Network Forensics for Splunk, an Emulex presentation

1,840 views

Published on

These slides were recently presented at a partner event held by Marquest Ltd.

Published in: Technology
  • Be the first to comment

  • Be the first to like this

Network Forensics for Splunk, an Emulex presentation

  1. 1. Network Forensics for Splunkers Matt Walmsley, EMEA Marketing Tom Jones, Sales Engineer Emulex, Endace Division
  2. 2. Today’s Topics Time to Resolution Splunk Connector 2 Network Recording Q&A Emulex Confidential - © 2013 Emulex Corporation
  3. 3. The Networking Wheel of Life! APM NPM IPS / IDS Firewall WAN Op QoS 3 Recording & Forensics Analysis & Intervention Emulex Confidential - © 2013 Emulex Corporation
  4. 4. # Events Time is… Money / Safety / Advantage / Reputation • Reduce Slow To Fix Items • Identify Root Cause & Fix Savings Time to Resolution
  5. 5. The 3 E of Great Interventions Skills & Knowledge Experience & Context Evidence Understanding • Efficient • Economic • Effective Decision Making Intervention 5 Emulex Confidential - © 2013 Emulex Corporation
  6. 6. Collecting Evidence - Recording Evolution Interesting Vs. Important 6 Specialised Vs. Generalised Emulex Confidential - © 2013 Emulex Corporation
  7. 7. Intelligent Network Recording Generalised Enterprise Banking & Trading National Security Specialised 7 Emulex Confidential - © 2013 Emulex Corporation
  8. 8. Endace – The Packet Capture Experts World leader in network recording 10+ years selling security solutions to global clients – Govt, Traders, Telco & Enterprise Reputation for accuracy, scalability & performance A division of Emulex 8 Emulex Confidential - © 2013 Emulex Corporation
  9. 9. Intelligent Network Recording - Use Cases Application Performance Management Custom Security Operations Legal Intercept Network Infrastructure Operations Audit & Compliance 9 Emulex Confidential - © 2013 Emulex Corporation
  10. 10. Intelligent Network Recording - Deployment Intelligent Network Recorder “Probe” Network Traffic Analysis App • High Speed, High Fidelity Packet Capture Appliance • Packet Processing and Indexing • Storage and Retrieval • Traffic Profiling & Visualisation • Packet Analysis • Integration with other networking tools 10 Emulex Confidential - © 2013 Emulex Corporation
  11. 11. Endace Network Recording - Infrastructure EndaceProbe™ INR EndaceAccess™ Endace Open Hosting Platform(ODE) High Performance Intelligent Network Recording Network Visibility Headend Hosting Platform for Monitoring Apps Up to 64 TB storage Mix of 1 and 10GbE ports Allows EndaceProbe INRs/ODE to scale to 40 and 100GbE 8x1GbE or 4x10GbE Ports Up to 16 TB internal storage; FC support for SAN 11 Emulex Confidential - © 2013 Emulex Corporation Endace NetFlow Generator High-Speed NetFlow Generation for 10GbE Networks 4x10GbE Ports
  12. 12. How Much Network Visibility Do You Need? High Definition – Endace Vision • See microbursts • Know exactly what data has been compromised • Identify issues impacting services and security application performance Low Definition • 12 Emulex Confidential - © 2013 Emulex Corporation The visibility most solutions provide
  13. 13. EndaceVision - Actionable Insight Bandwidth Over Time TCP/IP Conversations Traffic over time 13 Traffic breakdown and analysis Top Talkers Workflow Emulex Confidential - © 2013 Emulex Corporation
  14. 14. EndaceVision - Integrated and Open APM NPM IDS HFT EndaceFusion EndaceProbe Integration with “best of breed” solutions – API and hypervisor – All tools share data from same secure location in datacenter – Automated workflow, “pivot to packets” speeds up issue resolution Lower Investment While Increasing ROI – Reduce device count – Plan and train staff on the tools that fit customer situation best 14 Emulex Confidential - © 2013 Emulex Corporation
  15. 15. Endace Solution - Key Features • Market Leading Performance • 100% High fidelity packet capture • 10/100/1G/10G/40G/100GbE • 64TB on board storage • FC SAN offload • Multi-unit “Sledging” • Distributed Recording Fabric • Multiple EndaceProbe INRs, single recording fabric • Traffic search and visualisation • Diverse, concurrent multiple uses • Open and Flexible Integration • Endace dock hypervisor • RESTfull API • Endace Fusion solution ecosystem 15 Emulex Confidential - © 2013 Emulex Corporation
  16. 16. Splunk & Endace – Macro and Micro Log lines are a summary or interpretation of an event Packets are the ground truth from which these are derived Fusion connector links the two with a single click Endace’s depth complements Splunk’s breadth 16 Emulex Confidential - © 2013 Emulex Corporation
  17. 17. Feeding and Enabling Splunk EndaceProbe INR Generated Logs and Netflow Events 17 Splunk Generated Enquiries Emulex Confidential - © 2013 Emulex Corporation
  18. 18. Optimising Event Management Workflow Event Occurrence 18 Splunk Alert Click to Traffic Search Request Emulex Confidential - © 2013 Emulex Corporation Packet drill down and inspection Traffic Analysis and Visualisation
  19. 19. Example Case – Finance / Trading Solution Context • Network performance is critical to $ services • Latency and outage intolerant • Multiple management tools Solution • Integrated network monitoring and security for a low latency 10GbE network Products • Splunk! • EndaceProbe™ INR • Endace Fusion Connector for Splunk • EndaceVision™ 19 Key Benefits • Greater insight into critical network issues • Reduce time-to-resolution (TTR) • Lower operational expenditures (OPEX) Emulex Confidential - © 2013 Emulex Corporation
  20. 20. Real World Feedback “While consolidating network monitoring and security tools was the primary need for the EndaceProbe INR, it was put to work even before the official deployment. the pilot and immediately discovered a security breach that had gone undetected with their existing tools, providing an immediate return on investment for the EndaceProbe INR 7000.” “The EndaceProbe INR has been 100% reliable for us and we are impressed with its robust capabilities. We use it extensively and, coupled with the Fusion Connector for Splunk, are extremely happy with the results.” Global Head of Networks 20 Emulex Confidential - © 2013 Emulex Corporation
  21. 21. Endace Helps You Enable the “3 E” Understand macro and micro situation Reduce Time to Resolution Efficient Economic Effective Stop Recurrent Events 21 Reduce slow / hard to fix items Fix Route Cause Emulex Confidential - © 2013 Emulex Corporation
  22. 22. Which Means You Get… Less stress, improved results Uninterrupted weekends and evenings Happy family, boss and stakeholders 22 Emulex Confidential - © 2013 Emulex Corporation
  23. 23. Resources & Info www.emulex.com Video 23 Solution Brief Blog www.marquest.com Emulex Confidential - © 2013 Emulex Corporation Splunk Connector App Testing Brief
  24. 24. Questions? Thank you for your attention
  25. 25. 25 Emulex Confidential - © 2013 Emulex Corporation

×