SlideShare a Scribd company logo
Copyright © 2016 Splunk Inc.
Baylor University
Jon Allen
Assistant VP & CISO
2
About Baylor University
• Chartered in 1845
• In Waco Texas, the state’s oldest institution
of higher learning
• Nationally ranked research institution
• Private Christian university; world’s largest
Baptist university
• Tier 1 school among national universities
• 17,000 students
• 3000-3200 faculty / staff
3
About Me
• Assistant VP & CISO
— First full time info security employee here at Baylor, here now 17 years
— 13 years in information security
— Started the security program & built it up from the beginning
• BS, Political Science; Masters, Computers Science; CISSP
• Forensic examiner, give 6-10 presentations a year, publications
• Manage 3 full-time security analysts
• Team runs Splunk environment; performs security reviews on new
products, security awareness, instant-on response, forensics,
vulnerability management, security compliance consulting
4
Before Splunk: Highly Inefficient
• It was hard to get the info we needed quickly
— Had to log in to each domain controller separately
— Local searches and for different roles were tedious
• No ability to cross reference & make sense of data
• Operating in traditional siloed IT groups
• Vendors would decide what was important, and
were often wrong
• Experiencing account lockouts across domain
controllers in high-use environments
• End result = poor customer service
“We had a good
idea of what we
needed to
know, but it was
very hard to get
that
information in a
timely manner.”
5
Choosing Splunk
• Splunk started as a small PCI network project
— Needed to meet login requirements for processing transactions
• We were looking for more than the usual “compliance in a box”
• We needed solutions for bigger problems, such as:
— Identifying lockouts across domain controllers
— Resolving horribly inefficient log, search, and service issues
• Splunk gave us tools to pull our data together & cross reference it
• Unlike other vendors, Splunk was flexible & allowed us to map
risk for the education environment ourselves
• It was clear from the beginning, Splunk was a very powerful tool
— Ops team loved the applications for them
— We helped get the net plus agreement in place (1st school to sign on)
“Once our
OPS guys got
a little taste
of Splunk,
they were
hooked.”
6
Splunk Benefits
• From a low headcount staff perspective, our savings have
been in resources – people and saving time. Finding
information has gone from hours to minutes.
• Splunk puts everyone on the same page. Everybody has
access to the same information, which breaks down silos.
• Information security is about “protecting your treasure” as
much as you can. With Splunk, we can quickly see if
something is in isolation, a trend or requires action.
• It’s not always how can I prevent breaches, but how can I
minimize and control them. Splunk is a great tool for that.
“Splunk has
helped our team
build credibility
because we’re
bringing
something to the
table that helps
people get their
jobs done and
done well.”
7
Splunk at Baylor University
• 400 GB license
• Large central IT organization
• 30+ users:
• Architecture:
– Netflow and firewalls largest data sources
(firewalls 40 percent of license)
– 10 servers
– 3 indexers; role-based access control 100+ Universal Forwarders
3 Indexers
3 Search Heads + 1 Deployment Servers
8
Logs & Third-Party Apps at Baylor
• DNS monitoring
• Radius logs
• Crashplan
• Qualys
• Box, Duo
• Cloud services
• CloudFlare
• Office 365, Microsoft PA
Splunk Use Cases
Security
Visibility/Search/Analytics
DashboardsOperational Efficiency
Early Use Cases –
PCI Compliance, Ops,
Troubleshooting
10
Splunk Early Use Cases
• PCI compliance
• Ops cases:
— Mail logs and searches, authentication, AD, Shibboleth
• Troubleshooting
— Vendor “sent message claims” – easy to verify
• Being able to visualize data with illustrations
• Security (Phase 1) – SIEM (Security Information &
Event Mgmt)
“For us, the piece
that’s a plus & a
minus is you can
do so much. You
do the first 5
things & then it’s
‘Where does my
imagination take
me?’”
11
Splunk for Security
• We gained proactive security vs. reactive ‘insecurity’
– Real-life fix: When we saw failed Box authentications, research
revealed SNMP misconfigurations, not threats
– Splunk helps us uncover & resolve those “non-threat” threats
• Splunk provides a common language - everyone sees the
same thing, independent of different tools
• Splunk allows us to build strong relationships and
support procedures (ie, we don’t run the firewall/IPS
systems but we support the teams that do)
• Dealing with the “noise”
– IT security is challenged to find the valuable noise among all the
noises (malware, phishing, spearing)
– We can identify a problem source, talk to the right people & take
action in minutes vs. hours (drastic time shrinkage)
“In security,
you’re not
trying to find a
needle in a
haystack.
You’re trying to
find a needle in
a pile of
needles.”
12
Splunk for Visibility/Search/Analytics
• The “single pane of glass” is by far the most
powerful thing about Splunk
— Network logs, traffic logs, authentication are all visible
from one screen
— Cross referencing is easy and extremely useful
— Everyone across the organization can see the same thing
• Splunk supports visibility off campus where it’s
typically lost – cloud, vendors, Box
• Monitoring/real time analytics
— Load balancers, firewall connection rates
— Having screens up so you can see issues is very helpful
“At the end of the
day, Splunk is a
sandbox for our
data. We pull all
our data in the
sandbox and
decide what kind
of castle we want
to build today.”
13
Splunk for Operational Efficiency
“We are all
trusted to access
read-only data so
we know what
everybody
searches, which
helps us move
forward and build
efficiency into the
organization.”
• We’ve built a very collaborative environment
— Everyone gets “deputized” to do what needs to be done
— We work with and support other teams working together
(networking, firewall and server teams)
— By nature, Splunk fosters collaboration
• Splunk has opened up traditional IT silos – server / IT /
firewall teams – efficient, effective searches build trust
• Cloud computing
— Most vendors don’t understand cloud computing --
you’ll lose visibility without the right tools
— We know that’s the direction we’ll be going in
— Splunk is working on those tools and can take us there
14
Splunk for Dashboards
“There can
some time and
investment in
creating a
custom
dashboard, but
the benefit of
seeing all that
data in one
place is huge.”
• Our PCI log review dashboard is a significant investment
— Our analysts use open source tool OS X for file integrity
monitoring; Microsoft log numbers, OS X specs, firewall info
— Within a very short time our analyst created a dashboard that
includes data to meet log review reqt’s – all in one place
• We support many different custom team requests
— SysOps needed a dashboard showing who hasn’t had a
successful backup after 4 days
— Vendor interfaces that normally don’t work easily, can be
pulled into Splunk
• Predictive analysis - 2 years ago, we created a dashboard
that shows network pinch points needing > capacity
15
Splunk A-Ha Moment
• Now with Splunk, the security team doesn’t have to
be the one pushing initiatives
• Example: When we needed to move on a project:
— In the past, would have required multiple meetings, hard
conversations, going to the highest level
— Now, they ask us “Why aren’t you doing this?”
— Huge change!
• This high-level buy-in only happens with a significantly
useful, game-changing tool
“The real power
and value comes
when I start
understanding
what I need to
look like in the
future or what
may be coming
down the line that
I haven’t even
thought of yet.”
16
Users
• Vice President, deputy CIO, associate VPs
• OPS team; systems operations
• Server and networking team
• Web & marketing
• Client services; helpdesk, desktop support
• Mobile support
• Administrative systems
• ERPs, database management
17
Splunk Words to the Wise….
• With Splunk, you can jump right in and get your feet wet
quickly, but then you have to take that step back and
understand what you really want to do. Then you start
reaping the benefits more and more.
• Avoid the pitfall of underestimating the size of the license
you’ll need.
• Similarly for your platform, make sure you have sufficient
hardware capacity for what you want to do so Splunk can
run efficiently.
• Make the necessary investments so your platform will
perform to meet your users’ needs.
18
Splunking Ahead….
• Greater expansion into cloud services
— Microsoft project
• Fischer hosted identity management system
• Looking for new ways to leverage the
investment in Splunk
— Potential in managed services
— Augmenting staff resources
• Greater participation with vendors and Splunk
for their customers’ benefit
19
Splunk Successes
• Initially Splunk was another tool in the toolbox. Splunk is
now our analytics tool, and we’re not renewing our
traditional tools anymore.
• With Splunk, there’s no finger pointing because we have a
place where everybody knows to go for information and
that’s been a huge value. It’s becoming a kind of universal
expectation within the organization.
• Splunk has helped our team provide a valuable service in
helping the organization as a whole.
19
Thank You

More Related Content

PPTX
SplunkLive! Austin Customer Presentation - Dell
PDF
SplunkLive! Austin Customer Presentation - Xerox
PPTX
Getting Started with Splunk Enterprise
PPTX
SplunkLive! Customer Presentation – athenahealth
PPTX
Splunk EMEA Webinar: Scoping infections and disrupting breaches
PPTX
How to Design, Build and Map IT and Business Services in Splunk
PDF
Splunk @ Adobe
PPTX
Splunk Webinar: Webinar: Die Effizienz Ihres SOC verbessern mit neuen Funktio...
SplunkLive! Austin Customer Presentation - Dell
SplunkLive! Austin Customer Presentation - Xerox
Getting Started with Splunk Enterprise
SplunkLive! Customer Presentation – athenahealth
Splunk EMEA Webinar: Scoping infections and disrupting breaches
How to Design, Build and Map IT and Business Services in Splunk
Splunk @ Adobe
Splunk Webinar: Webinar: Die Effizienz Ihres SOC verbessern mit neuen Funktio...

What's hot (20)

PPTX
Customer Presentation
PPTX
Splunk for IT Operations
PPTX
Splunk Discovery Day Düsseldorf 2016
PPTX
SplunkLive! - Splunk for IT Operations
PPTX
Elevate your Splunk Deployment by Better Understanding your Value Breakfast S...
PPTX
Design, Build and Map IT and Business Services in Splunk
PPTX
Operational Security Intelligence Breakout Session
PPTX
Travis Perkins: Building a 'Lean SOC' over 'Legacy SOC'
PPTX
Getting Started with Splunk (Hands-On)
PPTX
Customer Presentation
PPTX
Splunk for IT Operations
PPTX
Distributed Management Console Breakout Session
PPTX
How to Design, Build and Map IT and Business Services in Splunk
PPTX
Taking Splunk to the Next Level - Management Breakout Session
PPTX
Cisco and Splunk: Under the Hood of Cisco IT Breakout Session
PDF
SplunkLive! London - Splunk App for Stream & MINT Breakout
PPTX
Splunk and Cisco UCS Breakout Session
PPTX
SplunkLive! Splunk for IT Operations
PPTX
Splunk live university of alberta 2015
PPTX
Building a Security Information and Event Management platform at Travis Per...
Customer Presentation
Splunk for IT Operations
Splunk Discovery Day Düsseldorf 2016
SplunkLive! - Splunk for IT Operations
Elevate your Splunk Deployment by Better Understanding your Value Breakfast S...
Design, Build and Map IT and Business Services in Splunk
Operational Security Intelligence Breakout Session
Travis Perkins: Building a 'Lean SOC' over 'Legacy SOC'
Getting Started with Splunk (Hands-On)
Customer Presentation
Splunk for IT Operations
Distributed Management Console Breakout Session
How to Design, Build and Map IT and Business Services in Splunk
Taking Splunk to the Next Level - Management Breakout Session
Cisco and Splunk: Under the Hood of Cisco IT Breakout Session
SplunkLive! London - Splunk App for Stream & MINT Breakout
Splunk and Cisco UCS Breakout Session
SplunkLive! Splunk for IT Operations
Splunk live university of alberta 2015
Building a Security Information and Event Management platform at Travis Per...
Ad

Viewers also liked (14)

PPTX
Taking Splunk to the Next Level - Manager
PDF
Projecting Enterprise Security Requirements on the Cloud
PPT
SplunkLive! Paris 2015 - Euler Hermes
DOCX
Cloud Access Security Broker (CASB)
PPTX
Cloud security, Cloud security Access broker, CSAB's 4 pillar, deployment mode
PPTX
The Definitive CASB Business Case Kit - Presentation
PPTX
Splunk for Industrial Data and the Internet of Things
PPTX
Reference Architecture for Data Loss Prevention in the Cloud
PPTX
Splunk for Enterprise Security and User Behavior Analytics
PDF
PPTX
5 Highest-Impact CASB Use Cases
PDF
Introducing IBM Cloud Security Enforcer, CASB, IDaaS and Threat Prevention
PPTX
5 Highest-Impact CASB Use Cases - Office 365
PPTX
Splunk live paris_overview_02_07_2013 v2.1
Taking Splunk to the Next Level - Manager
Projecting Enterprise Security Requirements on the Cloud
SplunkLive! Paris 2015 - Euler Hermes
Cloud Access Security Broker (CASB)
Cloud security, Cloud security Access broker, CSAB's 4 pillar, deployment mode
The Definitive CASB Business Case Kit - Presentation
Splunk for Industrial Data and the Internet of Things
Reference Architecture for Data Loss Prevention in the Cloud
Splunk for Enterprise Security and User Behavior Analytics
5 Highest-Impact CASB Use Cases
Introducing IBM Cloud Security Enforcer, CASB, IDaaS and Threat Prevention
5 Highest-Impact CASB Use Cases - Office 365
Splunk live paris_overview_02_07_2013 v2.1
Ad

Similar to SplunkLive! Austin Customer Presentation - Baylor (20)

PPTX
SplunkLive! Customer Presentation – Covance Inc"
PPTX
Customer Presentation, FirstSolar
PPTX
SplunkLive! Customer Presentation – athenahealth
PPTX
SplunkLive! Customer Presentation – athenahealth
PPTX
Splunk Different
PPTX
Customer Presentation
PPTX
Splunk live! Customer Presentation – Wellsfargo
PPTX
Splunk at Sabre
PDF
Splunk in the Cisco Unified Computing System (UCS)
PPTX
Getting Started with Splunk Breakout Session
PPTX
City of San Diego Customer Presentation
PPTX
Getting Started with Splunk Breakout Session
PPTX
Simplicity in Hybrid IT Environments – A Security Oxymoron?
PDF
ClickBank Customer Presentation
PPTX
Customer Presentation - Financial Services Organization
PPTX
Splunk @ HomeAway
PPTX
SplunkLive! Customer Presentation – UMCP
PPTX
Getting Started with Splunk Enterprise
PPTX
Getting Started with Splunk Enterprise
PPTX
Customer Presentation - Telus
SplunkLive! Customer Presentation – Covance Inc"
Customer Presentation, FirstSolar
SplunkLive! Customer Presentation – athenahealth
SplunkLive! Customer Presentation – athenahealth
Splunk Different
Customer Presentation
Splunk live! Customer Presentation – Wellsfargo
Splunk at Sabre
Splunk in the Cisco Unified Computing System (UCS)
Getting Started with Splunk Breakout Session
City of San Diego Customer Presentation
Getting Started with Splunk Breakout Session
Simplicity in Hybrid IT Environments – A Security Oxymoron?
ClickBank Customer Presentation
Customer Presentation - Financial Services Organization
Splunk @ HomeAway
SplunkLive! Customer Presentation – UMCP
Getting Started with Splunk Enterprise
Getting Started with Splunk Enterprise
Customer Presentation - Telus

More from Splunk (20)

PDF
Splunk Leadership Forum Wien - 20.05.2025
PDF
Splunk Security Update | Public Sector Summit Germany 2025
PDF
Building Resilience with Energy Management for the Public Sector
PDF
IT-Lagebild: Observability for Resilience (SVA)
PDF
Nach dem SOC-Aufbau ist vor der Automatisierung (OFD Baden-Württemberg)
PDF
Monitoring einer Sicheren Inter-Netzwerk Architektur (SINA)
PDF
Praktische Erfahrungen mit dem Attack Analyser (gematik)
PDF
Cisco XDR & Splunk SIEM - stronger together (DATAGROUP Cyber Security)
PDF
Security - Mit Sicherheit zum Erfolg (Telekom)
PDF
One Cisco - Splunk Public Sector Summit Germany April 2025
PDF
.conf Go 2023 - Data analysis as a routine
PDF
.conf Go 2023 - How KPN drives Customer Satisfaction on IPTV
PDF
.conf Go 2023 - Navegando la normativa SOX (Telefónica)
PDF
.conf Go 2023 - Raiffeisen Bank International
PDF
.conf Go 2023 - På liv og død Om sikkerhetsarbeid i Norsk helsenett
PDF
.conf Go 2023 - Many roads lead to Rome - this was our journey (Julius Bär)
PDF
.conf Go 2023 - Das passende Rezept für die digitale (Security) Revolution zu...
PDF
.conf go 2023 - Cyber Resilienz – Herausforderungen und Ansatz für Energiever...
PDF
.conf go 2023 - De NOC a CSIRT (Cellnex)
PDF
conf go 2023 - El camino hacia la ciberseguridad (ABANCA)
Splunk Leadership Forum Wien - 20.05.2025
Splunk Security Update | Public Sector Summit Germany 2025
Building Resilience with Energy Management for the Public Sector
IT-Lagebild: Observability for Resilience (SVA)
Nach dem SOC-Aufbau ist vor der Automatisierung (OFD Baden-Württemberg)
Monitoring einer Sicheren Inter-Netzwerk Architektur (SINA)
Praktische Erfahrungen mit dem Attack Analyser (gematik)
Cisco XDR & Splunk SIEM - stronger together (DATAGROUP Cyber Security)
Security - Mit Sicherheit zum Erfolg (Telekom)
One Cisco - Splunk Public Sector Summit Germany April 2025
.conf Go 2023 - Data analysis as a routine
.conf Go 2023 - How KPN drives Customer Satisfaction on IPTV
.conf Go 2023 - Navegando la normativa SOX (Telefónica)
.conf Go 2023 - Raiffeisen Bank International
.conf Go 2023 - På liv og død Om sikkerhetsarbeid i Norsk helsenett
.conf Go 2023 - Many roads lead to Rome - this was our journey (Julius Bär)
.conf Go 2023 - Das passende Rezept für die digitale (Security) Revolution zu...
.conf go 2023 - Cyber Resilienz – Herausforderungen und Ansatz für Energiever...
.conf go 2023 - De NOC a CSIRT (Cellnex)
conf go 2023 - El camino hacia la ciberseguridad (ABANCA)

Recently uploaded (20)

PDF
cuic standard and advanced reporting.pdf
PDF
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
PDF
Dropbox Q2 2025 Financial Results & Investor Presentation
PDF
Encapsulation_ Review paper, used for researhc scholars
PPTX
Detection-First SIEM: Rule Types, Dashboards, and Threat-Informed Strategy
PDF
Modernizing your data center with Dell and AMD
PPT
Teaching material agriculture food technology
PDF
Shreyas Phanse Resume: Experienced Backend Engineer | Java • Spring Boot • Ka...
PDF
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
PDF
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
PDF
Diabetes mellitus diagnosis method based random forest with bat algorithm
PDF
Reach Out and Touch Someone: Haptics and Empathic Computing
PDF
Machine learning based COVID-19 study performance prediction
PPT
“AI and Expert System Decision Support & Business Intelligence Systems”
PPTX
Digital-Transformation-Roadmap-for-Companies.pptx
PDF
Mobile App Security Testing_ A Comprehensive Guide.pdf
PDF
Electronic commerce courselecture one. Pdf
PPTX
Effective Security Operations Center (SOC) A Modern, Strategic, and Threat-In...
PPTX
Understanding_Digital_Forensics_Presentation.pptx
PDF
Bridging biosciences and deep learning for revolutionary discoveries: a compr...
cuic standard and advanced reporting.pdf
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
Dropbox Q2 2025 Financial Results & Investor Presentation
Encapsulation_ Review paper, used for researhc scholars
Detection-First SIEM: Rule Types, Dashboards, and Threat-Informed Strategy
Modernizing your data center with Dell and AMD
Teaching material agriculture food technology
Shreyas Phanse Resume: Experienced Backend Engineer | Java • Spring Boot • Ka...
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
Diabetes mellitus diagnosis method based random forest with bat algorithm
Reach Out and Touch Someone: Haptics and Empathic Computing
Machine learning based COVID-19 study performance prediction
“AI and Expert System Decision Support & Business Intelligence Systems”
Digital-Transformation-Roadmap-for-Companies.pptx
Mobile App Security Testing_ A Comprehensive Guide.pdf
Electronic commerce courselecture one. Pdf
Effective Security Operations Center (SOC) A Modern, Strategic, and Threat-In...
Understanding_Digital_Forensics_Presentation.pptx
Bridging biosciences and deep learning for revolutionary discoveries: a compr...

SplunkLive! Austin Customer Presentation - Baylor

  • 1. Copyright © 2016 Splunk Inc. Baylor University Jon Allen Assistant VP & CISO
  • 2. 2 About Baylor University • Chartered in 1845 • In Waco Texas, the state’s oldest institution of higher learning • Nationally ranked research institution • Private Christian university; world’s largest Baptist university • Tier 1 school among national universities • 17,000 students • 3000-3200 faculty / staff
  • 3. 3 About Me • Assistant VP & CISO — First full time info security employee here at Baylor, here now 17 years — 13 years in information security — Started the security program & built it up from the beginning • BS, Political Science; Masters, Computers Science; CISSP • Forensic examiner, give 6-10 presentations a year, publications • Manage 3 full-time security analysts • Team runs Splunk environment; performs security reviews on new products, security awareness, instant-on response, forensics, vulnerability management, security compliance consulting
  • 4. 4 Before Splunk: Highly Inefficient • It was hard to get the info we needed quickly — Had to log in to each domain controller separately — Local searches and for different roles were tedious • No ability to cross reference & make sense of data • Operating in traditional siloed IT groups • Vendors would decide what was important, and were often wrong • Experiencing account lockouts across domain controllers in high-use environments • End result = poor customer service “We had a good idea of what we needed to know, but it was very hard to get that information in a timely manner.”
  • 5. 5 Choosing Splunk • Splunk started as a small PCI network project — Needed to meet login requirements for processing transactions • We were looking for more than the usual “compliance in a box” • We needed solutions for bigger problems, such as: — Identifying lockouts across domain controllers — Resolving horribly inefficient log, search, and service issues • Splunk gave us tools to pull our data together & cross reference it • Unlike other vendors, Splunk was flexible & allowed us to map risk for the education environment ourselves • It was clear from the beginning, Splunk was a very powerful tool — Ops team loved the applications for them — We helped get the net plus agreement in place (1st school to sign on) “Once our OPS guys got a little taste of Splunk, they were hooked.”
  • 6. 6 Splunk Benefits • From a low headcount staff perspective, our savings have been in resources – people and saving time. Finding information has gone from hours to minutes. • Splunk puts everyone on the same page. Everybody has access to the same information, which breaks down silos. • Information security is about “protecting your treasure” as much as you can. With Splunk, we can quickly see if something is in isolation, a trend or requires action. • It’s not always how can I prevent breaches, but how can I minimize and control them. Splunk is a great tool for that. “Splunk has helped our team build credibility because we’re bringing something to the table that helps people get their jobs done and done well.”
  • 7. 7 Splunk at Baylor University • 400 GB license • Large central IT organization • 30+ users: • Architecture: – Netflow and firewalls largest data sources (firewalls 40 percent of license) – 10 servers – 3 indexers; role-based access control 100+ Universal Forwarders 3 Indexers 3 Search Heads + 1 Deployment Servers
  • 8. 8 Logs & Third-Party Apps at Baylor • DNS monitoring • Radius logs • Crashplan • Qualys • Box, Duo • Cloud services • CloudFlare • Office 365, Microsoft PA
  • 9. Splunk Use Cases Security Visibility/Search/Analytics DashboardsOperational Efficiency Early Use Cases – PCI Compliance, Ops, Troubleshooting
  • 10. 10 Splunk Early Use Cases • PCI compliance • Ops cases: — Mail logs and searches, authentication, AD, Shibboleth • Troubleshooting — Vendor “sent message claims” – easy to verify • Being able to visualize data with illustrations • Security (Phase 1) – SIEM (Security Information & Event Mgmt) “For us, the piece that’s a plus & a minus is you can do so much. You do the first 5 things & then it’s ‘Where does my imagination take me?’”
  • 11. 11 Splunk for Security • We gained proactive security vs. reactive ‘insecurity’ – Real-life fix: When we saw failed Box authentications, research revealed SNMP misconfigurations, not threats – Splunk helps us uncover & resolve those “non-threat” threats • Splunk provides a common language - everyone sees the same thing, independent of different tools • Splunk allows us to build strong relationships and support procedures (ie, we don’t run the firewall/IPS systems but we support the teams that do) • Dealing with the “noise” – IT security is challenged to find the valuable noise among all the noises (malware, phishing, spearing) – We can identify a problem source, talk to the right people & take action in minutes vs. hours (drastic time shrinkage) “In security, you’re not trying to find a needle in a haystack. You’re trying to find a needle in a pile of needles.”
  • 12. 12 Splunk for Visibility/Search/Analytics • The “single pane of glass” is by far the most powerful thing about Splunk — Network logs, traffic logs, authentication are all visible from one screen — Cross referencing is easy and extremely useful — Everyone across the organization can see the same thing • Splunk supports visibility off campus where it’s typically lost – cloud, vendors, Box • Monitoring/real time analytics — Load balancers, firewall connection rates — Having screens up so you can see issues is very helpful “At the end of the day, Splunk is a sandbox for our data. We pull all our data in the sandbox and decide what kind of castle we want to build today.”
  • 13. 13 Splunk for Operational Efficiency “We are all trusted to access read-only data so we know what everybody searches, which helps us move forward and build efficiency into the organization.” • We’ve built a very collaborative environment — Everyone gets “deputized” to do what needs to be done — We work with and support other teams working together (networking, firewall and server teams) — By nature, Splunk fosters collaboration • Splunk has opened up traditional IT silos – server / IT / firewall teams – efficient, effective searches build trust • Cloud computing — Most vendors don’t understand cloud computing -- you’ll lose visibility without the right tools — We know that’s the direction we’ll be going in — Splunk is working on those tools and can take us there
  • 14. 14 Splunk for Dashboards “There can some time and investment in creating a custom dashboard, but the benefit of seeing all that data in one place is huge.” • Our PCI log review dashboard is a significant investment — Our analysts use open source tool OS X for file integrity monitoring; Microsoft log numbers, OS X specs, firewall info — Within a very short time our analyst created a dashboard that includes data to meet log review reqt’s – all in one place • We support many different custom team requests — SysOps needed a dashboard showing who hasn’t had a successful backup after 4 days — Vendor interfaces that normally don’t work easily, can be pulled into Splunk • Predictive analysis - 2 years ago, we created a dashboard that shows network pinch points needing > capacity
  • 15. 15 Splunk A-Ha Moment • Now with Splunk, the security team doesn’t have to be the one pushing initiatives • Example: When we needed to move on a project: — In the past, would have required multiple meetings, hard conversations, going to the highest level — Now, they ask us “Why aren’t you doing this?” — Huge change! • This high-level buy-in only happens with a significantly useful, game-changing tool “The real power and value comes when I start understanding what I need to look like in the future or what may be coming down the line that I haven’t even thought of yet.”
  • 16. 16 Users • Vice President, deputy CIO, associate VPs • OPS team; systems operations • Server and networking team • Web & marketing • Client services; helpdesk, desktop support • Mobile support • Administrative systems • ERPs, database management
  • 17. 17 Splunk Words to the Wise…. • With Splunk, you can jump right in and get your feet wet quickly, but then you have to take that step back and understand what you really want to do. Then you start reaping the benefits more and more. • Avoid the pitfall of underestimating the size of the license you’ll need. • Similarly for your platform, make sure you have sufficient hardware capacity for what you want to do so Splunk can run efficiently. • Make the necessary investments so your platform will perform to meet your users’ needs.
  • 18. 18 Splunking Ahead…. • Greater expansion into cloud services — Microsoft project • Fischer hosted identity management system • Looking for new ways to leverage the investment in Splunk — Potential in managed services — Augmenting staff resources • Greater participation with vendors and Splunk for their customers’ benefit
  • 19. 19 Splunk Successes • Initially Splunk was another tool in the toolbox. Splunk is now our analytics tool, and we’re not renewing our traditional tools anymore. • With Splunk, there’s no finger pointing because we have a place where everybody knows to go for information and that’s been a huge value. It’s becoming a kind of universal expectation within the organization. • Splunk has helped our team provide a valuable service in helping the organization as a whole. 19