SlideShare a Scribd company logo
Copyright © 2016 Splunk Inc.
Gary Hayslip
Deputy Director, CISO
2
About the City of San Diego
• “America’s Finest City”
• U.S. 8th largest city
• 11,000+ employees
• $4 billion business
• 1.5 Million Citizens
• 24 Networks
• 40,000 endpoints
• 4 Millions attacks per week
3
About Me
• Chief Information Security Officer
(CISSP, CISA, CRISC, CCSK)
• Background in DOD and US Navy
• Responsible for developing and executing
city-wide security strategy
• Creating “risk-aware” culture that protects
city and personal information resources
I am a World of Warcraft gamer
Favorite Splunk T-shirt – “Taking the SH out
of IT”
4
Before Splunk: Chaos
• No visibility, no coordination, no control
• IT was outsourced to a city-owned non-profit
• No documentation; no strategic plan
• Lacked insight into networking, data analysis,
and who was doing what
• No security operation center; the security of the
networks was uncoordinated.
• Business impact
• Inefficiencies from too many networks and
disparate technologies duct-taped together
• Extreme vulnerability to cyber threats
• Voters were insisting on managed services
“Nothing was
documented and there
was no strategic plan. It
was like the Wild, Wild
West and the city was
just throwing money at
issues.”
5
Choosing Splunk
• Selection criteria:
• Prior experience and knowledge
• Good ranking on Gartner
• Able to handle our massive data streams on one
platform
• Strong track record of interfacing smoothly with
other products (we have 26+)
• Success meant bringing together disparate
systems and data into one integrated,
managed platform “Visibility = Action”
• Splunk expands to meet evolving needs
“Based on
Splunk’s track
record, I wasn’t
interested in
anybody else.”
Splunk at City of San Diego
• 100 GB license for production
• Splunk Enterprise Security
• 33 Splunk environments
• 1 clustered indexers, 25 forwarders
• 24 networks, a billion packets/month
40,000 endpoints, petabytes of data
• 90% of the SOC owned by city, 10% by
service provider Atos
6
25 Universal Forwarders
1 Indexers
1 Search Heads + 1 Deployment Servers
Use of Splunk at City of San Diego
Data / Log Visibility
Application Management
Security Reporting
Threat Detection
Analytics / Dashboards
8
End-to-End Visibility
• We now route all logs and manage multiple data
sources and apps on one platform
(Tenable, ActiveDirectory, networks audit server)
• We have visibility into our operations to function
effectively
• Achieved audit capability and intel into our
networks (Varonis tool, Netskope, Netwrix)
• With Splunk, we can create dashboards for any
function and see information in real time
“Splunk has the
ability to slice
and dice the
information to
give us the
visibility we
need.”
9
Security Reporting
• Splunk supports our large data volume
(100GB/hour, 1 Billion packets/month - - >
adds up to a petabyte of data)
• Security dashboard opens visibility across the
network & shows management “what’s going on
today in cyber”
• I can translate the ton of paperwork on my desk
into building meaningful metrics
• Visibility lets us protect the perimeter to its “BYOD”
end points
“Security goes
beyond my
perimeter, which
is no longer just
the firewalls; it’s
the bank of mobile
phones my
employees are
walking around
with.”
10
Threat Detection & Response
• We experience 4 million attacks/week (including
international countries & “hacktivists”)
• With Splunk Enterprise Security, we:
• Detect, investigate, scope and respond to threats
• Quarantine dangerous files in minutes
• When Mayor’s office hit with TeslaCrypt attack, we:
• Detected and had machine off network within 20 minutes
• Quickly protected critical folders (treasury, fire depts)
• Completely remediated and got back up and running in 3.5
hours (prior, would have taken several days)
“After a
TeslaCrypt
attack, we
identified the
effected
machine and
pulled it off
network in
minutes.”
11
Application Management
• We manage 26 apps and plug-ins in Splunk
• Able to interface with components like:
• Nessus
• Tenable
• Varonis
• Cisco
• ActiveDirectory
• SCADA, ICS networks
• For our diverse needs, there was no other
choice
“Splunk was
the right size
Lego in the
box for the
puzzle we are
building.”
12
Analytics, Dashboards, Reports
• Splunk gives us (multiple teams) a single pane and
point of access for our data
• Dashboards and reports to give full views across the
environment are in progress
• Able to view employee use of city data on cloud
solutions (mobile device, cloud storage)
• Future projects - see analytic reports on public
operations and functions (emergency teams, stop
lights, traffic)
• Reports drive more effective business management
decisions and practices
“I can show my
mayor and COO
how many attacks
we’ve blocked, how
many tickets we’re
handling, what’s
going on across the
network.”
13
City of San Diego Use Cases
Daily Operations
Network Behavior Analytics
Continuous Monitoring
Data Governance
14
Users Across City of San Diego
Enterprise networks
HVAC systems
Libraries
Police and fire departments, 911 dispatchers
Financial, medical (HIPAA), PCI data
GPS networks
Sanitation and utilities
Golf courses
15
Splunk Words to the Wise….
• Don’t underestimate the amount of support
you need—add another 25%
• Plan for growth
• Start with a trial version and take the training
• Devote the effort to get the most out of the
solution
• When building out and adding other vendors:
• Always ask, “Can you Splunk it?”, “Do you have a
Splunk App?”
• If the answer is “no,” don’t buy it
16
Splunking Ahead….
• We have a 5-year road map
• We plan to share our success by
introducing Splunk to other City
departments (Splunk Day)
• We want to expand to the cloud
• Our dream is to have Splunk’s versatility
touch every aspect of City operations, for
both ingress and egress
17
Splunk Successes
• “Aha” moment – Clear usage detail of our city phones
• For years our vendor couldn’t give us this information
• Took a class on using Splunk, and got a clear report showing phone charges
and details by department - That alone paid for the class!
• We have immediate visibility into our data
• High level of detail, across multiple functions and departments
• We can create reports that improve productivity and help reduce
costs
• Threat protection systems have saved the city from critical data
breaches
17
Thank You

More Related Content

Similar to City of San Diego Customer Presentation

SplunkLive! Austin Customer Presentation - Baylor
SplunkLive! Austin Customer Presentation - BaylorSplunkLive! Austin Customer Presentation - Baylor
SplunkLive! Austin Customer Presentation - Baylor
Splunk
 
SplunkLive! Milano 2016 - Splunk Plenary Session
SplunkLive! Milano 2016 - Splunk Plenary SessionSplunkLive! Milano 2016 - Splunk Plenary Session
SplunkLive! Milano 2016 - Splunk Plenary Session
Splunk
 
Splunk in the Cisco Unified Computing System (UCS)
Splunk in the Cisco Unified Computing System (UCS) Splunk in the Cisco Unified Computing System (UCS)
Splunk in the Cisco Unified Computing System (UCS)
Splunk
 
Getting Started with Splunk Breakout Session
Getting Started with Splunk Breakout SessionGetting Started with Splunk Breakout Session
Getting Started with Splunk Breakout Session
Splunk
 
Splunk and Cisco UCS Breakout Session
Splunk and Cisco UCS Breakout SessionSplunk and Cisco UCS Breakout Session
Splunk and Cisco UCS Breakout Session
Splunk
 
Splunk at Sabre
Splunk at SabreSplunk at Sabre
Splunk at Sabre
Splunk
 
Splunk @ HomeAway
Splunk @ HomeAwaySplunk @ HomeAway
Splunk @ HomeAway
Splunk
 
Customer Presentation, FirstSolar
Customer Presentation, FirstSolarCustomer Presentation, FirstSolar
Customer Presentation, FirstSolar
Splunk
 
Customer Presentation - Telus
Customer Presentation - TelusCustomer Presentation - Telus
Customer Presentation - Telus
Splunk
 
SplunkLive! Paris 2016 - Plenary session
SplunkLive! Paris 2016 - Plenary sessionSplunkLive! Paris 2016 - Plenary session
SplunkLive! Paris 2016 - Plenary session
Splunk
 
Harness the Power of Big Data with Oracle
Harness the Power of Big Data with OracleHarness the Power of Big Data with Oracle
Harness the Power of Big Data with OracleSai Janakiram Penumuru
 
NHS Choices: Managing complex infrastructure to deliver critical online services
NHS Choices: Managing complex infrastructure to deliver critical online servicesNHS Choices: Managing complex infrastructure to deliver critical online services
NHS Choices: Managing complex infrastructure to deliver critical online services
Splunk
 
Introduction to Neo4j
Introduction to Neo4jIntroduction to Neo4j
Introduction to Neo4j
Neo4j
 
Symantec_2-4-5 nov 2010
Symantec_2-4-5 nov 2010Symantec_2-4-5 nov 2010
Symantec_2-4-5 nov 2010Agora Group
 
SplunkLive! Austin Customer Presentation - Xerox
SplunkLive! Austin Customer Presentation - XeroxSplunkLive! Austin Customer Presentation - Xerox
SplunkLive! Austin Customer Presentation - Xerox
Splunk
 
Getting Started with Splunk Breakout Session
Getting Started with Splunk Breakout SessionGetting Started with Splunk Breakout Session
Getting Started with Splunk Breakout Session
Splunk
 
Rapidly Improving Security Posture - CanDeal
Rapidly Improving Security Posture - CanDealRapidly Improving Security Posture - CanDeal
Rapidly Improving Security Posture - CanDeal
Splunk
 
Keynote: GraphTour Toronto
Keynote: GraphTour TorontoKeynote: GraphTour Toronto
Keynote: GraphTour Toronto
Neo4j
 
Splunk @ Adobe
Splunk @ AdobeSplunk @ Adobe
Splunk @ Adobe
Splunk
 
Streaming Cyber Security into Graph: Accelerating Data into DataStax Graph an...
Streaming Cyber Security into Graph: Accelerating Data into DataStax Graph an...Streaming Cyber Security into Graph: Accelerating Data into DataStax Graph an...
Streaming Cyber Security into Graph: Accelerating Data into DataStax Graph an...
Keith Kraus
 

Similar to City of San Diego Customer Presentation (20)

SplunkLive! Austin Customer Presentation - Baylor
SplunkLive! Austin Customer Presentation - BaylorSplunkLive! Austin Customer Presentation - Baylor
SplunkLive! Austin Customer Presentation - Baylor
 
SplunkLive! Milano 2016 - Splunk Plenary Session
SplunkLive! Milano 2016 - Splunk Plenary SessionSplunkLive! Milano 2016 - Splunk Plenary Session
SplunkLive! Milano 2016 - Splunk Plenary Session
 
Splunk in the Cisco Unified Computing System (UCS)
Splunk in the Cisco Unified Computing System (UCS) Splunk in the Cisco Unified Computing System (UCS)
Splunk in the Cisco Unified Computing System (UCS)
 
Getting Started with Splunk Breakout Session
Getting Started with Splunk Breakout SessionGetting Started with Splunk Breakout Session
Getting Started with Splunk Breakout Session
 
Splunk and Cisco UCS Breakout Session
Splunk and Cisco UCS Breakout SessionSplunk and Cisco UCS Breakout Session
Splunk and Cisco UCS Breakout Session
 
Splunk at Sabre
Splunk at SabreSplunk at Sabre
Splunk at Sabre
 
Splunk @ HomeAway
Splunk @ HomeAwaySplunk @ HomeAway
Splunk @ HomeAway
 
Customer Presentation, FirstSolar
Customer Presentation, FirstSolarCustomer Presentation, FirstSolar
Customer Presentation, FirstSolar
 
Customer Presentation - Telus
Customer Presentation - TelusCustomer Presentation - Telus
Customer Presentation - Telus
 
SplunkLive! Paris 2016 - Plenary session
SplunkLive! Paris 2016 - Plenary sessionSplunkLive! Paris 2016 - Plenary session
SplunkLive! Paris 2016 - Plenary session
 
Harness the Power of Big Data with Oracle
Harness the Power of Big Data with OracleHarness the Power of Big Data with Oracle
Harness the Power of Big Data with Oracle
 
NHS Choices: Managing complex infrastructure to deliver critical online services
NHS Choices: Managing complex infrastructure to deliver critical online servicesNHS Choices: Managing complex infrastructure to deliver critical online services
NHS Choices: Managing complex infrastructure to deliver critical online services
 
Introduction to Neo4j
Introduction to Neo4jIntroduction to Neo4j
Introduction to Neo4j
 
Symantec_2-4-5 nov 2010
Symantec_2-4-5 nov 2010Symantec_2-4-5 nov 2010
Symantec_2-4-5 nov 2010
 
SplunkLive! Austin Customer Presentation - Xerox
SplunkLive! Austin Customer Presentation - XeroxSplunkLive! Austin Customer Presentation - Xerox
SplunkLive! Austin Customer Presentation - Xerox
 
Getting Started with Splunk Breakout Session
Getting Started with Splunk Breakout SessionGetting Started with Splunk Breakout Session
Getting Started with Splunk Breakout Session
 
Rapidly Improving Security Posture - CanDeal
Rapidly Improving Security Posture - CanDealRapidly Improving Security Posture - CanDeal
Rapidly Improving Security Posture - CanDeal
 
Keynote: GraphTour Toronto
Keynote: GraphTour TorontoKeynote: GraphTour Toronto
Keynote: GraphTour Toronto
 
Splunk @ Adobe
Splunk @ AdobeSplunk @ Adobe
Splunk @ Adobe
 
Streaming Cyber Security into Graph: Accelerating Data into DataStax Graph an...
Streaming Cyber Security into Graph: Accelerating Data into DataStax Graph an...Streaming Cyber Security into Graph: Accelerating Data into DataStax Graph an...
Streaming Cyber Security into Graph: Accelerating Data into DataStax Graph an...
 

More from Shannon Cuthbertson

Getting Started with Splunk Hands-on
Getting Started with Splunk Hands-onGetting Started with Splunk Hands-on
Getting Started with Splunk Hands-on
Shannon Cuthbertson
 
CSAA Customer Presentation
CSAA Customer PresentationCSAA Customer Presentation
CSAA Customer Presentation
Shannon Cuthbertson
 
IT Service Intelligence Hands On
IT Service Intelligence Hands OnIT Service Intelligence Hands On
IT Service Intelligence Hands On
Shannon Cuthbertson
 
Leverage Machine Data and Deliver New Insights for Business Analytics
Leverage Machine Data and Deliver New Insights for Business AnalyticsLeverage Machine Data and Deliver New Insights for Business Analytics
Leverage Machine Data and Deliver New Insights for Business Analytics
Shannon Cuthbertson
 
Using Splunk for Information Security
Using Splunk for Information SecurityUsing Splunk for Information Security
Using Splunk for Information Security
Shannon Cuthbertson
 
Splunk for Machine Learning and Analytics
Splunk for Machine Learning and AnalyticsSplunk for Machine Learning and Analytics
Splunk for Machine Learning and Analytics
Shannon Cuthbertson
 
Getting Started with Splunk Enterprise Hands-On
Getting Started with Splunk Enterprise Hands-OnGetting Started with Splunk Enterprise Hands-On
Getting Started with Splunk Enterprise Hands-On
Shannon Cuthbertson
 
Getting Started with Splunk Enterprise
Getting Started with Splunk EnterpriseGetting Started with Splunk Enterprise
Getting Started with Splunk Enterprise
Shannon Cuthbertson
 

More from Shannon Cuthbertson (8)

Getting Started with Splunk Hands-on
Getting Started with Splunk Hands-onGetting Started with Splunk Hands-on
Getting Started with Splunk Hands-on
 
CSAA Customer Presentation
CSAA Customer PresentationCSAA Customer Presentation
CSAA Customer Presentation
 
IT Service Intelligence Hands On
IT Service Intelligence Hands OnIT Service Intelligence Hands On
IT Service Intelligence Hands On
 
Leverage Machine Data and Deliver New Insights for Business Analytics
Leverage Machine Data and Deliver New Insights for Business AnalyticsLeverage Machine Data and Deliver New Insights for Business Analytics
Leverage Machine Data and Deliver New Insights for Business Analytics
 
Using Splunk for Information Security
Using Splunk for Information SecurityUsing Splunk for Information Security
Using Splunk for Information Security
 
Splunk for Machine Learning and Analytics
Splunk for Machine Learning and AnalyticsSplunk for Machine Learning and Analytics
Splunk for Machine Learning and Analytics
 
Getting Started with Splunk Enterprise Hands-On
Getting Started with Splunk Enterprise Hands-OnGetting Started with Splunk Enterprise Hands-On
Getting Started with Splunk Enterprise Hands-On
 
Getting Started with Splunk Enterprise
Getting Started with Splunk EnterpriseGetting Started with Splunk Enterprise
Getting Started with Splunk Enterprise
 

Recently uploaded

GraphRAG is All You need? LLM & Knowledge Graph
GraphRAG is All You need? LLM & Knowledge GraphGraphRAG is All You need? LLM & Knowledge Graph
GraphRAG is All You need? LLM & Knowledge Graph
Guy Korland
 
Elevating Tactical DDD Patterns Through Object Calisthenics
Elevating Tactical DDD Patterns Through Object CalisthenicsElevating Tactical DDD Patterns Through Object Calisthenics
Elevating Tactical DDD Patterns Through Object Calisthenics
Dorra BARTAGUIZ
 
Connector Corner: Automate dynamic content and events by pushing a button
Connector Corner: Automate dynamic content and events by pushing a buttonConnector Corner: Automate dynamic content and events by pushing a button
Connector Corner: Automate dynamic content and events by pushing a button
DianaGray10
 
Neuro-symbolic is not enough, we need neuro-*semantic*
Neuro-symbolic is not enough, we need neuro-*semantic*Neuro-symbolic is not enough, we need neuro-*semantic*
Neuro-symbolic is not enough, we need neuro-*semantic*
Frank van Harmelen
 
FIDO Alliance Osaka Seminar: FIDO Security Aspects.pdf
FIDO Alliance Osaka Seminar: FIDO Security Aspects.pdfFIDO Alliance Osaka Seminar: FIDO Security Aspects.pdf
FIDO Alliance Osaka Seminar: FIDO Security Aspects.pdf
FIDO Alliance
 
Transcript: Selling digital books in 2024: Insights from industry leaders - T...
Transcript: Selling digital books in 2024: Insights from industry leaders - T...Transcript: Selling digital books in 2024: Insights from industry leaders - T...
Transcript: Selling digital books in 2024: Insights from industry leaders - T...
BookNet Canada
 
Empowering NextGen Mobility via Large Action Model Infrastructure (LAMI): pav...
Empowering NextGen Mobility via Large Action Model Infrastructure (LAMI): pav...Empowering NextGen Mobility via Large Action Model Infrastructure (LAMI): pav...
Empowering NextGen Mobility via Large Action Model Infrastructure (LAMI): pav...
Thierry Lestable
 
Slack (or Teams) Automation for Bonterra Impact Management (fka Social Soluti...
Slack (or Teams) Automation for Bonterra Impact Management (fka Social Soluti...Slack (or Teams) Automation for Bonterra Impact Management (fka Social Soluti...
Slack (or Teams) Automation for Bonterra Impact Management (fka Social Soluti...
Jeffrey Haguewood
 
State of ICS and IoT Cyber Threat Landscape Report 2024 preview
State of ICS and IoT Cyber Threat Landscape Report 2024 previewState of ICS and IoT Cyber Threat Landscape Report 2024 preview
State of ICS and IoT Cyber Threat Landscape Report 2024 preview
Prayukth K V
 
AI for Every Business: Unlocking Your Product's Universal Potential by VP of ...
AI for Every Business: Unlocking Your Product's Universal Potential by VP of ...AI for Every Business: Unlocking Your Product's Universal Potential by VP of ...
AI for Every Business: Unlocking Your Product's Universal Potential by VP of ...
Product School
 
The Future of Platform Engineering
The Future of Platform EngineeringThe Future of Platform Engineering
The Future of Platform Engineering
Jemma Hussein Allen
 
Software Delivery At the Speed of AI: Inflectra Invests In AI-Powered Quality
Software Delivery At the Speed of AI: Inflectra Invests In AI-Powered QualitySoftware Delivery At the Speed of AI: Inflectra Invests In AI-Powered Quality
Software Delivery At the Speed of AI: Inflectra Invests In AI-Powered Quality
Inflectra
 
From Daily Decisions to Bottom Line: Connecting Product Work to Revenue by VP...
From Daily Decisions to Bottom Line: Connecting Product Work to Revenue by VP...From Daily Decisions to Bottom Line: Connecting Product Work to Revenue by VP...
From Daily Decisions to Bottom Line: Connecting Product Work to Revenue by VP...
Product School
 
Unsubscribed: Combat Subscription Fatigue With a Membership Mentality by Head...
Unsubscribed: Combat Subscription Fatigue With a Membership Mentality by Head...Unsubscribed: Combat Subscription Fatigue With a Membership Mentality by Head...
Unsubscribed: Combat Subscription Fatigue With a Membership Mentality by Head...
Product School
 
Monitoring Java Application Security with JDK Tools and JFR Events
Monitoring Java Application Security with JDK Tools and JFR EventsMonitoring Java Application Security with JDK Tools and JFR Events
Monitoring Java Application Security with JDK Tools and JFR Events
Ana-Maria Mihalceanu
 
From Siloed Products to Connected Ecosystem: Building a Sustainable and Scala...
From Siloed Products to Connected Ecosystem: Building a Sustainable and Scala...From Siloed Products to Connected Ecosystem: Building a Sustainable and Scala...
From Siloed Products to Connected Ecosystem: Building a Sustainable and Scala...
Product School
 
GDG Cloud Southlake #33: Boule & Rebala: Effective AppSec in SDLC using Deplo...
GDG Cloud Southlake #33: Boule & Rebala: Effective AppSec in SDLC using Deplo...GDG Cloud Southlake #33: Boule & Rebala: Effective AppSec in SDLC using Deplo...
GDG Cloud Southlake #33: Boule & Rebala: Effective AppSec in SDLC using Deplo...
James Anderson
 
Dev Dives: Train smarter, not harder – active learning and UiPath LLMs for do...
Dev Dives: Train smarter, not harder – active learning and UiPath LLMs for do...Dev Dives: Train smarter, not harder – active learning and UiPath LLMs for do...
Dev Dives: Train smarter, not harder – active learning and UiPath LLMs for do...
UiPathCommunity
 
FIDO Alliance Osaka Seminar: Passkeys at Amazon.pdf
FIDO Alliance Osaka Seminar: Passkeys at Amazon.pdfFIDO Alliance Osaka Seminar: Passkeys at Amazon.pdf
FIDO Alliance Osaka Seminar: Passkeys at Amazon.pdf
FIDO Alliance
 
LF Energy Webinar: Electrical Grid Modelling and Simulation Through PowSyBl -...
LF Energy Webinar: Electrical Grid Modelling and Simulation Through PowSyBl -...LF Energy Webinar: Electrical Grid Modelling and Simulation Through PowSyBl -...
LF Energy Webinar: Electrical Grid Modelling and Simulation Through PowSyBl -...
DanBrown980551
 

Recently uploaded (20)

GraphRAG is All You need? LLM & Knowledge Graph
GraphRAG is All You need? LLM & Knowledge GraphGraphRAG is All You need? LLM & Knowledge Graph
GraphRAG is All You need? LLM & Knowledge Graph
 
Elevating Tactical DDD Patterns Through Object Calisthenics
Elevating Tactical DDD Patterns Through Object CalisthenicsElevating Tactical DDD Patterns Through Object Calisthenics
Elevating Tactical DDD Patterns Through Object Calisthenics
 
Connector Corner: Automate dynamic content and events by pushing a button
Connector Corner: Automate dynamic content and events by pushing a buttonConnector Corner: Automate dynamic content and events by pushing a button
Connector Corner: Automate dynamic content and events by pushing a button
 
Neuro-symbolic is not enough, we need neuro-*semantic*
Neuro-symbolic is not enough, we need neuro-*semantic*Neuro-symbolic is not enough, we need neuro-*semantic*
Neuro-symbolic is not enough, we need neuro-*semantic*
 
FIDO Alliance Osaka Seminar: FIDO Security Aspects.pdf
FIDO Alliance Osaka Seminar: FIDO Security Aspects.pdfFIDO Alliance Osaka Seminar: FIDO Security Aspects.pdf
FIDO Alliance Osaka Seminar: FIDO Security Aspects.pdf
 
Transcript: Selling digital books in 2024: Insights from industry leaders - T...
Transcript: Selling digital books in 2024: Insights from industry leaders - T...Transcript: Selling digital books in 2024: Insights from industry leaders - T...
Transcript: Selling digital books in 2024: Insights from industry leaders - T...
 
Empowering NextGen Mobility via Large Action Model Infrastructure (LAMI): pav...
Empowering NextGen Mobility via Large Action Model Infrastructure (LAMI): pav...Empowering NextGen Mobility via Large Action Model Infrastructure (LAMI): pav...
Empowering NextGen Mobility via Large Action Model Infrastructure (LAMI): pav...
 
Slack (or Teams) Automation for Bonterra Impact Management (fka Social Soluti...
Slack (or Teams) Automation for Bonterra Impact Management (fka Social Soluti...Slack (or Teams) Automation for Bonterra Impact Management (fka Social Soluti...
Slack (or Teams) Automation for Bonterra Impact Management (fka Social Soluti...
 
State of ICS and IoT Cyber Threat Landscape Report 2024 preview
State of ICS and IoT Cyber Threat Landscape Report 2024 previewState of ICS and IoT Cyber Threat Landscape Report 2024 preview
State of ICS and IoT Cyber Threat Landscape Report 2024 preview
 
AI for Every Business: Unlocking Your Product's Universal Potential by VP of ...
AI for Every Business: Unlocking Your Product's Universal Potential by VP of ...AI for Every Business: Unlocking Your Product's Universal Potential by VP of ...
AI for Every Business: Unlocking Your Product's Universal Potential by VP of ...
 
The Future of Platform Engineering
The Future of Platform EngineeringThe Future of Platform Engineering
The Future of Platform Engineering
 
Software Delivery At the Speed of AI: Inflectra Invests In AI-Powered Quality
Software Delivery At the Speed of AI: Inflectra Invests In AI-Powered QualitySoftware Delivery At the Speed of AI: Inflectra Invests In AI-Powered Quality
Software Delivery At the Speed of AI: Inflectra Invests In AI-Powered Quality
 
From Daily Decisions to Bottom Line: Connecting Product Work to Revenue by VP...
From Daily Decisions to Bottom Line: Connecting Product Work to Revenue by VP...From Daily Decisions to Bottom Line: Connecting Product Work to Revenue by VP...
From Daily Decisions to Bottom Line: Connecting Product Work to Revenue by VP...
 
Unsubscribed: Combat Subscription Fatigue With a Membership Mentality by Head...
Unsubscribed: Combat Subscription Fatigue With a Membership Mentality by Head...Unsubscribed: Combat Subscription Fatigue With a Membership Mentality by Head...
Unsubscribed: Combat Subscription Fatigue With a Membership Mentality by Head...
 
Monitoring Java Application Security with JDK Tools and JFR Events
Monitoring Java Application Security with JDK Tools and JFR EventsMonitoring Java Application Security with JDK Tools and JFR Events
Monitoring Java Application Security with JDK Tools and JFR Events
 
From Siloed Products to Connected Ecosystem: Building a Sustainable and Scala...
From Siloed Products to Connected Ecosystem: Building a Sustainable and Scala...From Siloed Products to Connected Ecosystem: Building a Sustainable and Scala...
From Siloed Products to Connected Ecosystem: Building a Sustainable and Scala...
 
GDG Cloud Southlake #33: Boule & Rebala: Effective AppSec in SDLC using Deplo...
GDG Cloud Southlake #33: Boule & Rebala: Effective AppSec in SDLC using Deplo...GDG Cloud Southlake #33: Boule & Rebala: Effective AppSec in SDLC using Deplo...
GDG Cloud Southlake #33: Boule & Rebala: Effective AppSec in SDLC using Deplo...
 
Dev Dives: Train smarter, not harder – active learning and UiPath LLMs for do...
Dev Dives: Train smarter, not harder – active learning and UiPath LLMs for do...Dev Dives: Train smarter, not harder – active learning and UiPath LLMs for do...
Dev Dives: Train smarter, not harder – active learning and UiPath LLMs for do...
 
FIDO Alliance Osaka Seminar: Passkeys at Amazon.pdf
FIDO Alliance Osaka Seminar: Passkeys at Amazon.pdfFIDO Alliance Osaka Seminar: Passkeys at Amazon.pdf
FIDO Alliance Osaka Seminar: Passkeys at Amazon.pdf
 
LF Energy Webinar: Electrical Grid Modelling and Simulation Through PowSyBl -...
LF Energy Webinar: Electrical Grid Modelling and Simulation Through PowSyBl -...LF Energy Webinar: Electrical Grid Modelling and Simulation Through PowSyBl -...
LF Energy Webinar: Electrical Grid Modelling and Simulation Through PowSyBl -...
 

City of San Diego Customer Presentation

  • 1. Copyright © 2016 Splunk Inc. Gary Hayslip Deputy Director, CISO
  • 2. 2 About the City of San Diego • “America’s Finest City” • U.S. 8th largest city • 11,000+ employees • $4 billion business • 1.5 Million Citizens • 24 Networks • 40,000 endpoints • 4 Millions attacks per week
  • 3. 3 About Me • Chief Information Security Officer (CISSP, CISA, CRISC, CCSK) • Background in DOD and US Navy • Responsible for developing and executing city-wide security strategy • Creating “risk-aware” culture that protects city and personal information resources I am a World of Warcraft gamer Favorite Splunk T-shirt – “Taking the SH out of IT”
  • 4. 4 Before Splunk: Chaos • No visibility, no coordination, no control • IT was outsourced to a city-owned non-profit • No documentation; no strategic plan • Lacked insight into networking, data analysis, and who was doing what • No security operation center; the security of the networks was uncoordinated. • Business impact • Inefficiencies from too many networks and disparate technologies duct-taped together • Extreme vulnerability to cyber threats • Voters were insisting on managed services “Nothing was documented and there was no strategic plan. It was like the Wild, Wild West and the city was just throwing money at issues.”
  • 5. 5 Choosing Splunk • Selection criteria: • Prior experience and knowledge • Good ranking on Gartner • Able to handle our massive data streams on one platform • Strong track record of interfacing smoothly with other products (we have 26+) • Success meant bringing together disparate systems and data into one integrated, managed platform “Visibility = Action” • Splunk expands to meet evolving needs “Based on Splunk’s track record, I wasn’t interested in anybody else.”
  • 6. Splunk at City of San Diego • 100 GB license for production • Splunk Enterprise Security • 33 Splunk environments • 1 clustered indexers, 25 forwarders • 24 networks, a billion packets/month 40,000 endpoints, petabytes of data • 90% of the SOC owned by city, 10% by service provider Atos 6 25 Universal Forwarders 1 Indexers 1 Search Heads + 1 Deployment Servers
  • 7. Use of Splunk at City of San Diego Data / Log Visibility Application Management Security Reporting Threat Detection Analytics / Dashboards
  • 8. 8 End-to-End Visibility • We now route all logs and manage multiple data sources and apps on one platform (Tenable, ActiveDirectory, networks audit server) • We have visibility into our operations to function effectively • Achieved audit capability and intel into our networks (Varonis tool, Netskope, Netwrix) • With Splunk, we can create dashboards for any function and see information in real time “Splunk has the ability to slice and dice the information to give us the visibility we need.”
  • 9. 9 Security Reporting • Splunk supports our large data volume (100GB/hour, 1 Billion packets/month - - > adds up to a petabyte of data) • Security dashboard opens visibility across the network & shows management “what’s going on today in cyber” • I can translate the ton of paperwork on my desk into building meaningful metrics • Visibility lets us protect the perimeter to its “BYOD” end points “Security goes beyond my perimeter, which is no longer just the firewalls; it’s the bank of mobile phones my employees are walking around with.”
  • 10. 10 Threat Detection & Response • We experience 4 million attacks/week (including international countries & “hacktivists”) • With Splunk Enterprise Security, we: • Detect, investigate, scope and respond to threats • Quarantine dangerous files in minutes • When Mayor’s office hit with TeslaCrypt attack, we: • Detected and had machine off network within 20 minutes • Quickly protected critical folders (treasury, fire depts) • Completely remediated and got back up and running in 3.5 hours (prior, would have taken several days) “After a TeslaCrypt attack, we identified the effected machine and pulled it off network in minutes.”
  • 11. 11 Application Management • We manage 26 apps and plug-ins in Splunk • Able to interface with components like: • Nessus • Tenable • Varonis • Cisco • ActiveDirectory • SCADA, ICS networks • For our diverse needs, there was no other choice “Splunk was the right size Lego in the box for the puzzle we are building.”
  • 12. 12 Analytics, Dashboards, Reports • Splunk gives us (multiple teams) a single pane and point of access for our data • Dashboards and reports to give full views across the environment are in progress • Able to view employee use of city data on cloud solutions (mobile device, cloud storage) • Future projects - see analytic reports on public operations and functions (emergency teams, stop lights, traffic) • Reports drive more effective business management decisions and practices “I can show my mayor and COO how many attacks we’ve blocked, how many tickets we’re handling, what’s going on across the network.”
  • 13. 13 City of San Diego Use Cases Daily Operations Network Behavior Analytics Continuous Monitoring Data Governance
  • 14. 14 Users Across City of San Diego Enterprise networks HVAC systems Libraries Police and fire departments, 911 dispatchers Financial, medical (HIPAA), PCI data GPS networks Sanitation and utilities Golf courses
  • 15. 15 Splunk Words to the Wise…. • Don’t underestimate the amount of support you need—add another 25% • Plan for growth • Start with a trial version and take the training • Devote the effort to get the most out of the solution • When building out and adding other vendors: • Always ask, “Can you Splunk it?”, “Do you have a Splunk App?” • If the answer is “no,” don’t buy it
  • 16. 16 Splunking Ahead…. • We have a 5-year road map • We plan to share our success by introducing Splunk to other City departments (Splunk Day) • We want to expand to the cloud • Our dream is to have Splunk’s versatility touch every aspect of City operations, for both ingress and egress
  • 17. 17 Splunk Successes • “Aha” moment – Clear usage detail of our city phones • For years our vendor couldn’t give us this information • Took a class on using Splunk, and got a clear report showing phone charges and details by department - That alone paid for the class! • We have immediate visibility into our data • High level of detail, across multiple functions and departments • We can create reports that improve productivity and help reduce costs • Threat protection systems have saved the city from critical data breaches 17