact the performance of critical applications.
  • One of the biggest differentiators for our visualization tools comes from our partnership with a variety of best-in-breed network packet broker (NPB), Network Performance Management (NPM), Application Performance Management (APM), and Security Event Management (SEM) tool vendors. We have names these partnerships the Endace Fusion Alliance. The Endace Fusion Alliance enables customers to build NPM/APM/SEM suites that meet their exact needs, and is in contrast to integrated tools, which force customers to buy tools that they may or may not need. The benefit to customers of this best-in-breed approach is lower CapEx (less tools and recording hardware to buy) and lower OpEx (less training, quicker time to resolution of network issues). This also provides channel partners with additional opportunities to integrate custom suites of tools together for customers, increasing their “share of wallet”.
  • So what does all this mean?It means that you get to make quicker decisions about how to respond to events, and to have confidence in those decisions.You get to deal with those annoying recurring events.You save your company loads of money by reducing the area under the curve and you get to be a hero.
  • Network Forensics for Splunk, an Emulex presentation

    1. 1. Network Forensics for Splunkers Matt Walmsley, EMEA Marketing Tom Jones, Sales Engineer Emulex, Endace Division
    2. 2. Today’s Topics Time to Resolution Splunk Connector 2 Network Recording Q&A Emulex Confidential - © 2013 Emulex Corporation
    3. 3. The Networking Wheel of Life! APM NPM IPS / IDS Firewall WAN Op QoS 3 Recording & Forensics Analysis & Intervention Emulex Confidential - © 2013 Emulex Corporation
    4. 4. # Events Time is… Money / Safety / Advantage / Reputation • Reduce Slow To Fix Items • Identify Root Cause & Fix Savings Time to Resolution
    5. 5. The 3 E of Great Interventions Skills & Knowledge Experience & Context Evidence Understanding • Efficient • Economic • Effective Decision Making Intervention 5 Emulex Confidential - © 2013 Emulex Corporation
    6. 6. Collecting Evidence - Recording Evolution Interesting Vs. Important 6 Specialised Vs. Generalised Emulex Confidential - © 2013 Emulex Corporation
    7. 7. Intelligent Network Recording Generalised Enterprise Banking & Trading National Security Specialised 7 Emulex Confidential - © 2013 Emulex Corporation
    8. 8. Endace – The Packet Capture Experts World leader in network recording 10+ years selling security solutions to global clients – Govt, Traders, Telco & Enterprise Reputation for accuracy, scalability & performance A division of Emulex 8 Emulex Confidential - © 2013 Emulex Corporation
    9. 9. Intelligent Network Recording - Use Cases Application Performance Management Custom Security Operations Legal Intercept Network Infrastructure Operations Audit & Compliance 9 Emulex Confidential - © 2013 Emulex Corporation
    10. 10. Intelligent Network Recording - Deployment Intelligent Network Recorder “Probe” Network Traffic Analysis App • High Speed, High Fidelity Packet Capture Appliance • Packet Processing and Indexing • Storage and Retrieval • Traffic Profiling & Visualisation • Packet Analysis • Integration with other networking tools 10 Emulex Confidential - © 2013 Emulex Corporation
    11. 11. Endace Network Recording - Infrastructure EndaceProbe™ INR EndaceAccess™ Endace Open Hosting Platform(ODE) High Performance Intelligent Network Recording Network Visibility Headend Hosting Platform for Monitoring Apps Up to 64 TB storage Mix of 1 and 10GbE ports Allows EndaceProbe INRs/ODE to scale to 40 and 100GbE 8x1GbE or 4x10GbE Ports Up to 16 TB internal storage; FC support for SAN 11 Emulex Confidential - © 2013 Emulex Corporation Endace NetFlow Generator High-Speed NetFlow Generation for 10GbE Networks 4x10GbE Ports
    12. 12. How Much Network Visibility Do You Need? High Definition – Endace Vision • See microbursts • Know exactly what data has been compromised • Identify issues impacting services and security application performance Low Definition • 12 Emulex Confidential - © 2013 Emulex Corporation The visibility most solutions provide
    13. 13. EndaceVision - Actionable Insight Bandwidth Over Time TCP/IP Conversations Traffic over time 13 Traffic breakdown and analysis Top Talkers Workflow Emulex Confidential - © 2013 Emulex Corporation
    14. 14. EndaceVision - Integrated and Open APM NPM IDS HFT EndaceFusion EndaceProbe Integration with “best of breed” solutions – API and hypervisor – All tools share data from same secure location in datacenter – Automated workflow, “pivot to packets” speeds up issue resolution Lower Investment While Increasing ROI – Reduce device count – Plan and train staff on the tools that fit customer situation best 14 Emulex Confidential - © 2013 Emulex Corporation
    15. 15. Endace Solution - Key Features • Market Leading Performance • 100% High fidelity packet capture • 10/100/1G/10G/40G/100GbE • 64TB on board storage • FC SAN offload • Multi-unit “Sledging” • Distributed Recording Fabric • Multiple EndaceProbe INRs, single recording fabric • Traffic search and visualisation • Diverse, concurrent multiple uses • Open and Flexible Integration • Endace dock hypervisor • RESTfull API • Endace Fusion solution ecosystem 15 Emulex Confidential - © 2013 Emulex Corporation
    16. 16. Splunk & Endace – Macro and Micro Log lines are a summary or interpretation of an event Packets are the ground truth from which these are derived Fusion connector links the two with a single click Endace’s depth complements Splunk’s breadth 16 Emulex Confidential - © 2013 Emulex Corporation
    17. 17. Feeding and Enabling Splunk EndaceProbe INR Generated Logs and Netflow Events 17 Splunk Generated Enquiries Emulex Confidential - © 2013 Emulex Corporation
    18. 18. Optimising Event Management Workflow Event Occurrence 18 Splunk Alert Click to Traffic Search Request Emulex Confidential - © 2013 Emulex Corporation Packet drill down and inspection Traffic Analysis and Visualisation
    19. 19. Example Case – Finance / Trading Solution Context • Network performance is critical to $ services • Latency and outage intolerant • Multiple management tools Solution • Integrated network monitoring and security for a low latency 10GbE network Products • Splunk! • EndaceProbe™ INR • Endace Fusion Connector for Splunk • EndaceVision™ 19 Key Benefits • Greater insight into critical network issues • Reduce time-to-resolution (TTR) • Lower operational expenditures (OPEX) Emulex Confidential - © 2013 Emulex Corporation
    20. 20. Real World Feedback “While consolidating network monitoring and security tools was the primary need for the EndaceProbe INR, it was put to work even before the official deployment. the pilot and immediately discovered a security breach that had gone undetected with their existing tools, providing an immediate return on investment for the EndaceProbe INR 7000.” “The EndaceProbe INR has been 100% reliable for us and we are impressed with its robust capabilities. We use it extensively and, coupled with the Fusion Connector for Splunk, are extremely happy with the results.” Global Head of Networks 20 Emulex Confidential - © 2013 Emulex Corporation
    21. 21. Endace Helps You Enable the “3 E” Understand macro and micro situation Reduce Time to Resolution Efficient Economic Effective Stop Recurrent Events 21 Reduce slow / hard to fix items Fix Route Cause Emulex Confidential - © 2013 Emulex Corporation
    22. 22. Which Means You Get… Less stress, improved results Uninterrupted weekends and evenings Happy family, boss and stakeholders 22 Emulex Confidential - © 2013 Emulex Corporation
    23. 23. Resources & Info www.emulex.com Video 23 Solution Brief Blog www.marquest.com Emulex Confidential - © 2013 Emulex Corporation Splunk Connector App Testing Brief
    24. 24. Questions? Thank you for your attention
    25. 25. 25 Emulex Confidential - © 2013 Emulex Corporation

    ×