SlideShare a Scribd company logo
1 of 51
© 2019 SPLUNK INC.© 2019 SPLUNK INC.
Clear the Mist from your Clouds
with Splunk
SplunkLive London - June 2019
Yuval Tenenbaum
Director – SE Architects EMEA
© 2017 SPLUNK INC.
Migration To
Cloud & Hybrid
Cloud Insights
is Top Of Mind
© 2019 SPLUNK INC.
► Enables Least privileged model at the highest operational control
► Mitigates Risk – lower the ‘blast radius’ of impactful events
► Achieve Agility- deploy & run environments programmatically at scale
► Cost optimisation- clear ‘line of sight’ into the cost of running workloads
Hybrid Cloud – Think Differently
Legacy
Model Least
privileged
© 2019 SPLUNK INC.
► Split Investment may slow down your cloud adoption – Spreading your
resources across multiple clouds means that you may not get critical mass or a
fast ROI
► Portability - How many of us will actually move workloads around?
► Cloud Broker concept – Putting a “bloatware” between you and your cloud api’s
instead of working natively with these cloud API’s
Is it Really All Good Stuff?
I used to be
indecisive now I’m
definitely going multi-
cloud
© 2019 SPLUNK INC.
Cloud - Same Challenges-Different Environments
► Security
• Are we firewalled correctly?
• Do we use all necessary security features?
► Compliance
• Are we following all published standards?
► Networking
• Placed servers on the correct network?
► Financial
• Stayed within budget?
► Capacity Planning
• Used resources optimally?
And all of that in a
decentralized Model…
© 2019 SPLUNK INC.
Customer experience???
SAAS
Hybrid Everything - What happens when we stack
them?
ON PREMISES
Legacy systems
(Mainframe…)
Facilities
Dev/PreProd
Storage
Backup
Archive
DR
Security
VMs
Containers Micro
services
AWS (Application 1)Access / Security
Database
StorageDev
Compute
Containers
App engine
GCP
(Big Data project 1)
Dataflow
AWS
(Archive) Azure (Application 1)
VMs
Database
VM sets
Traffic mger
© 2017 SPLUNK INC.
So How Can Splunk Clear
up this Cloudy Mist?
Know your Clouds…..
© 2019 SPLUNK INC.
► Splunk has working relationships with AWS, Azure, and GCP
► We have customers successfully running Splunk Enterprise BYOL within AWS,
Azure, and GCP
► We have proven strategies to get data in from AWS, Azure, and GCP
Cloud Vendor Relationships
© 2017 SPLUNK INC.
Splunk’s Approach to Hybrid Cloud
One Consolidated
Solution
Manage Hybrid
Infrastructure
Cost, Capacity and
Resource Management
Cloud Migration
Splunk takes the place of the
multitude of monitoring tools
because sometimes one is
better than many.
Deploy Splunk in Hybrid
setup (on-prem, saas, byol)
and deal with Hybrid
infrastructure complex
monitoring
Understand how your
resources are performing –
and how many are being
used – then optimize
utilization and billing.
Get visibility at all stages of
the migration process
(landing zones)– whether
before, during or long after.
© 2017 SPLUNK INC.
In the Beginning……
Cloud Migration
© 2019 SPLUNK INC.
What Customers Want To Achieve When Migrating to
the Cloud
► Build - Differentiate yourself by
building unique and valuable services
► Move Fast - From initial idea to a
service which can be monetized
► Stay Secure - Make sure that what
we build is secure and compliant
▶ Manage Cost – Control what you
spend and gain visibility into future
cost
© 2019 SPLUNK INC.
Path To Successful Cloud Migration
Measure the baseline user
experience and performance,
as well as define acceptable
post-migration levels.
Security assessment – build a
well architected and compliant
landing zones
Performance metrics should
be closely monitored &
compared to the baseline.
Throughout the migration,
end-to-end monitoring can
help SecOps teams stay
ahead of any potential risks.
Continuous monitoring
should be used to measure
acceptable metrics and
success.
Leverage a platform that
shows insights into cost,
shared services, monitoring,
Security & compliance
BEFORE DURING AFTER
© 2019 SPLUNK INC.
Challenges With Building & Maintaining Landing
Zones
▶ Define & maintain an Account
structure
▶ Define your network architecture and
monitor it continuously
▶ Define & maintain a security
governance and compliance baseline Migrate Land Operate &
Optimize
© 2019 SPLUNK INC.
Additional Considerations
▶ Define & maintain centralized logging
▶ Define & maintain Cost Allocation
© 2019 SPLUNK INC.
How Can Splunk Help (1)?
▶ Tell you who is accessing
your accounts, from where
and what are they doing?
© 2019 SPLUNK INC.
How Can Splunk Help (2)?
▶ Tell you if anyone is breaking your security policies?
• Is encryption used everywhere
• Has the root account has MFA enabled
• Suspicious AWS S3 Activities
• IAM Password policies are kept as you defined in your security
baseline?
© 2019 SPLUNK INC.
How Can Splunk Help (3)?
▶ Help you understand your network topology and gain
visibility into who is trying to access it
▶ Help you gain visibility into performance & right sizing
of your key workloads
▶ Help you understand historic and future cost
© 2019 SPLUNK INC.
AWS Analytic Stories - ES Content Updates
© 2019 SPLUNK INC.
Migration Dashboards
© 2017 SPLUNK INC.
So How Do We
Collect Cloud Data to
do this Hybrid
Monitoring?
© 2017 SPLUNK INC.
Getting Data In
Cloud Patterns
© 2017 SPLUNK INC.
General Getting Data In Routes
Pull or Push, Add-Ons or Serverless
Poll/Request API
Data
Data
Cloud
Serverless
Code
Add-On
HEC “Push”
© 2017 SPLUNK INC.
GDI : AWS
© 2019 SPLUNK INC.
It May Look a Bit Complicated
© 2019 SPLUNK INC.
► AWS Config can be pulled with a Splunk Heavy Forwarder with the SQS Based
S3. Anything via CloudWatch Logs or CW events, can be pushed with Kinesis
Firehose to Splunk
AWS Pull vs. Push
Config Events
SNS
Topic
Notification
SQS
Subscription
Notification
Pulls Event from S3 Bucket
Splunk Pull
SQS Notification
HEC
PushPull
CloudWatch
Logs
© 2019 SPLUNK INC.
AWS Source Matrix
There are many options to GDI in AWS but Splunk can help
Data Type Recommended Input Type
Billing Billing
CloudWatch CloudWatch
CloudFront Access Logs SQS based S3
Config SQS based S3
Config Rules Config Rules
Description Description
ELB Access Logs SQS based S3
Inspector Inspector
CloudTrail SQS Based S3
S3 access logs SQS Based S3
VPC Flow Logs (CW Logs) Kinesis
With SQS Based S3 you can
scale out data collection by
configuring multiple inputs to
ingest logs from the same S3
bucket without creating duplicate
data.
Kinesis Firehose is
recommended for CloudWatch
Logs data collection
© 2017 SPLUNK INC.
GDI : Azure & O365
© 2019 SPLUNK INC.
3 Log Types in Azure
1) Control/Management, 2) Data Plane, 3) Processed Events
Control: System Configuration and Management
Data Plane: Provisioned Service and Diagnostic Data
Processed Events: Alerts & Recommendations
© 2019 SPLUNK INC.
{ REST }
Storage Event Hub
© 2019 SPLUNK INC.
► Splunk can pull data from Azure using a Heavy Forwarder and collect data from
either the MS Blob or a REST API using the modular input. Azure can push data
using the Event Hub to Azure Functions which can be sent to Splunk’s HEC.
Azure Pull vs. Push
MSBlob
HEC
PushPull
Splunk Indexers
Activity Monitor Event Hub Azure Function
Event Hub
© 2019 SPLUNK INC.
Azure Add-on Landscape
© 2019 SPLUNK INC.
Getting O365 Data In
Azure Active Directory
Application
OAUTH2
REST
Splunk Add-on for
Microsoft O365
Office 365
© 2017 SPLUNK INC.
GDI : Google Cloud
© 2019 SPLUNK INC.
Getting GCP Data In
REST
Splunk Add-on for
Google Cloud Platform
Billing
PubSub
Monitoring
StackDriver
© 2019 SPLUNK INC.
► Initial:
• Most customers will generate around 1-10GB when they are setting up their Public Cloud
deployments and enabling services.
• As they mature - 10-50GB.
► More instances and deployed apps in Cloud, 50-200GB.
► Most customers are 100-200GB / day of Public Cloud data.
► All-in Cloud Companies : 500GB-1TB range.
► Less common >1TB
► O365 - ~400 to 500 KB per user per day (50K users = 25 GB/day)
► Best way to analyze the amount of data is to spin-off a test environment and look
at the numbers.
How Much Data?
© 2017 SPLUNK INC.
Collection
Deployment
Architectures
© 2019 SPLUNK INC.
► Central Splunk Instance
• One Instance to manage – lower “Instance/Storage” costs
• Data egress cost considerations (data transfers from each cloud)
• Local or Distributed Heavy Forwarders
► Splunk Instance per Cloud, 1 “Master” view
• One Instance in each Cloud – potential higher “Instance/Storage” cost
• Management of Splunk in each Cloud
• “Master” Search Head needed for Hybrid Search – latency impact
• Lower egress cost
► Hybrid
• Mix of both options balancing out Costs/Hybrid Search
Deployment Architecture
3 Patterns
© 2019 SPLUNK INC.
Option 1
Public/Private Cloud /
Splunk Cloud
Single Splunk InstanceHeavy Forwarder (Add-On)
Heavy Forwarder (Add-On)
Heavy Forwarder (Add-On)
Note Options for Serverless/HEC input direct
to Central Instance
Cloud Data
© 2019 SPLUNK INC.
Option 2
Public/Private Cloud
Distributed Hybrid SearchSplunk Indexer(s)
Splunk Indexer(s)
Splunk Indexer(s)
Search Head
Search Results
© 2019 SPLUNK INC.
Option 3
Distributed Search
Splunk Indexer(s) &
Master Search
Splunk Indexer(s)
Heavy Forwarder (Add-On)
Cloud Data
Search Results
© 2019 SPLUNK INC.© 2017 SPLUNK INC.
© 2017 SPLUNK INC.
OUR MISSION
….Including Cloud data!
© 2019 SPLUNK INC.
Hybrid Monitoring
Collect & store machine data generated by on-premises IT sources and public cloud
sources simultaneously, and can correlate across both to monitor, alert, analyse,
troubleshoot and investigate.
© 2017 SPLUNK INC.
Pulling it all together:
Example Cloud Innovation,
Integration and Use Case
AWS Security Hub + Splunk Phantom Bi-Directional Integration
© 2019 SPLUNK INC.
AWS Security Hub - Findings
© 2019 SPLUNK INC.
Phantom - EC2 Instance- Investigate & Notify
© 2019 SPLUNK INC.
Geo Location & IP Reputation
© 2019 SPLUNK INC.
Prompting The Analyst- Quarantine Instance
© 2019 SPLUNK INC.
Phantom- Isolate ES2 Instance Playbook
© 2019 SPLUNK INC.
© 2019 SPLUNK INC.
Back To AWS Security Hub
© 2019 SPLUNK INC.© 2019 SPLUNK INC.
Don't forget to rate this session
in the .conf18 mobile app
Thank You.

More Related Content

What's hot

Splunk Distributed Management Console
Splunk Distributed Management Console                                         Splunk Distributed Management Console
Splunk Distributed Management Console Splunk
 
Splunk HTTP Event Collector
Splunk HTTP Event CollectorSplunk HTTP Event Collector
Splunk HTTP Event CollectorSplunk
 
"Splunk Worst Practices"... und wie man diese behebt
"Splunk Worst Practices"... und wie man diese behebt"Splunk Worst Practices"... und wie man diese behebt
"Splunk Worst Practices"... und wie man diese behebtSplunk
 
Power of Splunk Search Processing Language (SPL)
Power of Splunk Search Processing Language (SPL)Power of Splunk Search Processing Language (SPL)
Power of Splunk Search Processing Language (SPL)Splunk
 
SplunkLive! Getting Started with Splunk Enterprise
SplunkLive! Getting Started with Splunk EnterpriseSplunkLive! Getting Started with Splunk Enterprise
SplunkLive! Getting Started with Splunk EnterpriseSplunk
 
Elastic Stack Introduction
Elastic Stack IntroductionElastic Stack Introduction
Elastic Stack IntroductionVikram Shinde
 
SplunkLive! Data Models 101
SplunkLive! Data Models 101SplunkLive! Data Models 101
SplunkLive! Data Models 101Splunk
 
Snowflake essentials
Snowflake essentialsSnowflake essentials
Snowflake essentialsqureshihamid
 
Getting Started with Splunk Enterprise
Getting Started with Splunk EnterpriseGetting Started with Splunk Enterprise
Getting Started with Splunk EnterpriseSplunk
 
Snowflake: Your Data. No Limits (Session sponsored by Snowflake) - AWS Summit...
Snowflake: Your Data. No Limits (Session sponsored by Snowflake) - AWS Summit...Snowflake: Your Data. No Limits (Session sponsored by Snowflake) - AWS Summit...
Snowflake: Your Data. No Limits (Session sponsored by Snowflake) - AWS Summit...Amazon Web Services
 
Worst Splunk practices...and how to fix them
Worst Splunk practices...and how to fix themWorst Splunk practices...and how to fix them
Worst Splunk practices...and how to fix themSplunk
 
Introducing the Snowflake Computing Cloud Data Warehouse
Introducing the Snowflake Computing Cloud Data WarehouseIntroducing the Snowflake Computing Cloud Data Warehouse
Introducing the Snowflake Computing Cloud Data WarehouseSnowflake Computing
 
ELK stack introduction
ELK stack introduction ELK stack introduction
ELK stack introduction abenyeung1
 
Altis: AWS Snowflake Practice
Altis: AWS Snowflake PracticeAltis: AWS Snowflake Practice
Altis: AWS Snowflake PracticeAltis Consulting
 
Zero to Snowflake Presentation
Zero to Snowflake Presentation Zero to Snowflake Presentation
Zero to Snowflake Presentation Brett VanderPlaats
 
Marquez: A Metadata Service for Data Abstraction, Data Lineage, and Event-bas...
Marquez: A Metadata Service for Data Abstraction, Data Lineage, and Event-bas...Marquez: A Metadata Service for Data Abstraction, Data Lineage, and Event-bas...
Marquez: A Metadata Service for Data Abstraction, Data Lineage, and Event-bas...Willy Lulciuc
 
dlux - Splunk Technical Overview
dlux - Splunk Technical Overviewdlux - Splunk Technical Overview
dlux - Splunk Technical OverviewDavid Lutz
 

What's hot (20)

Snowflake Overview
Snowflake OverviewSnowflake Overview
Snowflake Overview
 
Splunk Distributed Management Console
Splunk Distributed Management Console                                         Splunk Distributed Management Console
Splunk Distributed Management Console
 
Splunk HTTP Event Collector
Splunk HTTP Event CollectorSplunk HTTP Event Collector
Splunk HTTP Event Collector
 
"Splunk Worst Practices"... und wie man diese behebt
"Splunk Worst Practices"... und wie man diese behebt"Splunk Worst Practices"... und wie man diese behebt
"Splunk Worst Practices"... und wie man diese behebt
 
Power of Splunk Search Processing Language (SPL)
Power of Splunk Search Processing Language (SPL)Power of Splunk Search Processing Language (SPL)
Power of Splunk Search Processing Language (SPL)
 
SplunkLive! Getting Started with Splunk Enterprise
SplunkLive! Getting Started with Splunk EnterpriseSplunkLive! Getting Started with Splunk Enterprise
SplunkLive! Getting Started with Splunk Enterprise
 
Splunk
SplunkSplunk
Splunk
 
Elastic Stack Introduction
Elastic Stack IntroductionElastic Stack Introduction
Elastic Stack Introduction
 
SplunkLive! Data Models 101
SplunkLive! Data Models 101SplunkLive! Data Models 101
SplunkLive! Data Models 101
 
Snowflake essentials
Snowflake essentialsSnowflake essentials
Snowflake essentials
 
Getting Started with Splunk Enterprise
Getting Started with Splunk EnterpriseGetting Started with Splunk Enterprise
Getting Started with Splunk Enterprise
 
Snowflake: Your Data. No Limits (Session sponsored by Snowflake) - AWS Summit...
Snowflake: Your Data. No Limits (Session sponsored by Snowflake) - AWS Summit...Snowflake: Your Data. No Limits (Session sponsored by Snowflake) - AWS Summit...
Snowflake: Your Data. No Limits (Session sponsored by Snowflake) - AWS Summit...
 
Worst Splunk practices...and how to fix them
Worst Splunk practices...and how to fix themWorst Splunk practices...and how to fix them
Worst Splunk practices...and how to fix them
 
Introducing the Snowflake Computing Cloud Data Warehouse
Introducing the Snowflake Computing Cloud Data WarehouseIntroducing the Snowflake Computing Cloud Data Warehouse
Introducing the Snowflake Computing Cloud Data Warehouse
 
ELK stack introduction
ELK stack introduction ELK stack introduction
ELK stack introduction
 
Cloudera SDX
Cloudera SDXCloudera SDX
Cloudera SDX
 
Altis: AWS Snowflake Practice
Altis: AWS Snowflake PracticeAltis: AWS Snowflake Practice
Altis: AWS Snowflake Practice
 
Zero to Snowflake Presentation
Zero to Snowflake Presentation Zero to Snowflake Presentation
Zero to Snowflake Presentation
 
Marquez: A Metadata Service for Data Abstraction, Data Lineage, and Event-bas...
Marquez: A Metadata Service for Data Abstraction, Data Lineage, and Event-bas...Marquez: A Metadata Service for Data Abstraction, Data Lineage, and Event-bas...
Marquez: A Metadata Service for Data Abstraction, Data Lineage, and Event-bas...
 
dlux - Splunk Technical Overview
dlux - Splunk Technical Overviewdlux - Splunk Technical Overview
dlux - Splunk Technical Overview
 

Similar to Clear the Mist from your Clouds with Splunk

Splunk und Multi-Cloud
Splunk und Multi-CloudSplunk und Multi-Cloud
Splunk und Multi-CloudSplunk
 
Splunk and Multicloud
Splunk and MulticloudSplunk and Multicloud
Splunk and MulticloudSplunk
 
Splunk and Multicloud
Splunk and Multicloud Splunk and Multicloud
Splunk and Multicloud Splunk
 
Securing the Enterprise/Cloud with Splunk at the Centre
Securing the Enterprise/Cloud with Splunk at the CentreSecuring the Enterprise/Cloud with Splunk at the Centre
Securing the Enterprise/Cloud with Splunk at the CentreHarry McLaren
 
What's New with the Latest Splunk Platform Release
What's New with the Latest Splunk Platform ReleaseWhat's New with the Latest Splunk Platform Release
What's New with the Latest Splunk Platform ReleaseSplunk
 
Splunk Cloud and Splunk Enterprise 7.2
Splunk Cloud and Splunk Enterprise 7.2 Splunk Cloud and Splunk Enterprise 7.2
Splunk Cloud and Splunk Enterprise 7.2 Splunk
 
Splunk Cloud and Splunk Enterprise 7.2
Splunk Cloud and Splunk Enterprise 7.2 Splunk Cloud and Splunk Enterprise 7.2
Splunk Cloud and Splunk Enterprise 7.2 Splunk
 
Splunk Cloud and Splunk Enterprise 7.2
Splunk Cloud and Splunk Enterprise 7.2Splunk Cloud and Splunk Enterprise 7.2
Splunk Cloud and Splunk Enterprise 7.2Splunk
 
Encontro anual para apresentação das novidades da .conf23
Encontro anual para apresentação das novidades da .conf23Encontro anual para apresentação das novidades da .conf23
Encontro anual para apresentação das novidades da .conf23Rafael Santos
 
Alle Neuigkeiten im letzten Plattform Release
Alle Neuigkeiten im letzten Plattform ReleaseAlle Neuigkeiten im letzten Plattform Release
Alle Neuigkeiten im letzten Plattform ReleaseSplunk
 
.conf Go Zurich 2022 - Platform Session
.conf Go Zurich 2022 - Platform Session.conf Go Zurich 2022 - Platform Session
.conf Go Zurich 2022 - Platform SessionSplunk
 
Splunk .conf18 Updates, Config Add-on, SplDevOps
Splunk .conf18 Updates, Config Add-on, SplDevOpsSplunk .conf18 Updates, Config Add-on, SplDevOps
Splunk .conf18 Updates, Config Add-on, SplDevOpsHarry McLaren
 
Best Practices for Splunk Deployments
Best Practices for Splunk DeploymentsBest Practices for Splunk Deployments
Best Practices for Splunk DeploymentsSplunk
 
SplunkLive! London 2017 - DevOps Powered by Splunk
SplunkLive! London 2017 - DevOps Powered by SplunkSplunkLive! London 2017 - DevOps Powered by Splunk
SplunkLive! London 2017 - DevOps Powered by SplunkSplunk
 
ABD208_Cox Automotive Empowered to Scale with Splunk Cloud & AWS and Explores...
ABD208_Cox Automotive Empowered to Scale with Splunk Cloud & AWS and Explores...ABD208_Cox Automotive Empowered to Scale with Splunk Cloud & AWS and Explores...
ABD208_Cox Automotive Empowered to Scale with Splunk Cloud & AWS and Explores...Amazon Web Services
 
How to Get on Top of Your Cloud Strategy
How to Get on Top of Your Cloud StrategyHow to Get on Top of Your Cloud Strategy
How to Get on Top of Your Cloud StrategyComcast Business
 
TechWiseTV Workshop: Cisco Hybrid Cloud Platform for Google Cloud
TechWiseTV Workshop:  Cisco Hybrid Cloud Platform for Google CloudTechWiseTV Workshop:  Cisco Hybrid Cloud Platform for Google Cloud
TechWiseTV Workshop: Cisco Hybrid Cloud Platform for Google CloudRobb Boyd
 
Splunk Discovery Day Milwaukee 9-14-17
Splunk Discovery Day Milwaukee 9-14-17Splunk Discovery Day Milwaukee 9-14-17
Splunk Discovery Day Milwaukee 9-14-17Splunk
 
Splunk Phantom, the Endpoint Data Model & Splunk Security Essentials App!
Splunk Phantom, the Endpoint Data Model & Splunk Security Essentials App!Splunk Phantom, the Endpoint Data Model & Splunk Security Essentials App!
Splunk Phantom, the Endpoint Data Model & Splunk Security Essentials App!Harry McLaren
 
SplunkLive! Zurich 2017 - Data Obfuscation in Splunk Enterprise
SplunkLive! Zurich 2017 - Data Obfuscation in Splunk EnterpriseSplunkLive! Zurich 2017 - Data Obfuscation in Splunk Enterprise
SplunkLive! Zurich 2017 - Data Obfuscation in Splunk EnterpriseSplunk
 

Similar to Clear the Mist from your Clouds with Splunk (20)

Splunk und Multi-Cloud
Splunk und Multi-CloudSplunk und Multi-Cloud
Splunk und Multi-Cloud
 
Splunk and Multicloud
Splunk and MulticloudSplunk and Multicloud
Splunk and Multicloud
 
Splunk and Multicloud
Splunk and Multicloud Splunk and Multicloud
Splunk and Multicloud
 
Securing the Enterprise/Cloud with Splunk at the Centre
Securing the Enterprise/Cloud with Splunk at the CentreSecuring the Enterprise/Cloud with Splunk at the Centre
Securing the Enterprise/Cloud with Splunk at the Centre
 
What's New with the Latest Splunk Platform Release
What's New with the Latest Splunk Platform ReleaseWhat's New with the Latest Splunk Platform Release
What's New with the Latest Splunk Platform Release
 
Splunk Cloud and Splunk Enterprise 7.2
Splunk Cloud and Splunk Enterprise 7.2 Splunk Cloud and Splunk Enterprise 7.2
Splunk Cloud and Splunk Enterprise 7.2
 
Splunk Cloud and Splunk Enterprise 7.2
Splunk Cloud and Splunk Enterprise 7.2 Splunk Cloud and Splunk Enterprise 7.2
Splunk Cloud and Splunk Enterprise 7.2
 
Splunk Cloud and Splunk Enterprise 7.2
Splunk Cloud and Splunk Enterprise 7.2Splunk Cloud and Splunk Enterprise 7.2
Splunk Cloud and Splunk Enterprise 7.2
 
Encontro anual para apresentação das novidades da .conf23
Encontro anual para apresentação das novidades da .conf23Encontro anual para apresentação das novidades da .conf23
Encontro anual para apresentação das novidades da .conf23
 
Alle Neuigkeiten im letzten Plattform Release
Alle Neuigkeiten im letzten Plattform ReleaseAlle Neuigkeiten im letzten Plattform Release
Alle Neuigkeiten im letzten Plattform Release
 
.conf Go Zurich 2022 - Platform Session
.conf Go Zurich 2022 - Platform Session.conf Go Zurich 2022 - Platform Session
.conf Go Zurich 2022 - Platform Session
 
Splunk .conf18 Updates, Config Add-on, SplDevOps
Splunk .conf18 Updates, Config Add-on, SplDevOpsSplunk .conf18 Updates, Config Add-on, SplDevOps
Splunk .conf18 Updates, Config Add-on, SplDevOps
 
Best Practices for Splunk Deployments
Best Practices for Splunk DeploymentsBest Practices for Splunk Deployments
Best Practices for Splunk Deployments
 
SplunkLive! London 2017 - DevOps Powered by Splunk
SplunkLive! London 2017 - DevOps Powered by SplunkSplunkLive! London 2017 - DevOps Powered by Splunk
SplunkLive! London 2017 - DevOps Powered by Splunk
 
ABD208_Cox Automotive Empowered to Scale with Splunk Cloud & AWS and Explores...
ABD208_Cox Automotive Empowered to Scale with Splunk Cloud & AWS and Explores...ABD208_Cox Automotive Empowered to Scale with Splunk Cloud & AWS and Explores...
ABD208_Cox Automotive Empowered to Scale with Splunk Cloud & AWS and Explores...
 
How to Get on Top of Your Cloud Strategy
How to Get on Top of Your Cloud StrategyHow to Get on Top of Your Cloud Strategy
How to Get on Top of Your Cloud Strategy
 
TechWiseTV Workshop: Cisco Hybrid Cloud Platform for Google Cloud
TechWiseTV Workshop:  Cisco Hybrid Cloud Platform for Google CloudTechWiseTV Workshop:  Cisco Hybrid Cloud Platform for Google Cloud
TechWiseTV Workshop: Cisco Hybrid Cloud Platform for Google Cloud
 
Splunk Discovery Day Milwaukee 9-14-17
Splunk Discovery Day Milwaukee 9-14-17Splunk Discovery Day Milwaukee 9-14-17
Splunk Discovery Day Milwaukee 9-14-17
 
Splunk Phantom, the Endpoint Data Model & Splunk Security Essentials App!
Splunk Phantom, the Endpoint Data Model & Splunk Security Essentials App!Splunk Phantom, the Endpoint Data Model & Splunk Security Essentials App!
Splunk Phantom, the Endpoint Data Model & Splunk Security Essentials App!
 
SplunkLive! Zurich 2017 - Data Obfuscation in Splunk Enterprise
SplunkLive! Zurich 2017 - Data Obfuscation in Splunk EnterpriseSplunkLive! Zurich 2017 - Data Obfuscation in Splunk Enterprise
SplunkLive! Zurich 2017 - Data Obfuscation in Splunk Enterprise
 

More from Splunk

.conf Go 2023 - Data analysis as a routine
.conf Go 2023 - Data analysis as a routine.conf Go 2023 - Data analysis as a routine
.conf Go 2023 - Data analysis as a routineSplunk
 
.conf Go 2023 - How KPN drives Customer Satisfaction on IPTV
.conf Go 2023 - How KPN drives Customer Satisfaction on IPTV.conf Go 2023 - How KPN drives Customer Satisfaction on IPTV
.conf Go 2023 - How KPN drives Customer Satisfaction on IPTVSplunk
 
.conf Go 2023 - Navegando la normativa SOX (Telefónica)
.conf Go 2023 - Navegando la normativa SOX (Telefónica).conf Go 2023 - Navegando la normativa SOX (Telefónica)
.conf Go 2023 - Navegando la normativa SOX (Telefónica)Splunk
 
.conf Go 2023 - Raiffeisen Bank International
.conf Go 2023 - Raiffeisen Bank International.conf Go 2023 - Raiffeisen Bank International
.conf Go 2023 - Raiffeisen Bank InternationalSplunk
 
.conf Go 2023 - På liv og død Om sikkerhetsarbeid i Norsk helsenett
.conf Go 2023 - På liv og død Om sikkerhetsarbeid i Norsk helsenett .conf Go 2023 - På liv og død Om sikkerhetsarbeid i Norsk helsenett
.conf Go 2023 - På liv og død Om sikkerhetsarbeid i Norsk helsenett Splunk
 
.conf Go 2023 - Many roads lead to Rome - this was our journey (Julius Bär)
.conf Go 2023 - Many roads lead to Rome - this was our journey (Julius Bär).conf Go 2023 - Many roads lead to Rome - this was our journey (Julius Bär)
.conf Go 2023 - Many roads lead to Rome - this was our journey (Julius Bär)Splunk
 
.conf Go 2023 - Das passende Rezept für die digitale (Security) Revolution zu...
.conf Go 2023 - Das passende Rezept für die digitale (Security) Revolution zu....conf Go 2023 - Das passende Rezept für die digitale (Security) Revolution zu...
.conf Go 2023 - Das passende Rezept für die digitale (Security) Revolution zu...Splunk
 
.conf go 2023 - Cyber Resilienz – Herausforderungen und Ansatz für Energiever...
.conf go 2023 - Cyber Resilienz – Herausforderungen und Ansatz für Energiever....conf go 2023 - Cyber Resilienz – Herausforderungen und Ansatz für Energiever...
.conf go 2023 - Cyber Resilienz – Herausforderungen und Ansatz für Energiever...Splunk
 
.conf go 2023 - De NOC a CSIRT (Cellnex)
.conf go 2023 - De NOC a CSIRT (Cellnex).conf go 2023 - De NOC a CSIRT (Cellnex)
.conf go 2023 - De NOC a CSIRT (Cellnex)Splunk
 
conf go 2023 - El camino hacia la ciberseguridad (ABANCA)
conf go 2023 - El camino hacia la ciberseguridad (ABANCA)conf go 2023 - El camino hacia la ciberseguridad (ABANCA)
conf go 2023 - El camino hacia la ciberseguridad (ABANCA)Splunk
 
Splunk - BMW connects business and IT with data driven operations SRE and O11y
Splunk - BMW connects business and IT with data driven operations SRE and O11ySplunk - BMW connects business and IT with data driven operations SRE and O11y
Splunk - BMW connects business and IT with data driven operations SRE and O11ySplunk
 
Splunk x Freenet - .conf Go Köln
Splunk x Freenet - .conf Go KölnSplunk x Freenet - .conf Go Köln
Splunk x Freenet - .conf Go KölnSplunk
 
Splunk Security Session - .conf Go Köln
Splunk Security Session - .conf Go KölnSplunk Security Session - .conf Go Köln
Splunk Security Session - .conf Go KölnSplunk
 
Data foundations building success, at city scale – Imperial College London
 Data foundations building success, at city scale – Imperial College London Data foundations building success, at city scale – Imperial College London
Data foundations building success, at city scale – Imperial College LondonSplunk
 
Splunk: How Vodafone established Operational Analytics in a Hybrid Environmen...
Splunk: How Vodafone established Operational Analytics in a Hybrid Environmen...Splunk: How Vodafone established Operational Analytics in a Hybrid Environmen...
Splunk: How Vodafone established Operational Analytics in a Hybrid Environmen...Splunk
 
SOC, Amore Mio! | Security Webinar
SOC, Amore Mio! | Security WebinarSOC, Amore Mio! | Security Webinar
SOC, Amore Mio! | Security WebinarSplunk
 
.conf Go 2022 - Observability Session
.conf Go 2022 - Observability Session.conf Go 2022 - Observability Session
.conf Go 2022 - Observability SessionSplunk
 
.conf Go Zurich 2022 - Keynote
.conf Go Zurich 2022 - Keynote.conf Go Zurich 2022 - Keynote
.conf Go Zurich 2022 - KeynoteSplunk
 
.conf Go Zurich 2022 - Security Session
.conf Go Zurich 2022 - Security Session.conf Go Zurich 2022 - Security Session
.conf Go Zurich 2022 - Security SessionSplunk
 
Inside SecOps at bet365
Inside SecOps at bet365 Inside SecOps at bet365
Inside SecOps at bet365 Splunk
 

More from Splunk (20)

.conf Go 2023 - Data analysis as a routine
.conf Go 2023 - Data analysis as a routine.conf Go 2023 - Data analysis as a routine
.conf Go 2023 - Data analysis as a routine
 
.conf Go 2023 - How KPN drives Customer Satisfaction on IPTV
.conf Go 2023 - How KPN drives Customer Satisfaction on IPTV.conf Go 2023 - How KPN drives Customer Satisfaction on IPTV
.conf Go 2023 - How KPN drives Customer Satisfaction on IPTV
 
.conf Go 2023 - Navegando la normativa SOX (Telefónica)
.conf Go 2023 - Navegando la normativa SOX (Telefónica).conf Go 2023 - Navegando la normativa SOX (Telefónica)
.conf Go 2023 - Navegando la normativa SOX (Telefónica)
 
.conf Go 2023 - Raiffeisen Bank International
.conf Go 2023 - Raiffeisen Bank International.conf Go 2023 - Raiffeisen Bank International
.conf Go 2023 - Raiffeisen Bank International
 
.conf Go 2023 - På liv og død Om sikkerhetsarbeid i Norsk helsenett
.conf Go 2023 - På liv og død Om sikkerhetsarbeid i Norsk helsenett .conf Go 2023 - På liv og død Om sikkerhetsarbeid i Norsk helsenett
.conf Go 2023 - På liv og død Om sikkerhetsarbeid i Norsk helsenett
 
.conf Go 2023 - Many roads lead to Rome - this was our journey (Julius Bär)
.conf Go 2023 - Many roads lead to Rome - this was our journey (Julius Bär).conf Go 2023 - Many roads lead to Rome - this was our journey (Julius Bär)
.conf Go 2023 - Many roads lead to Rome - this was our journey (Julius Bär)
 
.conf Go 2023 - Das passende Rezept für die digitale (Security) Revolution zu...
.conf Go 2023 - Das passende Rezept für die digitale (Security) Revolution zu....conf Go 2023 - Das passende Rezept für die digitale (Security) Revolution zu...
.conf Go 2023 - Das passende Rezept für die digitale (Security) Revolution zu...
 
.conf go 2023 - Cyber Resilienz – Herausforderungen und Ansatz für Energiever...
.conf go 2023 - Cyber Resilienz – Herausforderungen und Ansatz für Energiever....conf go 2023 - Cyber Resilienz – Herausforderungen und Ansatz für Energiever...
.conf go 2023 - Cyber Resilienz – Herausforderungen und Ansatz für Energiever...
 
.conf go 2023 - De NOC a CSIRT (Cellnex)
.conf go 2023 - De NOC a CSIRT (Cellnex).conf go 2023 - De NOC a CSIRT (Cellnex)
.conf go 2023 - De NOC a CSIRT (Cellnex)
 
conf go 2023 - El camino hacia la ciberseguridad (ABANCA)
conf go 2023 - El camino hacia la ciberseguridad (ABANCA)conf go 2023 - El camino hacia la ciberseguridad (ABANCA)
conf go 2023 - El camino hacia la ciberseguridad (ABANCA)
 
Splunk - BMW connects business and IT with data driven operations SRE and O11y
Splunk - BMW connects business and IT with data driven operations SRE and O11ySplunk - BMW connects business and IT with data driven operations SRE and O11y
Splunk - BMW connects business and IT with data driven operations SRE and O11y
 
Splunk x Freenet - .conf Go Köln
Splunk x Freenet - .conf Go KölnSplunk x Freenet - .conf Go Köln
Splunk x Freenet - .conf Go Köln
 
Splunk Security Session - .conf Go Köln
Splunk Security Session - .conf Go KölnSplunk Security Session - .conf Go Köln
Splunk Security Session - .conf Go Köln
 
Data foundations building success, at city scale – Imperial College London
 Data foundations building success, at city scale – Imperial College London Data foundations building success, at city scale – Imperial College London
Data foundations building success, at city scale – Imperial College London
 
Splunk: How Vodafone established Operational Analytics in a Hybrid Environmen...
Splunk: How Vodafone established Operational Analytics in a Hybrid Environmen...Splunk: How Vodafone established Operational Analytics in a Hybrid Environmen...
Splunk: How Vodafone established Operational Analytics in a Hybrid Environmen...
 
SOC, Amore Mio! | Security Webinar
SOC, Amore Mio! | Security WebinarSOC, Amore Mio! | Security Webinar
SOC, Amore Mio! | Security Webinar
 
.conf Go 2022 - Observability Session
.conf Go 2022 - Observability Session.conf Go 2022 - Observability Session
.conf Go 2022 - Observability Session
 
.conf Go Zurich 2022 - Keynote
.conf Go Zurich 2022 - Keynote.conf Go Zurich 2022 - Keynote
.conf Go Zurich 2022 - Keynote
 
.conf Go Zurich 2022 - Security Session
.conf Go Zurich 2022 - Security Session.conf Go Zurich 2022 - Security Session
.conf Go Zurich 2022 - Security Session
 
Inside SecOps at bet365
Inside SecOps at bet365 Inside SecOps at bet365
Inside SecOps at bet365
 

Recently uploaded

The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdfThe Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdfEnterprise Knowledge
 
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot TakeoffStrategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoffsammart93
 
Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024The Digital Insurer
 
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking MenDelhi Call girls
 
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptxHampshireHUG
 
Scaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationScaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationRadu Cotescu
 
Presentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreterPresentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreternaman860154
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerThousandEyes
 
Handwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed textsHandwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed textsMaria Levchenko
 
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024The Digital Insurer
 
How to convert PDF to text with Nanonets
How to convert PDF to text with NanonetsHow to convert PDF to text with Nanonets
How to convert PDF to text with Nanonetsnaman860154
 
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...Igalia
 
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...Neo4j
 
08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking Men08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking MenDelhi Call girls
 
IAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI SolutionsIAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI SolutionsEnterprise Knowledge
 
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptxEIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptxEarley Information Science
 
Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024The Digital Insurer
 
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProduct Anonymous
 
presentation ICT roal in 21st century education
presentation ICT roal in 21st century educationpresentation ICT roal in 21st century education
presentation ICT roal in 21st century educationjfdjdjcjdnsjd
 
🐬 The future of MySQL is Postgres 🐘
🐬  The future of MySQL is Postgres   🐘🐬  The future of MySQL is Postgres   🐘
🐬 The future of MySQL is Postgres 🐘RTylerCroy
 

Recently uploaded (20)

The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdfThe Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
 
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot TakeoffStrategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
 
Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024
 
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
 
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
 
Scaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationScaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organization
 
Presentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreterPresentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreter
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 
Handwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed textsHandwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed texts
 
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
 
How to convert PDF to text with Nanonets
How to convert PDF to text with NanonetsHow to convert PDF to text with Nanonets
How to convert PDF to text with Nanonets
 
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
 
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
 
08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking Men08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking Men
 
IAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI SolutionsIAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI Solutions
 
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptxEIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
 
Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024
 
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
 
presentation ICT roal in 21st century education
presentation ICT roal in 21st century educationpresentation ICT roal in 21st century education
presentation ICT roal in 21st century education
 
🐬 The future of MySQL is Postgres 🐘
🐬  The future of MySQL is Postgres   🐘🐬  The future of MySQL is Postgres   🐘
🐬 The future of MySQL is Postgres 🐘
 

Clear the Mist from your Clouds with Splunk

  • 1. © 2019 SPLUNK INC.© 2019 SPLUNK INC. Clear the Mist from your Clouds with Splunk SplunkLive London - June 2019 Yuval Tenenbaum Director – SE Architects EMEA
  • 2. © 2017 SPLUNK INC. Migration To Cloud & Hybrid Cloud Insights is Top Of Mind
  • 3. © 2019 SPLUNK INC. ► Enables Least privileged model at the highest operational control ► Mitigates Risk – lower the ‘blast radius’ of impactful events ► Achieve Agility- deploy & run environments programmatically at scale ► Cost optimisation- clear ‘line of sight’ into the cost of running workloads Hybrid Cloud – Think Differently Legacy Model Least privileged
  • 4. © 2019 SPLUNK INC. ► Split Investment may slow down your cloud adoption – Spreading your resources across multiple clouds means that you may not get critical mass or a fast ROI ► Portability - How many of us will actually move workloads around? ► Cloud Broker concept – Putting a “bloatware” between you and your cloud api’s instead of working natively with these cloud API’s Is it Really All Good Stuff? I used to be indecisive now I’m definitely going multi- cloud
  • 5. © 2019 SPLUNK INC. Cloud - Same Challenges-Different Environments ► Security • Are we firewalled correctly? • Do we use all necessary security features? ► Compliance • Are we following all published standards? ► Networking • Placed servers on the correct network? ► Financial • Stayed within budget? ► Capacity Planning • Used resources optimally? And all of that in a decentralized Model…
  • 6. © 2019 SPLUNK INC. Customer experience??? SAAS Hybrid Everything - What happens when we stack them? ON PREMISES Legacy systems (Mainframe…) Facilities Dev/PreProd Storage Backup Archive DR Security VMs Containers Micro services AWS (Application 1)Access / Security Database StorageDev Compute Containers App engine GCP (Big Data project 1) Dataflow AWS (Archive) Azure (Application 1) VMs Database VM sets Traffic mger
  • 7. © 2017 SPLUNK INC. So How Can Splunk Clear up this Cloudy Mist? Know your Clouds…..
  • 8. © 2019 SPLUNK INC. ► Splunk has working relationships with AWS, Azure, and GCP ► We have customers successfully running Splunk Enterprise BYOL within AWS, Azure, and GCP ► We have proven strategies to get data in from AWS, Azure, and GCP Cloud Vendor Relationships
  • 9. © 2017 SPLUNK INC. Splunk’s Approach to Hybrid Cloud One Consolidated Solution Manage Hybrid Infrastructure Cost, Capacity and Resource Management Cloud Migration Splunk takes the place of the multitude of monitoring tools because sometimes one is better than many. Deploy Splunk in Hybrid setup (on-prem, saas, byol) and deal with Hybrid infrastructure complex monitoring Understand how your resources are performing – and how many are being used – then optimize utilization and billing. Get visibility at all stages of the migration process (landing zones)– whether before, during or long after.
  • 10. © 2017 SPLUNK INC. In the Beginning…… Cloud Migration
  • 11. © 2019 SPLUNK INC. What Customers Want To Achieve When Migrating to the Cloud ► Build - Differentiate yourself by building unique and valuable services ► Move Fast - From initial idea to a service which can be monetized ► Stay Secure - Make sure that what we build is secure and compliant ▶ Manage Cost – Control what you spend and gain visibility into future cost
  • 12. © 2019 SPLUNK INC. Path To Successful Cloud Migration Measure the baseline user experience and performance, as well as define acceptable post-migration levels. Security assessment – build a well architected and compliant landing zones Performance metrics should be closely monitored & compared to the baseline. Throughout the migration, end-to-end monitoring can help SecOps teams stay ahead of any potential risks. Continuous monitoring should be used to measure acceptable metrics and success. Leverage a platform that shows insights into cost, shared services, monitoring, Security & compliance BEFORE DURING AFTER
  • 13. © 2019 SPLUNK INC. Challenges With Building & Maintaining Landing Zones ▶ Define & maintain an Account structure ▶ Define your network architecture and monitor it continuously ▶ Define & maintain a security governance and compliance baseline Migrate Land Operate & Optimize
  • 14. © 2019 SPLUNK INC. Additional Considerations ▶ Define & maintain centralized logging ▶ Define & maintain Cost Allocation
  • 15. © 2019 SPLUNK INC. How Can Splunk Help (1)? ▶ Tell you who is accessing your accounts, from where and what are they doing?
  • 16. © 2019 SPLUNK INC. How Can Splunk Help (2)? ▶ Tell you if anyone is breaking your security policies? • Is encryption used everywhere • Has the root account has MFA enabled • Suspicious AWS S3 Activities • IAM Password policies are kept as you defined in your security baseline?
  • 17. © 2019 SPLUNK INC. How Can Splunk Help (3)? ▶ Help you understand your network topology and gain visibility into who is trying to access it ▶ Help you gain visibility into performance & right sizing of your key workloads ▶ Help you understand historic and future cost
  • 18. © 2019 SPLUNK INC. AWS Analytic Stories - ES Content Updates
  • 19. © 2019 SPLUNK INC. Migration Dashboards
  • 20. © 2017 SPLUNK INC. So How Do We Collect Cloud Data to do this Hybrid Monitoring?
  • 21. © 2017 SPLUNK INC. Getting Data In Cloud Patterns
  • 22. © 2017 SPLUNK INC. General Getting Data In Routes Pull or Push, Add-Ons or Serverless Poll/Request API Data Data Cloud Serverless Code Add-On HEC “Push”
  • 23. © 2017 SPLUNK INC. GDI : AWS
  • 24. © 2019 SPLUNK INC. It May Look a Bit Complicated
  • 25. © 2019 SPLUNK INC. ► AWS Config can be pulled with a Splunk Heavy Forwarder with the SQS Based S3. Anything via CloudWatch Logs or CW events, can be pushed with Kinesis Firehose to Splunk AWS Pull vs. Push Config Events SNS Topic Notification SQS Subscription Notification Pulls Event from S3 Bucket Splunk Pull SQS Notification HEC PushPull CloudWatch Logs
  • 26. © 2019 SPLUNK INC. AWS Source Matrix There are many options to GDI in AWS but Splunk can help Data Type Recommended Input Type Billing Billing CloudWatch CloudWatch CloudFront Access Logs SQS based S3 Config SQS based S3 Config Rules Config Rules Description Description ELB Access Logs SQS based S3 Inspector Inspector CloudTrail SQS Based S3 S3 access logs SQS Based S3 VPC Flow Logs (CW Logs) Kinesis With SQS Based S3 you can scale out data collection by configuring multiple inputs to ingest logs from the same S3 bucket without creating duplicate data. Kinesis Firehose is recommended for CloudWatch Logs data collection
  • 27. © 2017 SPLUNK INC. GDI : Azure & O365
  • 28. © 2019 SPLUNK INC. 3 Log Types in Azure 1) Control/Management, 2) Data Plane, 3) Processed Events Control: System Configuration and Management Data Plane: Provisioned Service and Diagnostic Data Processed Events: Alerts & Recommendations
  • 29. © 2019 SPLUNK INC. { REST } Storage Event Hub
  • 30. © 2019 SPLUNK INC. ► Splunk can pull data from Azure using a Heavy Forwarder and collect data from either the MS Blob or a REST API using the modular input. Azure can push data using the Event Hub to Azure Functions which can be sent to Splunk’s HEC. Azure Pull vs. Push MSBlob HEC PushPull Splunk Indexers Activity Monitor Event Hub Azure Function Event Hub
  • 31. © 2019 SPLUNK INC. Azure Add-on Landscape
  • 32. © 2019 SPLUNK INC. Getting O365 Data In Azure Active Directory Application OAUTH2 REST Splunk Add-on for Microsoft O365 Office 365
  • 33. © 2017 SPLUNK INC. GDI : Google Cloud
  • 34. © 2019 SPLUNK INC. Getting GCP Data In REST Splunk Add-on for Google Cloud Platform Billing PubSub Monitoring StackDriver
  • 35. © 2019 SPLUNK INC. ► Initial: • Most customers will generate around 1-10GB when they are setting up their Public Cloud deployments and enabling services. • As they mature - 10-50GB. ► More instances and deployed apps in Cloud, 50-200GB. ► Most customers are 100-200GB / day of Public Cloud data. ► All-in Cloud Companies : 500GB-1TB range. ► Less common >1TB ► O365 - ~400 to 500 KB per user per day (50K users = 25 GB/day) ► Best way to analyze the amount of data is to spin-off a test environment and look at the numbers. How Much Data?
  • 36. © 2017 SPLUNK INC. Collection Deployment Architectures
  • 37. © 2019 SPLUNK INC. ► Central Splunk Instance • One Instance to manage – lower “Instance/Storage” costs • Data egress cost considerations (data transfers from each cloud) • Local or Distributed Heavy Forwarders ► Splunk Instance per Cloud, 1 “Master” view • One Instance in each Cloud – potential higher “Instance/Storage” cost • Management of Splunk in each Cloud • “Master” Search Head needed for Hybrid Search – latency impact • Lower egress cost ► Hybrid • Mix of both options balancing out Costs/Hybrid Search Deployment Architecture 3 Patterns
  • 38. © 2019 SPLUNK INC. Option 1 Public/Private Cloud / Splunk Cloud Single Splunk InstanceHeavy Forwarder (Add-On) Heavy Forwarder (Add-On) Heavy Forwarder (Add-On) Note Options for Serverless/HEC input direct to Central Instance Cloud Data
  • 39. © 2019 SPLUNK INC. Option 2 Public/Private Cloud Distributed Hybrid SearchSplunk Indexer(s) Splunk Indexer(s) Splunk Indexer(s) Search Head Search Results
  • 40. © 2019 SPLUNK INC. Option 3 Distributed Search Splunk Indexer(s) & Master Search Splunk Indexer(s) Heavy Forwarder (Add-On) Cloud Data Search Results
  • 41. © 2019 SPLUNK INC.© 2017 SPLUNK INC. © 2017 SPLUNK INC. OUR MISSION ….Including Cloud data!
  • 42. © 2019 SPLUNK INC. Hybrid Monitoring Collect & store machine data generated by on-premises IT sources and public cloud sources simultaneously, and can correlate across both to monitor, alert, analyse, troubleshoot and investigate.
  • 43. © 2017 SPLUNK INC. Pulling it all together: Example Cloud Innovation, Integration and Use Case AWS Security Hub + Splunk Phantom Bi-Directional Integration
  • 44. © 2019 SPLUNK INC. AWS Security Hub - Findings
  • 45. © 2019 SPLUNK INC. Phantom - EC2 Instance- Investigate & Notify
  • 46. © 2019 SPLUNK INC. Geo Location & IP Reputation
  • 47. © 2019 SPLUNK INC. Prompting The Analyst- Quarantine Instance
  • 48. © 2019 SPLUNK INC. Phantom- Isolate ES2 Instance Playbook
  • 50. © 2019 SPLUNK INC. Back To AWS Security Hub
  • 51. © 2019 SPLUNK INC.© 2019 SPLUNK INC. Don't forget to rate this session in the .conf18 mobile app Thank You.