SlideShare a Scribd company logo
© 2024 SPLUNK INC.
Power the SOC
of the Future
with scale, speed
and choice.
Forward-
looking
statements
This presentation may contain forward-looking statements regarding future events, plans or the expected financial
performance of our company, including our expectations regarding our products, technology, strategy, customers,
markets, acquisitions and investments. These statements reflect management’s current expectations, estimates and
assumptions based on the information currently available to us. These forward-looking statements are not
guarantees of future performance and involve significant risks, uncertainties and other factors that may cause our
actual results, performance or achievements to be materially different from results, performance or achievements
expressed or implied by the forward-looking statements contained in this presentation.
For additional information about factors that could cause actual results to differ materially from those described in
the forward-looking statements made in this presentation, please refer to our periodic reports and other filings with
the SEC, including the risk factors identified in our most recent quarterly reports on Form 10-Q and annual reports on
Form 10-K, copies of which may be obtained by visiting the Splunk Investor Relations website at
www.investors.splunk.com or the SEC's website at www.sec.gov. The forward-looking statements made in this
presentation are made as of the time and date of this presentation. If reviewed after the initial presentation, even if
made available by us, on our website or otherwise, it may not contain current or accurate information. We disclaim
any obligation to update or revise any forward-looking statement based on new information, future events or
otherwise, except as required by applicable law.
In addition, any information about our roadmap outlines our general product direction and is subject to change at
any time without notice. It is for informational purposes only and shall not be incorporated into any contract or other
commitment. We undertake no obligation either to develop the features or functionalities described, in beta or in
preview (used interchangeably), or to include any such feature or functionality in a future release.
Splunk, Splunk> and Turn Data Into Doing are trademarks and registered trademarks of Splunk Inc. in the United
States and other countries. All other brand names, product names or trademarks belong to their respective owners.
© 2024 Splunk Inc. All rights reserved.
© 2024 SPLUNK INC.
© 2024 SPLUNK INC.
Matthias Maier
Security Market Advisor, EMEA
CEH, CISSP, CISM
The SOC of the future
© 2024 SPLUNK INC.
The SOC of the
Future
Unified Threat
Detection,
Investigation
and Response
at the Core.
We gone a long way
© 2024 SPLUNK INC.
Building on SIEM to
drive continued
innovation to
evolve the SOC
2009 2015 2016 2017 2018 2019 2020 2021 2022 2023
Enterprise Security
UBA
Security Content & Threat Research Team
SOAR
Risk Based Alerting in Enterprise Security
SURGe
Threat Intelligence Management
Open Cybersecurity Schema Framework
Attack Analyzer
Cloud-Based Behavioral Analytics
Mission Control
Today
You will go a long way, too!
We will meet you wherever
you are!
© 2024 SPLUNK INC.
Forging a path to digital resilience
Search, monitor and
investigate for real-
time security
monitoring.
Reduce noise, detect
more threats and
identify risk with AI/ML
powered detections.
Accelerate incident
investigations and
response using
automation.
Maximize SOC
efficiency with
integrated threat
detection, investigation
and response.
Foundational
Visibility
Guided
Insights
Proactive
Response
Unified
Workflows
See across
environments
Detect threats and
issues with context
Get ahead of
issues
Collaborate
Seamlessly
Accelerated by Splunk AI
© 2024 SPLUNK INC.
Foundational
Visibility
Guided
Insights
Proactive
Response
Unified
Workflows
See across
environments
Detect threats and
issues with context
Get ahead of
issues
Collaborate
Seamlessly
Foundational use cases
Providing the critical capabilities on your resilience journey
Automate Threat Analysis
Automate Containment &
Response Actions
Orchestrate Response
Workflows
Automate Complete TDIR Life Cycle
Standardize SOC Processes using
Response Templates
Automate Recovery Playbooks
Federate Access & Analytics
Data Optimization
Security Monitoring
Incident Management
Asset Discovery &
Management
Compliance
Visualization & Reporting
Threat Intelligence
Enrichment
Leverage Cybersecurity
Frameworks
Risk Based Alerting
Anomaly Detection
Threat Hunting
Accelerated by Splunk AI
The AI & Automation
future ahead!
The double click into
advancements for SecOps
© 2024 SPLUNK INC.
What’s next? Our
critical security
innovation areas
Unified TDIR with automated workflows
World-Class detections
Insider threat, risk and compliance
Federation
AI-guided workflows
© 2024 SPLUNK INC.
Foundational and Generative AI
Combining predictive analytics, accelerated investigation, and workflow enhancements
Correlate and
Diagnose
Aggregate and analyze all
data to investigate and identify
root causes
Detect and
Predict
Real-time, streaming
analysis to detect
anomalies and
forecast trends
Make Everyone an
Expert
Reduce need for environment
and tool expertise by simplifying
content creation and investigation
workflows
Foundational AI Capabilities
Generative AI Capabilities
© 2024 SPLUNK INC.
Foundational and Generative AI
Combining predictive analytics, accelerated investigation, and workflow enhancements
Correlate and
Diagnose
Aggregate and analyze all
data to investigate and identify
root causes
Detect and
Predict
Real-time, streaming
analysis to detect
anomalies and
forecast trends
Make Everyone an
Expert
Reduce need for environment
and tool expertise by simplifying
content creation and investigation
workflows
Foundational AI Capabilities
Generative AI Capabilities
© 2024 SPLUNK INC. | Splunk Confidential and Internal - Do Not Distribute
Upskill new and advanced
Splunk users quickly.
Translate bi-directionally
between NL and SPL.
Receive personalized
recommendations.
New:
AI Assistant 1.0
AI Assistant 2.0
- In your Workflow
AI Assistant 3.0
© 2024 SPLUNK INC.
Foundational and Generative AI
Combining predictive analytics, accelerated investigation, and workflow enhancements
Correlate and
Diagnose
Aggregate and analyze all
data to investigate and identify
root causes
Detect and
Predict
Real-time, streaming
analysis to detect
anomalies and
forecast trends
Make Everyone an
Expert
Reduce need for environment
and tool expertise by simplifying
content creation and investigation
workflows
Foundational AI Capabilities
Generative AI Capabilities
Level 1
AI Detections
© 2024 SPLUNK INC.
Introductory
use cases for
using AI for
security.
Foundational AI for Security
© 2024 SPLUNK INC.
Splunk Enterprise Security
with ML-Powered Content Updates from the Splunk Machine Learning for Security Team
Foundational AI for Security
Study Threats
Identify emerging threats and understand how they operate
Create Datasets
Collect data and use Splunk to parse the data and identify patterns that can be used to detect the threat
Build ML-Powered Detections
Build a model based on data in order to make predictions or decisions; enable systems to learn from data, identify patterns,
and make decisions with minimal human intervention; and craft rules or queries designed to identify specific activity associated
with threats
Test Detections
Run queries against a dataset that simulates attacker behavior to improve accuracy and reduce false positives
Release
Package detections to deliver timely and effective protections against emerging threats to Splunk customers
Level 2
Workflow end-to-end to manage and
operationalize anomaly detection tasks
© 2024 SPLUNK INC.
Splunk App for Anomaly Detection
Find anomalies in time-series datasets in just a few clicks!
Beginner friendly
No need for complex SPL queries, parameter tuning, or
knowledge of statistics
Quick and simple
The app detects anomalies with a couple of clicks - no
trial and error required
Helps ensure accuracy
Health check diagnostics determine if the user’s dataset is
fit for anomaly detection with the app’s algorithm
End-to-end operationalization workflow
Create anomaly detection jobs to run at regular intervals
and generate alerts
Splunk Enterprise 9.1, Splunk Cloud Platform
Foundational AI for Security
© 2024 SPLUNK INC.
Splunk App for Behavioral Profiling
Foundational AI for Security
Deploy Behavioral Anomaly Rules
Define and schedule behavioral indicators and scoring rules
with the help of a guided workflow
Investigate Entities
Utilise the dashboards provided to view and drill-down on the
entities which have the highest behavioral scores
Monitor Performance
Ensure your rules continue to execute effectively by monitoring
their performance and output
Level 3
New techniques to defend
© 2024 SPLUNK INC.
Splunk Attack Analyzer
Examples of AI built into products
Level 4
Automated Investigation
Automated Scoping
Automated Remediation
Unified Analyst Experience
Power the SOC of the Future with scale, speed and choice - Splunk Public Sector Summit 2024
Power the SOC of the Future with scale, speed and choice - Splunk Public Sector Summit 2024
What is the future of SIEM?
What is the future with Cisco?
© 2024 SPLUNK INC.
SIEM Spending Outlook - European
© 2024 SPLUNK INC.
© 2024 SPLUNK INC.
We will deliver
with unparalleled data.
Unparalleled
data
User feedback enriches the model
Better Security
& Observability
outcomes
High-efficacy
LLM
Stronger AI
capabilities
Unique data from Cisco
network, endpoint, device, cloud
Unique data from Splunk
security and observability across diverse tech landscape
© 2024 SPLUNK INC.
Thank You

More Related Content

PDF
Using MLOps to Bring ML to Production/The Promise of MLOps
PPTX
MLOps - The Assembly Line of ML
PDF
Cybersecurity Tools | Popular Tools for Cybersecurity Threats | Cybersecurity...
PDF
Azure Sentinel Tips
PPTX
Azure Sentinel
PDF
TechnicalTerraformLandingZones121120229238.pdf
PPTX
AWS Cloud Security
PDF
introduction to Azure Sentinel
Using MLOps to Bring ML to Production/The Promise of MLOps
MLOps - The Assembly Line of ML
Cybersecurity Tools | Popular Tools for Cybersecurity Threats | Cybersecurity...
Azure Sentinel Tips
Azure Sentinel
TechnicalTerraformLandingZones121120229238.pdf
AWS Cloud Security
introduction to Azure Sentinel

What's hot (20)

PPTX
Azure WAF
PPTX
Microsoft Azure Technical Overview
PDF
Azure governance v4.0
PPTX
Azure Cloud Adoption Framework + Governance - Sana Khan and Jay Kumar
PPTX
MLOps in action
PDF
Microsoft Azure Overview
PPTX
Cloud Security
PPTX
Breakdown of Microsoft Purview Solutions
PPTX
Azure App Service Architecture. Web Apps.
PDF
Microsoft 365 eEnterprise E5 Overview
PDF
Intro to Vertex AI, unified MLOps platform for Data Scientists & ML Engineers
PDF
Identity Security - Azure Identity Protection
PPTX
Evolving Cybersecurity Threats
PPTX
Secure your Access to Cloud Apps using Microsoft Defender for Cloud Apps
PDF
Microsoft Azure Active Directory
PPTX
Azure cloud governance deck
PPTX
Introducing MlFlow: An Open Source Platform for the Machine Learning Lifecycl...
PDF
MLOps Using MLflow
PDF
Azure Sentinel
PPTX
Security operation center (SOC)
Azure WAF
Microsoft Azure Technical Overview
Azure governance v4.0
Azure Cloud Adoption Framework + Governance - Sana Khan and Jay Kumar
MLOps in action
Microsoft Azure Overview
Cloud Security
Breakdown of Microsoft Purview Solutions
Azure App Service Architecture. Web Apps.
Microsoft 365 eEnterprise E5 Overview
Intro to Vertex AI, unified MLOps platform for Data Scientists & ML Engineers
Identity Security - Azure Identity Protection
Evolving Cybersecurity Threats
Secure your Access to Cloud Apps using Microsoft Defender for Cloud Apps
Microsoft Azure Active Directory
Azure cloud governance deck
Introducing MlFlow: An Open Source Platform for the Machine Learning Lifecycl...
MLOps Using MLflow
Azure Sentinel
Security operation center (SOC)
Ad

Similar to Power the SOC of the Future with scale, speed and choice - Splunk Public Sector Summit 2024 (20)

PDF
Splunk-Presentation
PDF
December Bengaluru Splunk User Group Meetup
PPTX
Splunk Discovery Köln - 17-01-2020 - Accelerate Incident Response
PDF
Die Rolle von KI in der digitalen Widerstandsfähigkeit - Splunk Public Sector...
PPTX
Splunk for Enterprise Security featuring User Behavior Analytics
PDF
Building an Analytics Enables SOC
PPTX
Accelerate Incident Response with Orchestration & Automation
PDF
March 2023 PNW User Group
PPTX
Splunk for Enterprise Security featuring UBA Breakout Session
PPTX
Splunk Discovery Day Dubai 2017 - Security Keynote
PDF
Splunk Discovery: Warsaw 2018 - Solve Your Security Challenges with Splunk En...
PDF
Webinar: Neues zur Splunk App for Enterprise Security
PPTX
Splunk for Enterprise Security featuring User Behavior Analytics
PDF
Splunk Solution overview testing versi 1
PPTX
Accelerate incident Response Using Orchestration and Automation
PPTX
Accelerate incident Response Using Orchestration and Automation
PPTX
Splunk for Enterprise Security Featuring UBA
PPTX
Make Your SOC Work Smarter, Not Harder
PPTX
Getting Started with Splunk Enterprise
PPTX
SplunkLive! Zurich 2018: Use Splunk for Incident Response, Orchestration and ...
Splunk-Presentation
December Bengaluru Splunk User Group Meetup
Splunk Discovery Köln - 17-01-2020 - Accelerate Incident Response
Die Rolle von KI in der digitalen Widerstandsfähigkeit - Splunk Public Sector...
Splunk for Enterprise Security featuring User Behavior Analytics
Building an Analytics Enables SOC
Accelerate Incident Response with Orchestration & Automation
March 2023 PNW User Group
Splunk for Enterprise Security featuring UBA Breakout Session
Splunk Discovery Day Dubai 2017 - Security Keynote
Splunk Discovery: Warsaw 2018 - Solve Your Security Challenges with Splunk En...
Webinar: Neues zur Splunk App for Enterprise Security
Splunk for Enterprise Security featuring User Behavior Analytics
Splunk Solution overview testing versi 1
Accelerate incident Response Using Orchestration and Automation
Accelerate incident Response Using Orchestration and Automation
Splunk for Enterprise Security Featuring UBA
Make Your SOC Work Smarter, Not Harder
Getting Started with Splunk Enterprise
SplunkLive! Zurich 2018: Use Splunk for Incident Response, Orchestration and ...
Ad

More from Splunk EMEA (11)

PDF
Zentrales Logdaten-Management in der KfW - Splunk Public Sector Summit 2024
PDF
Transparenz? Leicht und zentral - Splunk Public Sector Summit 2024
PDF
Splunk für alle: Optimierte Prozesse für eine zuverlässige und störungsfreie ...
PDF
Splunk als zentrale Datendrehscheibe zur Dienstleistersteuerung - Splunk Publ...
PDF
SOC ist kein Allheilmittel! - Splunk Public Sector Summit 2024
PDF
Private Cloud Monitoring, Security Monitoring & DevOps - Splunk Public Sector...
PDF
Mandantenfähigkeit mit Splunk für den öffentlichen Bereich - Splunk Public Se...
PDF
Ein Umbrella Monitoring für die e-Akte Hessen - Splunk Public Sector Summit 2024
PDF
Compliance-Anforderungen erfüllen: Von der Standardlösung zur kundenspezifisc...
PDF
Aktuelles aus der Cybercrime Ermittlungswelt - Splunk Public Sector Summit
PDF
Cisco & Splunk: Better Together - Splunk Public Sector Summit 2024
Zentrales Logdaten-Management in der KfW - Splunk Public Sector Summit 2024
Transparenz? Leicht und zentral - Splunk Public Sector Summit 2024
Splunk für alle: Optimierte Prozesse für eine zuverlässige und störungsfreie ...
Splunk als zentrale Datendrehscheibe zur Dienstleistersteuerung - Splunk Publ...
SOC ist kein Allheilmittel! - Splunk Public Sector Summit 2024
Private Cloud Monitoring, Security Monitoring & DevOps - Splunk Public Sector...
Mandantenfähigkeit mit Splunk für den öffentlichen Bereich - Splunk Public Se...
Ein Umbrella Monitoring für die e-Akte Hessen - Splunk Public Sector Summit 2024
Compliance-Anforderungen erfüllen: Von der Standardlösung zur kundenspezifisc...
Aktuelles aus der Cybercrime Ermittlungswelt - Splunk Public Sector Summit
Cisco & Splunk: Better Together - Splunk Public Sector Summit 2024

Recently uploaded (20)

PPT
Teaching material agriculture food technology
PDF
CIFDAQ's Market Insight: SEC Turns Pro Crypto
PPT
“AI and Expert System Decision Support & Business Intelligence Systems”
PDF
Unlocking AI with Model Context Protocol (MCP)
PDF
Diabetes mellitus diagnosis method based random forest with bat algorithm
PDF
Mobile App Security Testing_ A Comprehensive Guide.pdf
PPTX
Effective Security Operations Center (SOC) A Modern, Strategic, and Threat-In...
PDF
Modernizing your data center with Dell and AMD
PPTX
Understanding_Digital_Forensics_Presentation.pptx
PDF
Architecting across the Boundaries of two Complex Domains - Healthcare & Tech...
PPTX
Detection-First SIEM: Rule Types, Dashboards, and Threat-Informed Strategy
PDF
Electronic commerce courselecture one. Pdf
PDF
cuic standard and advanced reporting.pdf
PDF
Encapsulation theory and applications.pdf
PDF
NewMind AI Monthly Chronicles - July 2025
PDF
KodekX | Application Modernization Development
PDF
Per capita expenditure prediction using model stacking based on satellite ima...
PPTX
20250228 LYD VKU AI Blended-Learning.pptx
DOCX
The AUB Centre for AI in Media Proposal.docx
PDF
Chapter 3 Spatial Domain Image Processing.pdf
Teaching material agriculture food technology
CIFDAQ's Market Insight: SEC Turns Pro Crypto
“AI and Expert System Decision Support & Business Intelligence Systems”
Unlocking AI with Model Context Protocol (MCP)
Diabetes mellitus diagnosis method based random forest with bat algorithm
Mobile App Security Testing_ A Comprehensive Guide.pdf
Effective Security Operations Center (SOC) A Modern, Strategic, and Threat-In...
Modernizing your data center with Dell and AMD
Understanding_Digital_Forensics_Presentation.pptx
Architecting across the Boundaries of two Complex Domains - Healthcare & Tech...
Detection-First SIEM: Rule Types, Dashboards, and Threat-Informed Strategy
Electronic commerce courselecture one. Pdf
cuic standard and advanced reporting.pdf
Encapsulation theory and applications.pdf
NewMind AI Monthly Chronicles - July 2025
KodekX | Application Modernization Development
Per capita expenditure prediction using model stacking based on satellite ima...
20250228 LYD VKU AI Blended-Learning.pptx
The AUB Centre for AI in Media Proposal.docx
Chapter 3 Spatial Domain Image Processing.pdf

Power the SOC of the Future with scale, speed and choice - Splunk Public Sector Summit 2024

  • 1. © 2024 SPLUNK INC. Power the SOC of the Future with scale, speed and choice.
  • 2. Forward- looking statements This presentation may contain forward-looking statements regarding future events, plans or the expected financial performance of our company, including our expectations regarding our products, technology, strategy, customers, markets, acquisitions and investments. These statements reflect management’s current expectations, estimates and assumptions based on the information currently available to us. These forward-looking statements are not guarantees of future performance and involve significant risks, uncertainties and other factors that may cause our actual results, performance or achievements to be materially different from results, performance or achievements expressed or implied by the forward-looking statements contained in this presentation. For additional information about factors that could cause actual results to differ materially from those described in the forward-looking statements made in this presentation, please refer to our periodic reports and other filings with the SEC, including the risk factors identified in our most recent quarterly reports on Form 10-Q and annual reports on Form 10-K, copies of which may be obtained by visiting the Splunk Investor Relations website at www.investors.splunk.com or the SEC's website at www.sec.gov. The forward-looking statements made in this presentation are made as of the time and date of this presentation. If reviewed after the initial presentation, even if made available by us, on our website or otherwise, it may not contain current or accurate information. We disclaim any obligation to update or revise any forward-looking statement based on new information, future events or otherwise, except as required by applicable law. In addition, any information about our roadmap outlines our general product direction and is subject to change at any time without notice. It is for informational purposes only and shall not be incorporated into any contract or other commitment. We undertake no obligation either to develop the features or functionalities described, in beta or in preview (used interchangeably), or to include any such feature or functionality in a future release. Splunk, Splunk> and Turn Data Into Doing are trademarks and registered trademarks of Splunk Inc. in the United States and other countries. All other brand names, product names or trademarks belong to their respective owners. © 2024 Splunk Inc. All rights reserved. © 2024 SPLUNK INC.
  • 3. © 2024 SPLUNK INC. Matthias Maier Security Market Advisor, EMEA CEH, CISSP, CISM
  • 4. The SOC of the future
  • 5. © 2024 SPLUNK INC. The SOC of the Future Unified Threat Detection, Investigation and Response at the Core.
  • 6. We gone a long way
  • 7. © 2024 SPLUNK INC. Building on SIEM to drive continued innovation to evolve the SOC 2009 2015 2016 2017 2018 2019 2020 2021 2022 2023 Enterprise Security UBA Security Content & Threat Research Team SOAR Risk Based Alerting in Enterprise Security SURGe Threat Intelligence Management Open Cybersecurity Schema Framework Attack Analyzer Cloud-Based Behavioral Analytics Mission Control Today
  • 8. You will go a long way, too! We will meet you wherever you are!
  • 9. © 2024 SPLUNK INC. Forging a path to digital resilience Search, monitor and investigate for real- time security monitoring. Reduce noise, detect more threats and identify risk with AI/ML powered detections. Accelerate incident investigations and response using automation. Maximize SOC efficiency with integrated threat detection, investigation and response. Foundational Visibility Guided Insights Proactive Response Unified Workflows See across environments Detect threats and issues with context Get ahead of issues Collaborate Seamlessly Accelerated by Splunk AI
  • 10. © 2024 SPLUNK INC. Foundational Visibility Guided Insights Proactive Response Unified Workflows See across environments Detect threats and issues with context Get ahead of issues Collaborate Seamlessly Foundational use cases Providing the critical capabilities on your resilience journey Automate Threat Analysis Automate Containment & Response Actions Orchestrate Response Workflows Automate Complete TDIR Life Cycle Standardize SOC Processes using Response Templates Automate Recovery Playbooks Federate Access & Analytics Data Optimization Security Monitoring Incident Management Asset Discovery & Management Compliance Visualization & Reporting Threat Intelligence Enrichment Leverage Cybersecurity Frameworks Risk Based Alerting Anomaly Detection Threat Hunting Accelerated by Splunk AI
  • 11. The AI & Automation future ahead! The double click into advancements for SecOps
  • 12. © 2024 SPLUNK INC. What’s next? Our critical security innovation areas Unified TDIR with automated workflows World-Class detections Insider threat, risk and compliance Federation AI-guided workflows
  • 13. © 2024 SPLUNK INC. Foundational and Generative AI Combining predictive analytics, accelerated investigation, and workflow enhancements Correlate and Diagnose Aggregate and analyze all data to investigate and identify root causes Detect and Predict Real-time, streaming analysis to detect anomalies and forecast trends Make Everyone an Expert Reduce need for environment and tool expertise by simplifying content creation and investigation workflows Foundational AI Capabilities Generative AI Capabilities
  • 14. © 2024 SPLUNK INC. Foundational and Generative AI Combining predictive analytics, accelerated investigation, and workflow enhancements Correlate and Diagnose Aggregate and analyze all data to investigate and identify root causes Detect and Predict Real-time, streaming analysis to detect anomalies and forecast trends Make Everyone an Expert Reduce need for environment and tool expertise by simplifying content creation and investigation workflows Foundational AI Capabilities Generative AI Capabilities
  • 15. © 2024 SPLUNK INC. | Splunk Confidential and Internal - Do Not Distribute Upskill new and advanced Splunk users quickly. Translate bi-directionally between NL and SPL. Receive personalized recommendations. New: AI Assistant 1.0
  • 16. AI Assistant 2.0 - In your Workflow
  • 18. © 2024 SPLUNK INC. Foundational and Generative AI Combining predictive analytics, accelerated investigation, and workflow enhancements Correlate and Diagnose Aggregate and analyze all data to investigate and identify root causes Detect and Predict Real-time, streaming analysis to detect anomalies and forecast trends Make Everyone an Expert Reduce need for environment and tool expertise by simplifying content creation and investigation workflows Foundational AI Capabilities Generative AI Capabilities
  • 20. © 2024 SPLUNK INC. Introductory use cases for using AI for security. Foundational AI for Security
  • 21. © 2024 SPLUNK INC. Splunk Enterprise Security with ML-Powered Content Updates from the Splunk Machine Learning for Security Team Foundational AI for Security Study Threats Identify emerging threats and understand how they operate Create Datasets Collect data and use Splunk to parse the data and identify patterns that can be used to detect the threat Build ML-Powered Detections Build a model based on data in order to make predictions or decisions; enable systems to learn from data, identify patterns, and make decisions with minimal human intervention; and craft rules or queries designed to identify specific activity associated with threats Test Detections Run queries against a dataset that simulates attacker behavior to improve accuracy and reduce false positives Release Package detections to deliver timely and effective protections against emerging threats to Splunk customers
  • 22. Level 2 Workflow end-to-end to manage and operationalize anomaly detection tasks
  • 23. © 2024 SPLUNK INC. Splunk App for Anomaly Detection Find anomalies in time-series datasets in just a few clicks! Beginner friendly No need for complex SPL queries, parameter tuning, or knowledge of statistics Quick and simple The app detects anomalies with a couple of clicks - no trial and error required Helps ensure accuracy Health check diagnostics determine if the user’s dataset is fit for anomaly detection with the app’s algorithm End-to-end operationalization workflow Create anomaly detection jobs to run at regular intervals and generate alerts Splunk Enterprise 9.1, Splunk Cloud Platform Foundational AI for Security
  • 24. © 2024 SPLUNK INC. Splunk App for Behavioral Profiling Foundational AI for Security Deploy Behavioral Anomaly Rules Define and schedule behavioral indicators and scoring rules with the help of a guided workflow Investigate Entities Utilise the dashboards provided to view and drill-down on the entities which have the highest behavioral scores Monitor Performance Ensure your rules continue to execute effectively by monitoring their performance and output
  • 26. © 2024 SPLUNK INC. Splunk Attack Analyzer Examples of AI built into products
  • 27. Level 4 Automated Investigation Automated Scoping Automated Remediation Unified Analyst Experience
  • 30. What is the future of SIEM? What is the future with Cisco?
  • 31. © 2024 SPLUNK INC. SIEM Spending Outlook - European
  • 32. © 2024 SPLUNK INC. © 2024 SPLUNK INC. We will deliver with unparalleled data. Unparalleled data User feedback enriches the model Better Security & Observability outcomes High-efficacy LLM Stronger AI capabilities Unique data from Cisco network, endpoint, device, cloud Unique data from Splunk security and observability across diverse tech landscape
  • 33. © 2024 SPLUNK INC. Thank You