SlideShare a Scribd company logo
1 of 34
Download to read offline
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
“Cloud First” Helps Hub Intl Grow the
Business with Splunk on AWS
Seth Morrell
Vice President,
Enterprise Architecture
and Design
HUB International
A N T 3 3 0 - S
Jeremy Embalabala
Director, Security
Architecture &
Engineering
HUB International
Jae Lee
Director Product
Marketing, Security
Splunk
“Our partnership with Splunk is
incredibly important for our
customers. Customers love AWS agility
with Splunk visibility.”
Andy Jassy, CEO
Amazon Web Services
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
One consolidated solutionManage hybrid
infrastructure
Cost, capacity, and resource
management
Cloud migration
Splunk takes the place of the
multitude of monitoring tools
because sometimes one is
better than many.
Hybrid infrastructure creates
a complex monitoring
environment. Legacy tools
can't keep up. Splunk can.
Understand how your
resources are performing –
and how many are being
used – then optimize
utilization and billing.
Get visibility at all stages of
the migration process –
whether before, during, or
long after.
End state: Comprehensive AWS visibility
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Splunk and AWS
Custom
dashboards
Report and
analyze
Monitor
and alert
Developer
Platform
Ad hoc
search
Real-time
machine data
References – Coded fields, mappings, aliases
Dynamic information – Stored in non-traditional formats
Environmental context – Human-maintained files, documents
System/application – Available only using application request
Intelligence/analytics – Indicators, anomaly, research, white/blacklist
On-premises
Private cloud
Public cloud
Storage
Online
shopping cart
Telecoms
Desktops
Security
Web
Services
Networks
Containers
Web
clickstreams
RFID
Smartphones
and devices
Servers
Messaging
GPS
location
Packaged
applications
Custom
applications
Online
services
DatabasesCall detail
records
AWS
CloudTrail
AWS Config
Index untapped data: Any source, type, volume
Amazon EC2
AWS Lambda
AWS app & add-on
Amazon GuardDuty
Amazon Kinesis
Data
Firehose
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
End state: Comprehensive AWS visibility
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
 Sudden change in the number of security group rules?
 Sudden change in the number of ACL modifications?
 Spike in error activity caused by unauthorized actions?
 Are there any publicly accessible Amazon Simple Storage Service
(Amazon S3) buckets?
 Any provisioning activity from an unusual country?
 API calls from users who have not made API calls before?
 First time a user provisioned an instance / account / other?
Examples: Basic posture methods
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
 Who added that rule in the security group that protects our
application servers?
 Where is the blocked traffic into that VPC coming from?
 What was the activity trail of a particular user before and after
an incident?
 Alert me when a user imports key-pairs or when a security
group allows all ports
 What instances are provisioned outside of a VPC, by whom,
and when?
 What security groups are defined but not attached to
any resource?
Example investigative methods
Splunk App for AWS
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Seth Morrell
Vice President, Enterprise Architecture and Design
Jeremy Embalabala
Director, Security Architecture and Engineering
• Currently lead the information security, governance, and risk
management programs at HUB
• Previously the CISO of Beam Suntory
• Specialize in building cloud-first security programs tightly
aligned with business risks and goals
• Currently am married and live in Woodstock, IL, and enjoy
sustainable farming and fishing
• Responsible for security architecture and engineering at HUB
• Background in information security, Insuretech, and deep
learning
• AWS Certified Solutions Architect
• Global Information Security certification – GSEC, GCED
Who are we?
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
SCOPE & SCALE FOOTPRINT
National HUB 2017
15%
27%
2%
51%
5%
Commercial Lines
Employee Benefits
Personal Lines
Wholesale
Other
Total Revenue: $2 Billion+
OWNERSHIP
Hellman & Friedman: Our Private Equity Partner
o Partners since October 2013
o One of the most experienced and successful investment
organizations in the private equity industry
o Strong track record for investors in H&F’s portfolio companies
o Extensive investment experience in the insurance industry and
related verticals
25%
Principals
& Employees
75%
H&F and Co-investors
400+
locations in
North America
Top 5
Global Broker
based on
revenue
11,000+
employees
1 million+
clients
92%
client
retention
$17 billion+
in premium
Who is HUB?
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
What was the Initiative?
HUB International working
on slide or two
Hub team to create content
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
A best-in-class technology
strategy with a cloud-first
mandate
Ability to detect and
remediate next-
generation threats quickly
before breach or impact
Drive revenue and organic
growth through M&A,
process optimization, and
digital transformation
Building security according
to best practices, which
allows HUB to stay ahead of
future regulations
Leverage data analytics to
make faster and more
accurate business decisions
Optimizing process and
change management across
our organization
HUB transformation goals
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Rapid program development
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Sept Oct Nov Dec Jan 2018 Feb Mar Apr May June July
Network Transition
Office 365 Migration
Information Security Rollout
AugAug
CRM Cloud
Data Analytics Buildout
Cloud End User Computing
Risk Management Project
2016 SharePoint Migration
Cloud Migration
Transformation roadmap
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
The immediate challenge – Secure migration
• Controlling AWS costs
• Track AWS infrastructure and service usage
• Capacity planning
• Security of applications and infrastructure across hybrid
environments
• Organizations with multiple accounts
• Services and infrastructure deployed in many AWS Regions and
Availability Zones
• Data taking on many different formats
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
○ Extremely flexible architecture and cost structure
○ Ability to log and report on both security and
cloud health
○ Ability to grow with our business, security, and
cloud needs
○ Great network of support and knowledge
○ Strong app integrations
○ Ability to host existing system and provide
options to “fail fast”
○ Exceptional service options and availability
○ Ability to leverage security capability that was
previously unavailable to HUB
○ Enhance HUB’s disaster recovery and backup
strategy
Cost-effective, agile dev environmentSecure cloud migration
Why we chose Splunk and AWS
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Security use cases
• Security Operation Center (SOC)
• One of the cornerstones of our InfoSec program
• Partnered with an MSSP to build and manage
• Partner brings agility and high-level experience
• Splunk Enterprise Security for SIEM
• Security priority
• Also offers benefits to our IT operations, applications, and engineering teams
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Splunk design
MSSP Account
HUB Datacenter
HUB Account(s)
AWS Direct
Connect
VPN
connection
VPN
connection
VPN
connection
Data Sources
Search Head
Data SourcesIndexers
Forwarders
Forwarders
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Amazon
EC2
Flow logs
Amazon
S3
Amazon
CloudWatch
AWS
Config
AWS
CloudTrailIAM
Amazon Kinesis
Amazon
SQS
Amazon
SNS
Amazon
VPC
Amazon elastic
load balancers
Source Capture Delivery Consumption
AWS API
Splunk Indices
AWS integration
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Threat
Hunting
Analysis
Correlation
Complexity
Investment
Efficacy
Adapted from Yuval Sinay’s Cybersecurity Monitoring Maturity Model
Threat detection
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Why Amazon Kinesis Data Firehose?
• Data sources
• Change logs
• Log-in activity
• Storage logs
• Performance telemetry
• Network activity
Amazon VPC
Flow Logs
Queue-based messaging
• Not necessarily ordered
• Low read/write frequency limits
Real-time data stream
• Ordered messages
• Message receipt acknowledgement
• Re-playable messages
• High read/write frequency limits
Flow Data Index Correlation Alerting
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Threat intelligence integration
Threat bulletins
Indicators of compromise
Import into Splunk
High-confidence incidents
• Command & control
• Malware traffic
• Anonymizers & proxies
• Tor traffic
• Vulnerability context
• Threat actor attribution
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Dashboards
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
VPC Flow Logs
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
App search and reporting
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Dashboards
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Lessons learned
• Use IAM roles instead of AWS access keys
• Large volume of VPC flow data
• Make sure your indexers have enough horsepower
• Understand the licensing cost
• Invest in third-party threat intelligence feeds and integrate with Splunk
• Use the Splunk App for AWS to identify misconfigurations in the environment
and for greater insights into billing
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Roadmap – Leveraging AWS and Splunk
• SOC automation
• Proactive threat hunting
• Microservices, containers, & transient workloads
• Amazon Macie data classification for M&A data transfers
• Enterprise monitoring
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
© 2017 SPLUNK INC.
1. Splunk and AWS partner across data
ingestion, cloud migration, and AWS
best practices to ensure joint customer
success
2. Get deep visibility into AWS – Security,
operations, and cost management with
the Splunk App for AWS
3. Monitor your on-premises to AWS
migrations and help ensure your AWS
environment is well-architected with
Splunk
To get end-to-end
visibility with Splunk +
AWS
Key takeaways
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
© 2017 SPLUNK INC.
1. Drop by booth #2816 – Grab a Splunk
T-shirt and participate in a demo
2. Start your free trial of Splunk solutions
on AWS Marketplace today!
Thank you!
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.

More Related Content

What's hot

Implementing Multi-Region AWS IoT, ft. Analog Devices (IOT401) - AWS re:Inven...
Implementing Multi-Region AWS IoT, ft. Analog Devices (IOT401) - AWS re:Inven...Implementing Multi-Region AWS IoT, ft. Analog Devices (IOT401) - AWS re:Inven...
Implementing Multi-Region AWS IoT, ft. Analog Devices (IOT401) - AWS re:Inven...Amazon Web Services
 
Designing for Operability: Getting the Last Nines in Five-Nines Availability ...
Designing for Operability: Getting the Last Nines in Five-Nines Availability ...Designing for Operability: Getting the Last Nines in Five-Nines Availability ...
Designing for Operability: Getting the Last Nines in Five-Nines Availability ...Amazon Web Services
 
DevOps Concepts for Data Science (DEV347-R2) - AWS re:Invent 2018
DevOps Concepts for Data Science (DEV347-R2) - AWS re:Invent 2018DevOps Concepts for Data Science (DEV347-R2) - AWS re:Invent 2018
DevOps Concepts for Data Science (DEV347-R2) - AWS re:Invent 2018Amazon Web Services
 
Pause and Resume your EC2 Instances with Hibernate (CMP392) - AWS re:Invent 2018
Pause and Resume your EC2 Instances with Hibernate (CMP392) - AWS re:Invent 2018Pause and Resume your EC2 Instances with Hibernate (CMP392) - AWS re:Invent 2018
Pause and Resume your EC2 Instances with Hibernate (CMP392) - AWS re:Invent 2018Amazon Web Services
 
Operationalizing Microsoft Workloads (WIN320) - AWS re:Invent 2018
Operationalizing Microsoft Workloads (WIN320) - AWS re:Invent 2018Operationalizing Microsoft Workloads (WIN320) - AWS re:Invent 2018
Operationalizing Microsoft Workloads (WIN320) - AWS re:Invent 2018Amazon Web Services
 
How Avatars & AR Are Driving Innovation: Lessons from Electronic Caregiver (A...
How Avatars & AR Are Driving Innovation: Lessons from Electronic Caregiver (A...How Avatars & AR Are Driving Innovation: Lessons from Electronic Caregiver (A...
How Avatars & AR Are Driving Innovation: Lessons from Electronic Caregiver (A...Amazon Web Services
 
Operations for Containerized Applications (CON334-R1) - AWS re:Invent 2018
Operations for Containerized Applications (CON334-R1) - AWS re:Invent 2018Operations for Containerized Applications (CON334-R1) - AWS re:Invent 2018
Operations for Containerized Applications (CON334-R1) - AWS re:Invent 2018Amazon Web Services
 
The New Normal for Mission-Critical SAP Workloads (ENT219-R1) - AWS re:Invent...
The New Normal for Mission-Critical SAP Workloads (ENT219-R1) - AWS re:Invent...The New Normal for Mission-Critical SAP Workloads (ENT219-R1) - AWS re:Invent...
The New Normal for Mission-Critical SAP Workloads (ENT219-R1) - AWS re:Invent...Amazon Web Services
 
How Amazon.com Migrates Inventory Management Systems (DAT346) - AWS re:Invent...
How Amazon.com Migrates Inventory Management Systems (DAT346) - AWS re:Invent...How Amazon.com Migrates Inventory Management Systems (DAT346) - AWS re:Invent...
How Amazon.com Migrates Inventory Management Systems (DAT346) - AWS re:Invent...Amazon Web Services
 
Automate Your Alexa Lambda Function Deployment Workflows Using AWS CodeCommit...
Automate Your Alexa Lambda Function Deployment Workflows Using AWS CodeCommit...Automate Your Alexa Lambda Function Deployment Workflows Using AWS CodeCommit...
Automate Your Alexa Lambda Function Deployment Workflows Using AWS CodeCommit...Amazon Web Services
 
[NEW LAUNCH!] Introducing AWS App Mesh – service mesh on AWS (CON367) - AWS r...
[NEW LAUNCH!] Introducing AWS App Mesh – service mesh on AWS (CON367) - AWS r...[NEW LAUNCH!] Introducing AWS App Mesh – service mesh on AWS (CON367) - AWS r...
[NEW LAUNCH!] Introducing AWS App Mesh – service mesh on AWS (CON367) - AWS r...Amazon Web Services
 
Deploy Serverless Apps with Python: AWS Chalice Deep Dive (DEV427-R2) - AWS r...
Deploy Serverless Apps with Python: AWS Chalice Deep Dive (DEV427-R2) - AWS r...Deploy Serverless Apps with Python: AWS Chalice Deep Dive (DEV427-R2) - AWS r...
Deploy Serverless Apps with Python: AWS Chalice Deep Dive (DEV427-R2) - AWS r...Amazon Web Services
 
Running Enterprise Test/Dev on Amazon EC2 Spot Instances (CMP407-R1) - AWS re...
Running Enterprise Test/Dev on Amazon EC2 Spot Instances (CMP407-R1) - AWS re...Running Enterprise Test/Dev on Amazon EC2 Spot Instances (CMP407-R1) - AWS re...
Running Enterprise Test/Dev on Amazon EC2 Spot Instances (CMP407-R1) - AWS re...Amazon Web Services
 
MySQL High Availability & Disaster Recovery (DAT361) - AWS re:Invent 2018
MySQL High Availability & Disaster Recovery (DAT361) - AWS re:Invent 2018MySQL High Availability & Disaster Recovery (DAT361) - AWS re:Invent 2018
MySQL High Availability & Disaster Recovery (DAT361) - AWS re:Invent 2018Amazon Web Services
 
Manage Queries, and Audit Usage & Control Costs at Scale on Amazon Athena (AN...
Manage Queries, and Audit Usage & Control Costs at Scale on Amazon Athena (AN...Manage Queries, and Audit Usage & Control Costs at Scale on Amazon Athena (AN...
Manage Queries, and Audit Usage & Control Costs at Scale on Amazon Athena (AN...Amazon Web Services
 
Customizing Data Lakes to Work for Your Enterprise with Sysco (STG340) - AWS ...
Customizing Data Lakes to Work for Your Enterprise with Sysco (STG340) - AWS ...Customizing Data Lakes to Work for Your Enterprise with Sysco (STG340) - AWS ...
Customizing Data Lakes to Work for Your Enterprise with Sysco (STG340) - AWS ...Amazon Web Services
 
Move Data to AWS Faster for Migrations, DR, & Bidirectional Workflows (STG382...
Move Data to AWS Faster for Migrations, DR, & Bidirectional Workflows (STG382...Move Data to AWS Faster for Migrations, DR, & Bidirectional Workflows (STG382...
Move Data to AWS Faster for Migrations, DR, & Bidirectional Workflows (STG382...Amazon Web Services
 
Continuous Integration Best Practices (DEV319-R1) - AWS re:Invent 2018
Continuous Integration Best Practices (DEV319-R1) - AWS re:Invent 2018Continuous Integration Best Practices (DEV319-R1) - AWS re:Invent 2018
Continuous Integration Best Practices (DEV319-R1) - AWS re:Invent 2018Amazon Web Services
 
How Cox Automotive Runs GitHub Enterprise on AWS (ENT356-S) - AWS re:Invent 2018
How Cox Automotive Runs GitHub Enterprise on AWS (ENT356-S) - AWS re:Invent 2018How Cox Automotive Runs GitHub Enterprise on AWS (ENT356-S) - AWS re:Invent 2018
How Cox Automotive Runs GitHub Enterprise on AWS (ENT356-S) - AWS re:Invent 2018Amazon Web Services
 
Shift-Left SRE: Self-Healing with AWS Lambda Functions (DEV313-S) - AWS re:In...
Shift-Left SRE: Self-Healing with AWS Lambda Functions (DEV313-S) - AWS re:In...Shift-Left SRE: Self-Healing with AWS Lambda Functions (DEV313-S) - AWS re:In...
Shift-Left SRE: Self-Healing with AWS Lambda Functions (DEV313-S) - AWS re:In...Amazon Web Services
 

What's hot (20)

Implementing Multi-Region AWS IoT, ft. Analog Devices (IOT401) - AWS re:Inven...
Implementing Multi-Region AWS IoT, ft. Analog Devices (IOT401) - AWS re:Inven...Implementing Multi-Region AWS IoT, ft. Analog Devices (IOT401) - AWS re:Inven...
Implementing Multi-Region AWS IoT, ft. Analog Devices (IOT401) - AWS re:Inven...
 
Designing for Operability: Getting the Last Nines in Five-Nines Availability ...
Designing for Operability: Getting the Last Nines in Five-Nines Availability ...Designing for Operability: Getting the Last Nines in Five-Nines Availability ...
Designing for Operability: Getting the Last Nines in Five-Nines Availability ...
 
DevOps Concepts for Data Science (DEV347-R2) - AWS re:Invent 2018
DevOps Concepts for Data Science (DEV347-R2) - AWS re:Invent 2018DevOps Concepts for Data Science (DEV347-R2) - AWS re:Invent 2018
DevOps Concepts for Data Science (DEV347-R2) - AWS re:Invent 2018
 
Pause and Resume your EC2 Instances with Hibernate (CMP392) - AWS re:Invent 2018
Pause and Resume your EC2 Instances with Hibernate (CMP392) - AWS re:Invent 2018Pause and Resume your EC2 Instances with Hibernate (CMP392) - AWS re:Invent 2018
Pause and Resume your EC2 Instances with Hibernate (CMP392) - AWS re:Invent 2018
 
Operationalizing Microsoft Workloads (WIN320) - AWS re:Invent 2018
Operationalizing Microsoft Workloads (WIN320) - AWS re:Invent 2018Operationalizing Microsoft Workloads (WIN320) - AWS re:Invent 2018
Operationalizing Microsoft Workloads (WIN320) - AWS re:Invent 2018
 
How Avatars & AR Are Driving Innovation: Lessons from Electronic Caregiver (A...
How Avatars & AR Are Driving Innovation: Lessons from Electronic Caregiver (A...How Avatars & AR Are Driving Innovation: Lessons from Electronic Caregiver (A...
How Avatars & AR Are Driving Innovation: Lessons from Electronic Caregiver (A...
 
Operations for Containerized Applications (CON334-R1) - AWS re:Invent 2018
Operations for Containerized Applications (CON334-R1) - AWS re:Invent 2018Operations for Containerized Applications (CON334-R1) - AWS re:Invent 2018
Operations for Containerized Applications (CON334-R1) - AWS re:Invent 2018
 
The New Normal for Mission-Critical SAP Workloads (ENT219-R1) - AWS re:Invent...
The New Normal for Mission-Critical SAP Workloads (ENT219-R1) - AWS re:Invent...The New Normal for Mission-Critical SAP Workloads (ENT219-R1) - AWS re:Invent...
The New Normal for Mission-Critical SAP Workloads (ENT219-R1) - AWS re:Invent...
 
How Amazon.com Migrates Inventory Management Systems (DAT346) - AWS re:Invent...
How Amazon.com Migrates Inventory Management Systems (DAT346) - AWS re:Invent...How Amazon.com Migrates Inventory Management Systems (DAT346) - AWS re:Invent...
How Amazon.com Migrates Inventory Management Systems (DAT346) - AWS re:Invent...
 
Automate Your Alexa Lambda Function Deployment Workflows Using AWS CodeCommit...
Automate Your Alexa Lambda Function Deployment Workflows Using AWS CodeCommit...Automate Your Alexa Lambda Function Deployment Workflows Using AWS CodeCommit...
Automate Your Alexa Lambda Function Deployment Workflows Using AWS CodeCommit...
 
[NEW LAUNCH!] Introducing AWS App Mesh – service mesh on AWS (CON367) - AWS r...
[NEW LAUNCH!] Introducing AWS App Mesh – service mesh on AWS (CON367) - AWS r...[NEW LAUNCH!] Introducing AWS App Mesh – service mesh on AWS (CON367) - AWS r...
[NEW LAUNCH!] Introducing AWS App Mesh – service mesh on AWS (CON367) - AWS r...
 
Deploy Serverless Apps with Python: AWS Chalice Deep Dive (DEV427-R2) - AWS r...
Deploy Serverless Apps with Python: AWS Chalice Deep Dive (DEV427-R2) - AWS r...Deploy Serverless Apps with Python: AWS Chalice Deep Dive (DEV427-R2) - AWS r...
Deploy Serverless Apps with Python: AWS Chalice Deep Dive (DEV427-R2) - AWS r...
 
Running Enterprise Test/Dev on Amazon EC2 Spot Instances (CMP407-R1) - AWS re...
Running Enterprise Test/Dev on Amazon EC2 Spot Instances (CMP407-R1) - AWS re...Running Enterprise Test/Dev on Amazon EC2 Spot Instances (CMP407-R1) - AWS re...
Running Enterprise Test/Dev on Amazon EC2 Spot Instances (CMP407-R1) - AWS re...
 
MySQL High Availability & Disaster Recovery (DAT361) - AWS re:Invent 2018
MySQL High Availability & Disaster Recovery (DAT361) - AWS re:Invent 2018MySQL High Availability & Disaster Recovery (DAT361) - AWS re:Invent 2018
MySQL High Availability & Disaster Recovery (DAT361) - AWS re:Invent 2018
 
Manage Queries, and Audit Usage & Control Costs at Scale on Amazon Athena (AN...
Manage Queries, and Audit Usage & Control Costs at Scale on Amazon Athena (AN...Manage Queries, and Audit Usage & Control Costs at Scale on Amazon Athena (AN...
Manage Queries, and Audit Usage & Control Costs at Scale on Amazon Athena (AN...
 
Customizing Data Lakes to Work for Your Enterprise with Sysco (STG340) - AWS ...
Customizing Data Lakes to Work for Your Enterprise with Sysco (STG340) - AWS ...Customizing Data Lakes to Work for Your Enterprise with Sysco (STG340) - AWS ...
Customizing Data Lakes to Work for Your Enterprise with Sysco (STG340) - AWS ...
 
Move Data to AWS Faster for Migrations, DR, & Bidirectional Workflows (STG382...
Move Data to AWS Faster for Migrations, DR, & Bidirectional Workflows (STG382...Move Data to AWS Faster for Migrations, DR, & Bidirectional Workflows (STG382...
Move Data to AWS Faster for Migrations, DR, & Bidirectional Workflows (STG382...
 
Continuous Integration Best Practices (DEV319-R1) - AWS re:Invent 2018
Continuous Integration Best Practices (DEV319-R1) - AWS re:Invent 2018Continuous Integration Best Practices (DEV319-R1) - AWS re:Invent 2018
Continuous Integration Best Practices (DEV319-R1) - AWS re:Invent 2018
 
How Cox Automotive Runs GitHub Enterprise on AWS (ENT356-S) - AWS re:Invent 2018
How Cox Automotive Runs GitHub Enterprise on AWS (ENT356-S) - AWS re:Invent 2018How Cox Automotive Runs GitHub Enterprise on AWS (ENT356-S) - AWS re:Invent 2018
How Cox Automotive Runs GitHub Enterprise on AWS (ENT356-S) - AWS re:Invent 2018
 
Shift-Left SRE: Self-Healing with AWS Lambda Functions (DEV313-S) - AWS re:In...
Shift-Left SRE: Self-Healing with AWS Lambda Functions (DEV313-S) - AWS re:In...Shift-Left SRE: Self-Healing with AWS Lambda Functions (DEV313-S) - AWS re:In...
Shift-Left SRE: Self-Healing with AWS Lambda Functions (DEV313-S) - AWS re:In...
 

Similar to “Cloud First” Helps Hub Intl Grow the Business with Splunk on AWS (ANT330-S) - AWS re:Invent 2018

Security & Compliance in the Cloud
Security & Compliance in the CloudSecurity & Compliance in the Cloud
Security & Compliance in the CloudAmazon Web Services
 
Executive Security Simulation Workshop (WPS206) - AWS re:Invent 2018
Executive Security Simulation Workshop (WPS206) - AWS re:Invent 2018Executive Security Simulation Workshop (WPS206) - AWS re:Invent 2018
Executive Security Simulation Workshop (WPS206) - AWS re:Invent 2018Amazon Web Services
 
Migrate, Modernize, and Manage: Best Practices for a Cloud Migration
Migrate, Modernize, and Manage: Best Practices for a Cloud MigrationMigrate, Modernize, and Manage: Best Practices for a Cloud Migration
Migrate, Modernize, and Manage: Best Practices for a Cloud MigrationAmazon Web Services
 
Security Framework Shakedown: Chart Your Journey with AWS Best Practices (SEC...
Security Framework Shakedown: Chart Your Journey with AWS Best Practices (SEC...Security Framework Shakedown: Chart Your Journey with AWS Best Practices (SEC...
Security Framework Shakedown: Chart Your Journey with AWS Best Practices (SEC...Amazon Web Services
 
MongoDB World 2018: Tutorial - How to Build Applications with MongoDB Atlas &...
MongoDB World 2018: Tutorial - How to Build Applications with MongoDB Atlas &...MongoDB World 2018: Tutorial - How to Build Applications with MongoDB Atlas &...
MongoDB World 2018: Tutorial - How to Build Applications with MongoDB Atlas &...MongoDB
 
Unlocking Software Innovation with AWS - Adrian White - AWS TechShift ANZ 2018
Unlocking Software Innovation with AWS - Adrian White - AWS TechShift ANZ 2018Unlocking Software Innovation with AWS - Adrian White - AWS TechShift ANZ 2018
Unlocking Software Innovation with AWS - Adrian White - AWS TechShift ANZ 2018Amazon Web Services
 
How Rent-A-Center Stays Secure and Compliant on AWS with Alert Logic
 How Rent-A-Center Stays Secure and Compliant on AWS with Alert Logic How Rent-A-Center Stays Secure and Compliant on AWS with Alert Logic
How Rent-A-Center Stays Secure and Compliant on AWS with Alert LogicAmazon Web Services
 
AWS and Symantec: Cyber Defense at Scale (SEC311-S) - AWS re:Invent 2018
AWS and Symantec: Cyber Defense at Scale (SEC311-S) - AWS re:Invent 2018AWS and Symantec: Cyber Defense at Scale (SEC311-S) - AWS re:Invent 2018
AWS and Symantec: Cyber Defense at Scale (SEC311-S) - AWS re:Invent 2018Amazon Web Services
 
ENT305 Compliance and Cloud Security for Regulated Industries
ENT305 Compliance and Cloud Security for Regulated IndustriesENT305 Compliance and Cloud Security for Regulated Industries
ENT305 Compliance and Cloud Security for Regulated IndustriesAmazon Web Services
 
Cloud DevSecOps Considerations Leveraging AWS Marketplace Software
Cloud DevSecOps Considerations Leveraging AWS Marketplace SoftwareCloud DevSecOps Considerations Leveraging AWS Marketplace Software
Cloud DevSecOps Considerations Leveraging AWS Marketplace SoftwareAmazon Web Services
 
AWS Governance at Scale_AWSPSSummit_Singapore
AWS Governance at Scale_AWSPSSummit_SingaporeAWS Governance at Scale_AWSPSSummit_Singapore
AWS Governance at Scale_AWSPSSummit_SingaporeAmazon Web Services
 
How Do I Plan for Security, Risk and Compliance when Migrating to AWS?
How Do I Plan for Security, Risk and Compliance when Migrating to AWS?How Do I Plan for Security, Risk and Compliance when Migrating to AWS?
How Do I Plan for Security, Risk and Compliance when Migrating to AWS?Amazon Web Services
 
[REPEAT 1] Safeguard the Integrity of Your Code for Fast and Secure Deploymen...
[REPEAT 1] Safeguard the Integrity of Your Code for Fast and Secure Deploymen...[REPEAT 1] Safeguard the Integrity of Your Code for Fast and Secure Deploymen...
[REPEAT 1] Safeguard the Integrity of Your Code for Fast and Secure Deploymen...Amazon Web Services
 
Safeguard the Integrity of Your Code for Fast and Secure Deployments (DEV349-...
Safeguard the Integrity of Your Code for Fast and Secure Deployments (DEV349-...Safeguard the Integrity of Your Code for Fast and Secure Deployments (DEV349-...
Safeguard the Integrity of Your Code for Fast and Secure Deployments (DEV349-...Amazon Web Services
 
Cloud DevSecOps and compliance considerations leveraging AWS Marketplace sellers
Cloud DevSecOps and compliance considerations leveraging AWS Marketplace sellersCloud DevSecOps and compliance considerations leveraging AWS Marketplace sellers
Cloud DevSecOps and compliance considerations leveraging AWS Marketplace sellersAmazon Web Services
 
A Case Study on Insider Threat Detection
A Case Study on Insider Threat DetectionA Case Study on Insider Threat Detection
A Case Study on Insider Threat DetectionAmazon Web Services
 
Moving 400 Engineers to AWS: Our Journey to Secure Adoption (SEC306-S) - AWS ...
Moving 400 Engineers to AWS: Our Journey to Secure Adoption (SEC306-S) - AWS ...Moving 400 Engineers to AWS: Our Journey to Secure Adoption (SEC306-S) - AWS ...
Moving 400 Engineers to AWS: Our Journey to Secure Adoption (SEC306-S) - AWS ...Amazon Web Services
 
Operational Excellence for Identity & Access Management (SEC334) - AWS re:Inv...
Operational Excellence for Identity & Access Management (SEC334) - AWS re:Inv...Operational Excellence for Identity & Access Management (SEC334) - AWS re:Inv...
Operational Excellence for Identity & Access Management (SEC334) - AWS re:Inv...Amazon Web Services
 

Similar to “Cloud First” Helps Hub Intl Grow the Business with Splunk on AWS (ANT330-S) - AWS re:Invent 2018 (20)

Security & Compliance in the Cloud
Security & Compliance in the CloudSecurity & Compliance in the Cloud
Security & Compliance in the Cloud
 
Executive Security Simulation Workshop (WPS206) - AWS re:Invent 2018
Executive Security Simulation Workshop (WPS206) - AWS re:Invent 2018Executive Security Simulation Workshop (WPS206) - AWS re:Invent 2018
Executive Security Simulation Workshop (WPS206) - AWS re:Invent 2018
 
AWS - Security & Compliance
AWS - Security & ComplianceAWS - Security & Compliance
AWS - Security & Compliance
 
Migrate, Modernize, and Manage: Best Practices for a Cloud Migration
Migrate, Modernize, and Manage: Best Practices for a Cloud MigrationMigrate, Modernize, and Manage: Best Practices for a Cloud Migration
Migrate, Modernize, and Manage: Best Practices for a Cloud Migration
 
Security Framework Shakedown: Chart Your Journey with AWS Best Practices (SEC...
Security Framework Shakedown: Chart Your Journey with AWS Best Practices (SEC...Security Framework Shakedown: Chart Your Journey with AWS Best Practices (SEC...
Security Framework Shakedown: Chart Your Journey with AWS Best Practices (SEC...
 
Breaking Down the 'Monowhat'
Breaking Down the 'Monowhat'Breaking Down the 'Monowhat'
Breaking Down the 'Monowhat'
 
MongoDB World 2018: Tutorial - How to Build Applications with MongoDB Atlas &...
MongoDB World 2018: Tutorial - How to Build Applications with MongoDB Atlas &...MongoDB World 2018: Tutorial - How to Build Applications with MongoDB Atlas &...
MongoDB World 2018: Tutorial - How to Build Applications with MongoDB Atlas &...
 
Unlocking Software Innovation with AWS - Adrian White - AWS TechShift ANZ 2018
Unlocking Software Innovation with AWS - Adrian White - AWS TechShift ANZ 2018Unlocking Software Innovation with AWS - Adrian White - AWS TechShift ANZ 2018
Unlocking Software Innovation with AWS - Adrian White - AWS TechShift ANZ 2018
 
How Rent-A-Center Stays Secure and Compliant on AWS with Alert Logic
 How Rent-A-Center Stays Secure and Compliant on AWS with Alert Logic How Rent-A-Center Stays Secure and Compliant on AWS with Alert Logic
How Rent-A-Center Stays Secure and Compliant on AWS with Alert Logic
 
AWS and Symantec: Cyber Defense at Scale (SEC311-S) - AWS re:Invent 2018
AWS and Symantec: Cyber Defense at Scale (SEC311-S) - AWS re:Invent 2018AWS and Symantec: Cyber Defense at Scale (SEC311-S) - AWS re:Invent 2018
AWS and Symantec: Cyber Defense at Scale (SEC311-S) - AWS re:Invent 2018
 
ENT305 Compliance and Cloud Security for Regulated Industries
ENT305 Compliance and Cloud Security for Regulated IndustriesENT305 Compliance and Cloud Security for Regulated Industries
ENT305 Compliance and Cloud Security for Regulated Industries
 
Cloud DevSecOps Considerations Leveraging AWS Marketplace Software
Cloud DevSecOps Considerations Leveraging AWS Marketplace SoftwareCloud DevSecOps Considerations Leveraging AWS Marketplace Software
Cloud DevSecOps Considerations Leveraging AWS Marketplace Software
 
AWS Governance at Scale_AWSPSSummit_Singapore
AWS Governance at Scale_AWSPSSummit_SingaporeAWS Governance at Scale_AWSPSSummit_Singapore
AWS Governance at Scale_AWSPSSummit_Singapore
 
How Do I Plan for Security, Risk and Compliance when Migrating to AWS?
How Do I Plan for Security, Risk and Compliance when Migrating to AWS?How Do I Plan for Security, Risk and Compliance when Migrating to AWS?
How Do I Plan for Security, Risk and Compliance when Migrating to AWS?
 
[REPEAT 1] Safeguard the Integrity of Your Code for Fast and Secure Deploymen...
[REPEAT 1] Safeguard the Integrity of Your Code for Fast and Secure Deploymen...[REPEAT 1] Safeguard the Integrity of Your Code for Fast and Secure Deploymen...
[REPEAT 1] Safeguard the Integrity of Your Code for Fast and Secure Deploymen...
 
Safeguard the Integrity of Your Code for Fast and Secure Deployments (DEV349-...
Safeguard the Integrity of Your Code for Fast and Secure Deployments (DEV349-...Safeguard the Integrity of Your Code for Fast and Secure Deployments (DEV349-...
Safeguard the Integrity of Your Code for Fast and Secure Deployments (DEV349-...
 
Cloud DevSecOps and compliance considerations leveraging AWS Marketplace sellers
Cloud DevSecOps and compliance considerations leveraging AWS Marketplace sellersCloud DevSecOps and compliance considerations leveraging AWS Marketplace sellers
Cloud DevSecOps and compliance considerations leveraging AWS Marketplace sellers
 
A Case Study on Insider Threat Detection
A Case Study on Insider Threat DetectionA Case Study on Insider Threat Detection
A Case Study on Insider Threat Detection
 
Moving 400 Engineers to AWS: Our Journey to Secure Adoption (SEC306-S) - AWS ...
Moving 400 Engineers to AWS: Our Journey to Secure Adoption (SEC306-S) - AWS ...Moving 400 Engineers to AWS: Our Journey to Secure Adoption (SEC306-S) - AWS ...
Moving 400 Engineers to AWS: Our Journey to Secure Adoption (SEC306-S) - AWS ...
 
Operational Excellence for Identity & Access Management (SEC334) - AWS re:Inv...
Operational Excellence for Identity & Access Management (SEC334) - AWS re:Inv...Operational Excellence for Identity & Access Management (SEC334) - AWS re:Inv...
Operational Excellence for Identity & Access Management (SEC334) - AWS re:Inv...
 

More from Amazon Web Services

Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...Amazon Web Services
 
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...Amazon Web Services
 
Esegui pod serverless con Amazon EKS e AWS Fargate
Esegui pod serverless con Amazon EKS e AWS FargateEsegui pod serverless con Amazon EKS e AWS Fargate
Esegui pod serverless con Amazon EKS e AWS FargateAmazon Web Services
 
Costruire Applicazioni Moderne con AWS
Costruire Applicazioni Moderne con AWSCostruire Applicazioni Moderne con AWS
Costruire Applicazioni Moderne con AWSAmazon Web Services
 
Come spendere fino al 90% in meno con i container e le istanze spot
Come spendere fino al 90% in meno con i container e le istanze spot Come spendere fino al 90% in meno con i container e le istanze spot
Come spendere fino al 90% in meno con i container e le istanze spot Amazon Web Services
 
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...Amazon Web Services
 
OpsWorks Configuration Management: automatizza la gestione e i deployment del...
OpsWorks Configuration Management: automatizza la gestione e i deployment del...OpsWorks Configuration Management: automatizza la gestione e i deployment del...
OpsWorks Configuration Management: automatizza la gestione e i deployment del...Amazon Web Services
 
Microsoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows WorkloadsMicrosoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows WorkloadsAmazon Web Services
 
Database Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatareDatabase Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatareAmazon Web Services
 
Crea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJSCrea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJSAmazon Web Services
 
API moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e webAPI moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e webAmazon Web Services
 
Database Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatareDatabase Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatareAmazon Web Services
 
Tools for building your MVP on AWS
Tools for building your MVP on AWSTools for building your MVP on AWS
Tools for building your MVP on AWSAmazon Web Services
 
How to Build a Winning Pitch Deck
How to Build a Winning Pitch DeckHow to Build a Winning Pitch Deck
How to Build a Winning Pitch DeckAmazon Web Services
 
Building a web application without servers
Building a web application without serversBuilding a web application without servers
Building a web application without serversAmazon Web Services
 
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...Amazon Web Services
 
Introduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container ServiceIntroduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container ServiceAmazon Web Services
 

More from Amazon Web Services (20)

Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
 
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
 
Esegui pod serverless con Amazon EKS e AWS Fargate
Esegui pod serverless con Amazon EKS e AWS FargateEsegui pod serverless con Amazon EKS e AWS Fargate
Esegui pod serverless con Amazon EKS e AWS Fargate
 
Costruire Applicazioni Moderne con AWS
Costruire Applicazioni Moderne con AWSCostruire Applicazioni Moderne con AWS
Costruire Applicazioni Moderne con AWS
 
Come spendere fino al 90% in meno con i container e le istanze spot
Come spendere fino al 90% in meno con i container e le istanze spot Come spendere fino al 90% in meno con i container e le istanze spot
Come spendere fino al 90% in meno con i container e le istanze spot
 
Open banking as a service
Open banking as a serviceOpen banking as a service
Open banking as a service
 
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
 
OpsWorks Configuration Management: automatizza la gestione e i deployment del...
OpsWorks Configuration Management: automatizza la gestione e i deployment del...OpsWorks Configuration Management: automatizza la gestione e i deployment del...
OpsWorks Configuration Management: automatizza la gestione e i deployment del...
 
Microsoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows WorkloadsMicrosoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows Workloads
 
Computer Vision con AWS
Computer Vision con AWSComputer Vision con AWS
Computer Vision con AWS
 
Database Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatareDatabase Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatare
 
Crea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJSCrea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJS
 
API moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e webAPI moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e web
 
Database Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatareDatabase Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatare
 
Tools for building your MVP on AWS
Tools for building your MVP on AWSTools for building your MVP on AWS
Tools for building your MVP on AWS
 
How to Build a Winning Pitch Deck
How to Build a Winning Pitch DeckHow to Build a Winning Pitch Deck
How to Build a Winning Pitch Deck
 
Building a web application without servers
Building a web application without serversBuilding a web application without servers
Building a web application without servers
 
Fundraising Essentials
Fundraising EssentialsFundraising Essentials
Fundraising Essentials
 
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
 
Introduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container ServiceIntroduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container Service
 

“Cloud First” Helps Hub Intl Grow the Business with Splunk on AWS (ANT330-S) - AWS re:Invent 2018

  • 1.
  • 2. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. “Cloud First” Helps Hub Intl Grow the Business with Splunk on AWS Seth Morrell Vice President, Enterprise Architecture and Design HUB International A N T 3 3 0 - S Jeremy Embalabala Director, Security Architecture & Engineering HUB International Jae Lee Director Product Marketing, Security Splunk
  • 3. “Our partnership with Splunk is incredibly important for our customers. Customers love AWS agility with Splunk visibility.” Andy Jassy, CEO Amazon Web Services
  • 4. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. One consolidated solutionManage hybrid infrastructure Cost, capacity, and resource management Cloud migration Splunk takes the place of the multitude of monitoring tools because sometimes one is better than many. Hybrid infrastructure creates a complex monitoring environment. Legacy tools can't keep up. Splunk can. Understand how your resources are performing – and how many are being used – then optimize utilization and billing. Get visibility at all stages of the migration process – whether before, during, or long after. End state: Comprehensive AWS visibility
  • 5. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Splunk and AWS Custom dashboards Report and analyze Monitor and alert Developer Platform Ad hoc search Real-time machine data References – Coded fields, mappings, aliases Dynamic information – Stored in non-traditional formats Environmental context – Human-maintained files, documents System/application – Available only using application request Intelligence/analytics – Indicators, anomaly, research, white/blacklist On-premises Private cloud Public cloud Storage Online shopping cart Telecoms Desktops Security Web Services Networks Containers Web clickstreams RFID Smartphones and devices Servers Messaging GPS location Packaged applications Custom applications Online services DatabasesCall detail records AWS CloudTrail AWS Config Index untapped data: Any source, type, volume Amazon EC2 AWS Lambda AWS app & add-on Amazon GuardDuty Amazon Kinesis Data Firehose
  • 6. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. End state: Comprehensive AWS visibility
  • 7. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.  Sudden change in the number of security group rules?  Sudden change in the number of ACL modifications?  Spike in error activity caused by unauthorized actions?  Are there any publicly accessible Amazon Simple Storage Service (Amazon S3) buckets?  Any provisioning activity from an unusual country?  API calls from users who have not made API calls before?  First time a user provisioned an instance / account / other? Examples: Basic posture methods
  • 8. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.  Who added that rule in the security group that protects our application servers?  Where is the blocked traffic into that VPC coming from?  What was the activity trail of a particular user before and after an incident?  Alert me when a user imports key-pairs or when a security group allows all ports  What instances are provisioned outside of a VPC, by whom, and when?  What security groups are defined but not attached to any resource? Example investigative methods Splunk App for AWS
  • 9. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
  • 10. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Seth Morrell Vice President, Enterprise Architecture and Design Jeremy Embalabala Director, Security Architecture and Engineering • Currently lead the information security, governance, and risk management programs at HUB • Previously the CISO of Beam Suntory • Specialize in building cloud-first security programs tightly aligned with business risks and goals • Currently am married and live in Woodstock, IL, and enjoy sustainable farming and fishing • Responsible for security architecture and engineering at HUB • Background in information security, Insuretech, and deep learning • AWS Certified Solutions Architect • Global Information Security certification – GSEC, GCED Who are we?
  • 11. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. SCOPE & SCALE FOOTPRINT National HUB 2017 15% 27% 2% 51% 5% Commercial Lines Employee Benefits Personal Lines Wholesale Other Total Revenue: $2 Billion+ OWNERSHIP Hellman & Friedman: Our Private Equity Partner o Partners since October 2013 o One of the most experienced and successful investment organizations in the private equity industry o Strong track record for investors in H&F’s portfolio companies o Extensive investment experience in the insurance industry and related verticals 25% Principals & Employees 75% H&F and Co-investors 400+ locations in North America Top 5 Global Broker based on revenue 11,000+ employees 1 million+ clients 92% client retention $17 billion+ in premium Who is HUB?
  • 12. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. What was the Initiative? HUB International working on slide or two Hub team to create content
  • 13. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. A best-in-class technology strategy with a cloud-first mandate Ability to detect and remediate next- generation threats quickly before breach or impact Drive revenue and organic growth through M&A, process optimization, and digital transformation Building security according to best practices, which allows HUB to stay ahead of future regulations Leverage data analytics to make faster and more accurate business decisions Optimizing process and change management across our organization HUB transformation goals
  • 14. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Rapid program development
  • 15. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Sept Oct Nov Dec Jan 2018 Feb Mar Apr May June July Network Transition Office 365 Migration Information Security Rollout AugAug CRM Cloud Data Analytics Buildout Cloud End User Computing Risk Management Project 2016 SharePoint Migration Cloud Migration Transformation roadmap
  • 16. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. The immediate challenge – Secure migration • Controlling AWS costs • Track AWS infrastructure and service usage • Capacity planning • Security of applications and infrastructure across hybrid environments • Organizations with multiple accounts • Services and infrastructure deployed in many AWS Regions and Availability Zones • Data taking on many different formats
  • 17. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. ○ Extremely flexible architecture and cost structure ○ Ability to log and report on both security and cloud health ○ Ability to grow with our business, security, and cloud needs ○ Great network of support and knowledge ○ Strong app integrations ○ Ability to host existing system and provide options to “fail fast” ○ Exceptional service options and availability ○ Ability to leverage security capability that was previously unavailable to HUB ○ Enhance HUB’s disaster recovery and backup strategy Cost-effective, agile dev environmentSecure cloud migration Why we chose Splunk and AWS
  • 18. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Security use cases • Security Operation Center (SOC) • One of the cornerstones of our InfoSec program • Partnered with an MSSP to build and manage • Partner brings agility and high-level experience • Splunk Enterprise Security for SIEM • Security priority • Also offers benefits to our IT operations, applications, and engineering teams
  • 19. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Splunk design MSSP Account HUB Datacenter HUB Account(s) AWS Direct Connect VPN connection VPN connection VPN connection Data Sources Search Head Data SourcesIndexers Forwarders Forwarders
  • 20. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Amazon EC2 Flow logs Amazon S3 Amazon CloudWatch AWS Config AWS CloudTrailIAM Amazon Kinesis Amazon SQS Amazon SNS Amazon VPC Amazon elastic load balancers Source Capture Delivery Consumption AWS API Splunk Indices AWS integration
  • 21. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Threat Hunting Analysis Correlation Complexity Investment Efficacy Adapted from Yuval Sinay’s Cybersecurity Monitoring Maturity Model Threat detection
  • 22. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Why Amazon Kinesis Data Firehose? • Data sources • Change logs • Log-in activity • Storage logs • Performance telemetry • Network activity Amazon VPC Flow Logs Queue-based messaging • Not necessarily ordered • Low read/write frequency limits Real-time data stream • Ordered messages • Message receipt acknowledgement • Re-playable messages • High read/write frequency limits Flow Data Index Correlation Alerting
  • 23. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Threat intelligence integration Threat bulletins Indicators of compromise Import into Splunk High-confidence incidents • Command & control • Malware traffic • Anonymizers & proxies • Tor traffic • Vulnerability context • Threat actor attribution
  • 24. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Dashboards
  • 25. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. VPC Flow Logs
  • 26. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. App search and reporting
  • 27. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Dashboards
  • 28. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Lessons learned • Use IAM roles instead of AWS access keys • Large volume of VPC flow data • Make sure your indexers have enough horsepower • Understand the licensing cost • Invest in third-party threat intelligence feeds and integrate with Splunk • Use the Splunk App for AWS to identify misconfigurations in the environment and for greater insights into billing
  • 29. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Roadmap – Leveraging AWS and Splunk • SOC automation • Proactive threat hunting • Microservices, containers, & transient workloads • Amazon Macie data classification for M&A data transfers • Enterprise monitoring
  • 30. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
  • 31. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. © 2017 SPLUNK INC. 1. Splunk and AWS partner across data ingestion, cloud migration, and AWS best practices to ensure joint customer success 2. Get deep visibility into AWS – Security, operations, and cost management with the Splunk App for AWS 3. Monitor your on-premises to AWS migrations and help ensure your AWS environment is well-architected with Splunk To get end-to-end visibility with Splunk + AWS Key takeaways
  • 32. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. © 2017 SPLUNK INC. 1. Drop by booth #2816 – Grab a Splunk T-shirt and participate in a demo 2. Start your free trial of Splunk solutions on AWS Marketplace today!
  • 33. Thank you! © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
  • 34. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.