SlideShare a Scribd company logo
© 2015 Global Technology Resources, Inc. All Rights Reserved. Contents herein contain confidential information not to be copied.© 2015 Global Technology Resources, Inc. All Rights Reserved. Contents herein contain confidential information not to be copied.
GTRI & Splunk Case Studies
Presented by Taylor Williams
December 8, 2015
© 2015 Global Technology Resources, Inc. All Rights Reserved. Contents
herein contain confidential information not to be copied.
Case Study: Multi-Site Security/Compliance
Customer:
Multi-national systems and (cloud) services-provider with 140,000+ employees and
140 data centers globally.
Challenge:
Many different services within corporation with proprietary and shared compliance
and security concerns with no structured or centralized log management solution in
place. Various missing components company-wide:
• Accountability and Audit
• Purchasing and Healthcare Compliance (PCI, HIPPA, etc.)
• Network and System Security
© 2015 Global Technology Resources, Inc. All Rights Reserved. Contents
herein contain confidential information not to be copied.
Case Study: Multi-Site Security/Compliance
Solution Process:
Phased approach for requirements gathering, proof of concept, pilot rollout, and a
production rollout. RFP released for solution proposal (not specific to Splunk) awarded
to GTRI for depth of Splunk practice and solutions provided.
• Phase 1: Requirements gathering for use cases in 8 defined data centers out of 140
• Phase 2: Proof of Concept of solution for approximately 10% subset of data
• Phase 3: Pilot Rollout of solution to all use cases for 8 defined data centers
• Phase 4: Production Rollout to data centers globally
Project currently nearing conclusion of Phase 2 with use cases met by viability of data
thus far collected and indexed into Splunk
© 2015 Global Technology Resources, Inc. All Rights Reserved. Contents
herein contain confidential information not to be copied.
Case Study: Multi-Site Security/Compliance
GTRI Solution:
Scalable and repeatable Splunk solution designed for implementation on Cisco
Flexpod solution(s). Designed for scalability to data centers beyond original 8
proposed with standard operating procedures (SOPs) defined for both Splunk
operations as well as hardware. Overall project inclusions:
• Full “ground-up” Splunk Architectural design
• Multi-site solution
• Repeatable philosophy in architecture and deployment
• Standard operating procedures and staffing plan for full 24x7 management
• GTRI Splunk Managed Service
© 2015 Global Technology Resources, Inc. All Rights Reserved. Contents
herein contain confidential information not to be copied.
Case Study: Multi-Site Security
Customer:
Private aerospace and engineering firm that designs and launches next generation
rockets and propulsion systems. Data centers located in Denver and various launch
locations across the US.
Challenge:
No central security incident and event management (SIEM) solution in place to have
holistic view of network security posture from all data centers. Security concerns are
great especially in monitoring those central to launch locations.
• Create a centrally deployed and managed SIEM
• Filter and fine-tune system to only see events deemed critical
© 2015 Global Technology Resources, Inc. All Rights Reserved. Contents
herein contain confidential information not to be copied.
Case Study: Multi-Site Security
Solution Process:
RFP released for vendors to propose a security solution inclusive of full design and
deployment methodologies to be enacted upon after award and project execution.
Discovery stage included to assess and capture complete security use case, inclusive of
relevant and irrelevant network sources to the central SIEM. Steps:
1. Design multi-site Splunk architecture. Two main data center locations for storage
of logs, fully replicated for redundancy between each.
2. Execute on validated design, deploying Splunk Enterprise servers to all proposed
locations
3. Ingest of logs from all validated sources
4. Filter nearly 1800+ hosts into a 200GB Splunk solution
© 2015 Global Technology Resources, Inc. All Rights Reserved. Contents
herein contain confidential information not to be copied.
Case Study: Multi-Site Security
GTRI Solution:
Fully executed multi-site SIEM solution using Splunk and the Splunk App for Enterprise
security. Security requirements and objectives met and exceeded using this solution
and its fully executed design. Work continues today with full time GTRI Splunk
Certified Architect on-site to manage solution. Overall project inclusions:
• Full “ground-up” Splunk Architectural design
• Multi-site solution
• Assessment of all relevant use cases to meet licensing threshold
• Splunk Enterprise Security Application installation and managed service
© 2015 Global Technology Resources, Inc. All Rights Reserved. Contents
herein contain confidential information not to be copied.
© 2015 Global Technology Resources, Inc. All Rights Reserved. Contents
herein contain confidential information not to be copied.
Case Study: SOC Staffing and Managed Service
Customer:
Self-funding not-for-profit US federal agency part of the United States Department of
Energy. Main location(s) located in the US Pacific Northwest region.
Challenge:
No SIEM in place to manage and monitor the agency’s overall network security
posture. Security operations in place, but incident management and response was
lacking and without use of proper tools. Customer needed to:
• Create a centrally deployed and managed SIEM
• Develop and deploy a 24x7 staffing model to fully staff and enable Security
Operations Center with Splunk
© 2015 Global Technology Resources, Inc. All Rights Reserved. Contents
herein contain confidential information not to be copied.
Case Study: SOC Staffing and Managed Service
Solution Process:
RFP released for vendors to propose a security solution inclusive of full design and
deployment methodologies, as well as a proposed staffing model to fully enable
customer SOC with use of the proposed tool. Phased approach to execution of project
included:
1. Execute on validated design, deploying Splunk App for Enterprise Security within
the deployed architecture for SIEM enablement
2. Propose finalized staffing model to customer for approval. Once approved, source,
hire, and train staff on use of Splunk and ES
© 2015 Global Technology Resources, Inc. All Rights Reserved. Contents
herein contain confidential information not to be copied.
Case Study: SOC Staffing and Managed Service
GTRI Solution:
Staffing model to manage 24x7 security operations: Shift times proposed for all
personnel
• SOC-specific personnel to be network security subject matter experts used for
incident response and resolution.
– SOC Manager (1)
– Security – Lead Analyst (1)
– Security – Senior Analyst (3)
– Security – Analyst (9)
• Splunk Operations personnel, to be used to manage to integrity of the Splunk
architecture and be first tier for SOC personnel in event mining.
– Operations Manager (1 per site)
– Operations Architect (1 FTE)
– Operations Data Scientist (1 per site and 1 FTE)
© 2015 Global Technology Resources, Inc. All Rights Reserved. Contents
herein contain confidential information not to be copied.
Additional Case Studies
Denver Water:
Use Splunk for overall service health dashboards. A deluge of machine data from logs
and databases overwhelmed IT administrators, hampering efforts to pinpoint
problems when users notified the help desk.
• Monitor and maintain applications
– Asset management, customer information, geospatial, mobile, Web services, REST services
• Dashboards provide visibility into:
– Current performance and availability
– Historical performance trending and availability
– Average daily performance
– Recent issues (uptime and failures)
© 2015 Global Technology Resources, Inc. All Rights Reserved. Contents
herein contain confidential information not to be copied.
Additional Case Studies
The University of Texas at Austin:
• Began using Splunk for security forensics
• Now using Splunk for identification and control, outbreak management, and
visibility of 120,000+ network devices
The City and County of San Francisco:
• Using Splunk for network security services to become proactive versus reactive
• Help identify what is/isn’t normal for web traffic to City and County’s website
• “With Splunk, instead of spending 40% of an FTE’s day to understand what the
web filters are telling us, we now just look at the dashboards to show us
abnormalities”
© 2015 Global Technology Resources, Inc. All Rights Reserved. Contents herein contain confidential information not to be copied.
Questions?

More Related Content

PDF
Nida event oracle business analytics 1 sep2016
PDF
How to Handle the Realities of DevOps Monitoring Today
PPTX
Cyber Security testing in an agile environment
PDF
Viasat Customer Presentation
PDF
D6: Cloud Directions ( Predix Transform 2016)
PPTX
ATAGTR2017 Security Testing for Healthcare applications
PDF
Operationalizing Data Analytics
PPTX
Enabling DataOps with Unified Data Lineage
Nida event oracle business analytics 1 sep2016
How to Handle the Realities of DevOps Monitoring Today
Cyber Security testing in an agile environment
Viasat Customer Presentation
D6: Cloud Directions ( Predix Transform 2016)
ATAGTR2017 Security Testing for Healthcare applications
Operationalizing Data Analytics
Enabling DataOps with Unified Data Lineage

What's hot (20)

PPTX
The DevSecOps Showdown: How to Bridge the Gap Between Security and Developers
PPTX
Splunk Discovery: Milan 2018 - Get More From Your Machine Data with Splunk AI
PPTX
Why SDN Skills is a Big Boost to Networking Careers
PPTX
Supply Chain Visualization
PDF
Practical DevSecOps - Arief Karfianto
PDF
ICIC 2014 Panel: Mobile Apps for Patent Searchers
PDF
Synopsys Security Event Israel Presentation: Making AppSec Testing Work in CI/CD
PDF
Pipeline analytics concept for posting
PDF
From rogue one to rebel alliance by Peter Chestna
PPT
Emergence of ITOA: An Evolution in IT Monitoring and Management
PDF
Top 10 Practices of Highly Successful DevOps Incident Management Teams
PDF
Take Control: Design a Complete DevSecOps Program
PDF
Synergist SCADA Introduction Slide Deck 2013
PDF
One neck case study v1 ge
PPTX
Splunk Discovery: Milan 2018 - Delivering New Visibility and Analytics for IT...
PPTX
Cross Section and Deep Dive into GE Predix
PDF
A modern approach to cloud computing
PPTX
Il paradigma DevOps e Continuous Delivery Automation
PPTX
Splunk Discovery: Milan 2018 - Splunk Overview
PDF
Devops: Security's big opportunity by Peter Chestna
The DevSecOps Showdown: How to Bridge the Gap Between Security and Developers
Splunk Discovery: Milan 2018 - Get More From Your Machine Data with Splunk AI
Why SDN Skills is a Big Boost to Networking Careers
Supply Chain Visualization
Practical DevSecOps - Arief Karfianto
ICIC 2014 Panel: Mobile Apps for Patent Searchers
Synopsys Security Event Israel Presentation: Making AppSec Testing Work in CI/CD
Pipeline analytics concept for posting
From rogue one to rebel alliance by Peter Chestna
Emergence of ITOA: An Evolution in IT Monitoring and Management
Top 10 Practices of Highly Successful DevOps Incident Management Teams
Take Control: Design a Complete DevSecOps Program
Synergist SCADA Introduction Slide Deck 2013
One neck case study v1 ge
Splunk Discovery: Milan 2018 - Delivering New Visibility and Analytics for IT...
Cross Section and Deep Dive into GE Predix
A modern approach to cloud computing
Il paradigma DevOps e Continuous Delivery Automation
Splunk Discovery: Milan 2018 - Splunk Overview
Devops: Security's big opportunity by Peter Chestna
Ad

Viewers also liked (20)

PDF
SplunkLive! Customer Presentation – Peak Hosting
PPTX
Cerner at SplunkLive! Minneapolis
PPTX
Легкие мобильные приложения – альтернатива традиционной экосистемной модели?
PPTX
SplunkLive! London 2016 - BBC Worldwide
PDF
Splunk for Online Services Event featuring Groupon
PDF
Splunk in Target: Internet of Things (Robot Analytics)
PDF
Integra Customer Presentation
DOC
PPTX
Splunk live! Italy 2015
PPTX
SplunkLive! London 2016 - John Lewis
PPTX
SplunkLive! London 2016 - HSCIC / NHS Digital / Spine 2
PPTX
SplunkLive! London 2016 - Shazam
PDF
How to Create an Effective RFP for your LMS Project
PPT
Periodo de entreguerras
PPTX
Five Best and Five Worst Practices for SIEM by Dr. Anton Chuvakin
PPTX
SplunkLive! Paris 2016 - Plenary session
PDF
T-Mobile Customer Presentation
PPTX
SplunkLive! Customer Presentation - FINRA
PPSX
Synergy Global Sourcing_India_Engineering_June2016_youtube
PDF
Decision Ready Data: Power Your Analytics with Great Data
SplunkLive! Customer Presentation – Peak Hosting
Cerner at SplunkLive! Minneapolis
Легкие мобильные приложения – альтернатива традиционной экосистемной модели?
SplunkLive! London 2016 - BBC Worldwide
Splunk for Online Services Event featuring Groupon
Splunk in Target: Internet of Things (Robot Analytics)
Integra Customer Presentation
Splunk live! Italy 2015
SplunkLive! London 2016 - John Lewis
SplunkLive! London 2016 - HSCIC / NHS Digital / Spine 2
SplunkLive! London 2016 - Shazam
How to Create an Effective RFP for your LMS Project
Periodo de entreguerras
Five Best and Five Worst Practices for SIEM by Dr. Anton Chuvakin
SplunkLive! Paris 2016 - Plenary session
T-Mobile Customer Presentation
SplunkLive! Customer Presentation - FINRA
Synergy Global Sourcing_India_Engineering_June2016_youtube
Decision Ready Data: Power Your Analytics with Great Data
Ad

Similar to GTRI Splunk Case Studies - Splunk Tech Day (20)

PPTX
Splunk Fundamentals: Investigations with Core Splunk - Splunk Tech Day
PPTX
SplunkLive! Frankfurt 2018 - Legacy SIEM to Splunk, How to Conquer Migration ...
PPTX
Single Glass of Pain: See Your World, Maybe You Wish You Hadn't
PPTX
DO5T17S_T5 Thur 430 GilesE_BR_20151114_012422
PPTX
Splunk and Cisco UCS Breakout Session
PDF
Case Study: University of Chicago Achieves High Availability through a Centr...
PPTX
Webinar: Improve Splunk Analytics and Automate Processes with SnapLogic
PPTX
SplunkLive! Zurich 2018: Legacy SIEM to Splunk, How to Conquer Migration and ...
PPTX
Inside SecOps at bet365
PDF
Migrating Critical Applications to the Cloud - isaca seattle - sanitized
PDF
Migrating Critical Applications To The Cloud - ISACA Seattle - Sanitized
PDF
Splunk in the Cisco Unified Computing System (UCS)
PPTX
Splunk MINT and Stream Breakout
PPTX
Virtual Gov Day - Security Breakout - Deloitte
ODT
Anitha_Resume_BigData
PPTX
Splunk MINT for Mobile Intelligence and Splunk App for Stream for Enhanced Op...
PPTX
Cloud Computing Gets Put to the Test
PPTX
SplunkLive! Zurich 2018: Use Splunk for Incident Response, Orchestration and ...
PPTX
Travis Perkins: Building a 'Lean SOC' over 'Legacy SOC'
PPTX
How a Leading Saudi Bank Matured Security to Better Partner the Business
Splunk Fundamentals: Investigations with Core Splunk - Splunk Tech Day
SplunkLive! Frankfurt 2018 - Legacy SIEM to Splunk, How to Conquer Migration ...
Single Glass of Pain: See Your World, Maybe You Wish You Hadn't
DO5T17S_T5 Thur 430 GilesE_BR_20151114_012422
Splunk and Cisco UCS Breakout Session
Case Study: University of Chicago Achieves High Availability through a Centr...
Webinar: Improve Splunk Analytics and Automate Processes with SnapLogic
SplunkLive! Zurich 2018: Legacy SIEM to Splunk, How to Conquer Migration and ...
Inside SecOps at bet365
Migrating Critical Applications to the Cloud - isaca seattle - sanitized
Migrating Critical Applications To The Cloud - ISACA Seattle - Sanitized
Splunk in the Cisco Unified Computing System (UCS)
Splunk MINT and Stream Breakout
Virtual Gov Day - Security Breakout - Deloitte
Anitha_Resume_BigData
Splunk MINT for Mobile Intelligence and Splunk App for Stream for Enhanced Op...
Cloud Computing Gets Put to the Test
SplunkLive! Zurich 2018: Use Splunk for Incident Response, Orchestration and ...
Travis Perkins: Building a 'Lean SOC' over 'Legacy SOC'
How a Leading Saudi Bank Matured Security to Better Partner the Business

More from Zivaro Inc (20)

PPTX
How to Rightsize Your Citrix Investment
PPTX
On-Prem vs. Cloud Collaboration Showdown
PPTX
Beyond the Phish with GTRI and Wombat Security Technologies
PDF
Big Data Workshop: Splunk and Dell EMC...Better Together
PDF
Organizational Change Management
PDF
Software-Defined WAN 101
PPTX
Insider Threat Solution from GTRI
PDF
SDN Security: Two Sides of the Same Coin
PPTX
Denver Big Data Analytics Day
PDF
Support Software Defined Networking with Dynamic Network Architecture
PDF
Cisco ACI: A New Approach to Software Defined Networking
PDF
Software Defined Networking (SDN) Technology Brief
PDF
Software Defined Networking (SDN) with VMware NSX
PPTX
Splunk Enterprise 6.3 - Splunk Tech Day
PPTX
GTRI Splunk Overview - Splunk Tech Day
PDF
Successfully Deploying IPv6
PPTX
Good Guys vs Bad Guys: Using Big Data to Counteract Advanced Threats
PDF
Successfully Deploying IPv6
PPTX
Using Big Data to Counteract Advanced Threats
PDF
IPv6 Security - Hacker Halted 2013
How to Rightsize Your Citrix Investment
On-Prem vs. Cloud Collaboration Showdown
Beyond the Phish with GTRI and Wombat Security Technologies
Big Data Workshop: Splunk and Dell EMC...Better Together
Organizational Change Management
Software-Defined WAN 101
Insider Threat Solution from GTRI
SDN Security: Two Sides of the Same Coin
Denver Big Data Analytics Day
Support Software Defined Networking with Dynamic Network Architecture
Cisco ACI: A New Approach to Software Defined Networking
Software Defined Networking (SDN) Technology Brief
Software Defined Networking (SDN) with VMware NSX
Splunk Enterprise 6.3 - Splunk Tech Day
GTRI Splunk Overview - Splunk Tech Day
Successfully Deploying IPv6
Good Guys vs Bad Guys: Using Big Data to Counteract Advanced Threats
Successfully Deploying IPv6
Using Big Data to Counteract Advanced Threats
IPv6 Security - Hacker Halted 2013

Recently uploaded (20)

PDF
August Patch Tuesday
PDF
Profit Center Accounting in SAP S/4HANA, S4F28 Col11
PPTX
Digital-Transformation-Roadmap-for-Companies.pptx
PDF
Heart disease approach using modified random forest and particle swarm optimi...
PDF
Accuracy of neural networks in brain wave diagnosis of schizophrenia
PDF
WOOl fibre morphology and structure.pdf for textiles
PDF
Univ-Connecticut-ChatGPT-Presentaion.pdf
PPTX
OMC Textile Division Presentation 2021.pptx
PDF
Approach and Philosophy of On baking technology
PPTX
A Presentation on Touch Screen Technology
PPTX
KOM of Painting work and Equipment Insulation REV00 update 25-dec.pptx
PDF
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
PDF
MIND Revenue Release Quarter 2 2025 Press Release
PDF
project resource management chapter-09.pdf
PDF
DASA ADMISSION 2024_FirstRound_FirstRank_LastRank.pdf
PDF
Assigned Numbers - 2025 - Bluetooth® Document
PDF
Hindi spoken digit analysis for native and non-native speakers
PDF
1 - Historical Antecedents, Social Consideration.pdf
PDF
Video forgery: An extensive analysis of inter-and intra-frame manipulation al...
PDF
A comparative analysis of optical character recognition models for extracting...
August Patch Tuesday
Profit Center Accounting in SAP S/4HANA, S4F28 Col11
Digital-Transformation-Roadmap-for-Companies.pptx
Heart disease approach using modified random forest and particle swarm optimi...
Accuracy of neural networks in brain wave diagnosis of schizophrenia
WOOl fibre morphology and structure.pdf for textiles
Univ-Connecticut-ChatGPT-Presentaion.pdf
OMC Textile Division Presentation 2021.pptx
Approach and Philosophy of On baking technology
A Presentation on Touch Screen Technology
KOM of Painting work and Equipment Insulation REV00 update 25-dec.pptx
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
MIND Revenue Release Quarter 2 2025 Press Release
project resource management chapter-09.pdf
DASA ADMISSION 2024_FirstRound_FirstRank_LastRank.pdf
Assigned Numbers - 2025 - Bluetooth® Document
Hindi spoken digit analysis for native and non-native speakers
1 - Historical Antecedents, Social Consideration.pdf
Video forgery: An extensive analysis of inter-and intra-frame manipulation al...
A comparative analysis of optical character recognition models for extracting...

GTRI Splunk Case Studies - Splunk Tech Day

  • 1. © 2015 Global Technology Resources, Inc. All Rights Reserved. Contents herein contain confidential information not to be copied.© 2015 Global Technology Resources, Inc. All Rights Reserved. Contents herein contain confidential information not to be copied. GTRI & Splunk Case Studies Presented by Taylor Williams December 8, 2015
  • 2. © 2015 Global Technology Resources, Inc. All Rights Reserved. Contents herein contain confidential information not to be copied. Case Study: Multi-Site Security/Compliance Customer: Multi-national systems and (cloud) services-provider with 140,000+ employees and 140 data centers globally. Challenge: Many different services within corporation with proprietary and shared compliance and security concerns with no structured or centralized log management solution in place. Various missing components company-wide: • Accountability and Audit • Purchasing and Healthcare Compliance (PCI, HIPPA, etc.) • Network and System Security
  • 3. © 2015 Global Technology Resources, Inc. All Rights Reserved. Contents herein contain confidential information not to be copied. Case Study: Multi-Site Security/Compliance Solution Process: Phased approach for requirements gathering, proof of concept, pilot rollout, and a production rollout. RFP released for solution proposal (not specific to Splunk) awarded to GTRI for depth of Splunk practice and solutions provided. • Phase 1: Requirements gathering for use cases in 8 defined data centers out of 140 • Phase 2: Proof of Concept of solution for approximately 10% subset of data • Phase 3: Pilot Rollout of solution to all use cases for 8 defined data centers • Phase 4: Production Rollout to data centers globally Project currently nearing conclusion of Phase 2 with use cases met by viability of data thus far collected and indexed into Splunk
  • 4. © 2015 Global Technology Resources, Inc. All Rights Reserved. Contents herein contain confidential information not to be copied. Case Study: Multi-Site Security/Compliance GTRI Solution: Scalable and repeatable Splunk solution designed for implementation on Cisco Flexpod solution(s). Designed for scalability to data centers beyond original 8 proposed with standard operating procedures (SOPs) defined for both Splunk operations as well as hardware. Overall project inclusions: • Full “ground-up” Splunk Architectural design • Multi-site solution • Repeatable philosophy in architecture and deployment • Standard operating procedures and staffing plan for full 24x7 management • GTRI Splunk Managed Service
  • 5. © 2015 Global Technology Resources, Inc. All Rights Reserved. Contents herein contain confidential information not to be copied. Case Study: Multi-Site Security Customer: Private aerospace and engineering firm that designs and launches next generation rockets and propulsion systems. Data centers located in Denver and various launch locations across the US. Challenge: No central security incident and event management (SIEM) solution in place to have holistic view of network security posture from all data centers. Security concerns are great especially in monitoring those central to launch locations. • Create a centrally deployed and managed SIEM • Filter and fine-tune system to only see events deemed critical
  • 6. © 2015 Global Technology Resources, Inc. All Rights Reserved. Contents herein contain confidential information not to be copied. Case Study: Multi-Site Security Solution Process: RFP released for vendors to propose a security solution inclusive of full design and deployment methodologies to be enacted upon after award and project execution. Discovery stage included to assess and capture complete security use case, inclusive of relevant and irrelevant network sources to the central SIEM. Steps: 1. Design multi-site Splunk architecture. Two main data center locations for storage of logs, fully replicated for redundancy between each. 2. Execute on validated design, deploying Splunk Enterprise servers to all proposed locations 3. Ingest of logs from all validated sources 4. Filter nearly 1800+ hosts into a 200GB Splunk solution
  • 7. © 2015 Global Technology Resources, Inc. All Rights Reserved. Contents herein contain confidential information not to be copied. Case Study: Multi-Site Security GTRI Solution: Fully executed multi-site SIEM solution using Splunk and the Splunk App for Enterprise security. Security requirements and objectives met and exceeded using this solution and its fully executed design. Work continues today with full time GTRI Splunk Certified Architect on-site to manage solution. Overall project inclusions: • Full “ground-up” Splunk Architectural design • Multi-site solution • Assessment of all relevant use cases to meet licensing threshold • Splunk Enterprise Security Application installation and managed service
  • 8. © 2015 Global Technology Resources, Inc. All Rights Reserved. Contents herein contain confidential information not to be copied.
  • 9. © 2015 Global Technology Resources, Inc. All Rights Reserved. Contents herein contain confidential information not to be copied. Case Study: SOC Staffing and Managed Service Customer: Self-funding not-for-profit US federal agency part of the United States Department of Energy. Main location(s) located in the US Pacific Northwest region. Challenge: No SIEM in place to manage and monitor the agency’s overall network security posture. Security operations in place, but incident management and response was lacking and without use of proper tools. Customer needed to: • Create a centrally deployed and managed SIEM • Develop and deploy a 24x7 staffing model to fully staff and enable Security Operations Center with Splunk
  • 10. © 2015 Global Technology Resources, Inc. All Rights Reserved. Contents herein contain confidential information not to be copied. Case Study: SOC Staffing and Managed Service Solution Process: RFP released for vendors to propose a security solution inclusive of full design and deployment methodologies, as well as a proposed staffing model to fully enable customer SOC with use of the proposed tool. Phased approach to execution of project included: 1. Execute on validated design, deploying Splunk App for Enterprise Security within the deployed architecture for SIEM enablement 2. Propose finalized staffing model to customer for approval. Once approved, source, hire, and train staff on use of Splunk and ES
  • 11. © 2015 Global Technology Resources, Inc. All Rights Reserved. Contents herein contain confidential information not to be copied. Case Study: SOC Staffing and Managed Service GTRI Solution: Staffing model to manage 24x7 security operations: Shift times proposed for all personnel • SOC-specific personnel to be network security subject matter experts used for incident response and resolution. – SOC Manager (1) – Security – Lead Analyst (1) – Security – Senior Analyst (3) – Security – Analyst (9) • Splunk Operations personnel, to be used to manage to integrity of the Splunk architecture and be first tier for SOC personnel in event mining. – Operations Manager (1 per site) – Operations Architect (1 FTE) – Operations Data Scientist (1 per site and 1 FTE)
  • 12. © 2015 Global Technology Resources, Inc. All Rights Reserved. Contents herein contain confidential information not to be copied. Additional Case Studies Denver Water: Use Splunk for overall service health dashboards. A deluge of machine data from logs and databases overwhelmed IT administrators, hampering efforts to pinpoint problems when users notified the help desk. • Monitor and maintain applications – Asset management, customer information, geospatial, mobile, Web services, REST services • Dashboards provide visibility into: – Current performance and availability – Historical performance trending and availability – Average daily performance – Recent issues (uptime and failures)
  • 13. © 2015 Global Technology Resources, Inc. All Rights Reserved. Contents herein contain confidential information not to be copied. Additional Case Studies The University of Texas at Austin: • Began using Splunk for security forensics • Now using Splunk for identification and control, outbreak management, and visibility of 120,000+ network devices The City and County of San Francisco: • Using Splunk for network security services to become proactive versus reactive • Help identify what is/isn’t normal for web traffic to City and County’s website • “With Splunk, instead of spending 40% of an FTE’s day to understand what the web filters are telling us, we now just look at the dashboards to show us abnormalities”
  • 14. © 2015 Global Technology Resources, Inc. All Rights Reserved. Contents herein contain confidential information not to be copied. Questions?