Copyright © 2014 Splunk Inc.
July 15th, 2014
ExxonMobil Splunk
Razi Asaduddin
Cyber Security Advisor &
Splunk Shared Service Team Lead
July 15th, 2014
2
About ExxonMobil Corp
2
• Pretty Big - Fortune 1-ish 
• ~50 Countries
• 80,000 Employees
• $32.5bn in earnings in 2013
• 2M Barrels per day
• 11.8bn cubic feet of natural gas
3
About Me – Razi Asaduddin
Cyber Security Technical Advisor
– Monitoring, Process Design, Incident Handling, Threat
Assessment, Malware Reverse Engineering, Digital Forensics
Splunk Shared Service Team Lead
– Designed, Architected, Implemented, Coded, and
Administered Global Splunk Instance
– Responsible for Splunk service and strategy
– In-house consulting for prospective use cases
– Evangelizing, PoCs, modeling, and tool rationalization
Two-year Splunker and 2013 Revolution Award
nominee
• Contact: Razi.asaduddin@gmail.com
4
Agenda
Why Splunk?
How we use Splunk
How we have evolved
Best practices
Future
5
Why Splunk?
Extensibility
Speed
Late-binding Schema
Scalability
6
Why Splunk?
7
Before Splunk
Manual data
Lag Time
Visibility
Silos
Data knowledge
8
How We Use Splunk
Cyber Security
Network
Performance
Application
Performance
Capacity PlanningCall Quality
Misconfiguration
Linux
Administration
9
How We Use Splunk – Cyber Security
• Investigation and Incident Response
• Complex Correlation
• Proactive Alerting
• Auto-remediation 
10
How We Use Splunk – Performance
• Reduce Data to:
– OS + Application + Server + DB + Network + Endpoint Performance
• 10,000 foot view & 1-foot view
• Pivot
11
Thought Process
Gather Correlate Enrich
Visualize
Alert
Action
12
Evolution
One-dimensional
Multi-dimensional
Pivoting
Visualizing
&
Base-lining
13
Best Practices
Ask simple questions and build up
Double-check raw data
What data do we not have?
Splunk it!
Build a Splunk network
Alert on it or automate it
Policing
14
Policing
I’ll just run this at midnight when no one else does 
15
Policing
CPU & Memory Performance
Number of searches
Errors
Long searches
Wall of Shame
16
Fun Stuff
Longest running search – 96 hrs
Longest search text – 80 lines
Magical Midnight – pitfall
Wall of Shame – 
Splunk in life
17
Future
More Visualization - Turn raw events into this:
18
Future
Then reduce:
19
Questions?
Happy -ing!
Thank You

More Related Content

PDF
Managing SCADA Operations and Security with Splunk Enterprise
PPT
SplunkLive! Customer Presentation - Penn State Hershey Medical Center
PPTX
SplunkLive! Customer Presentation - Satcom Direct
PPTX
SplunkLive! Customer Presentation - Cardinal Health
PDF
SplunkLive! Customer Presentation – Harris
PPTX
Managing SCADA Operations and Security with Splunk Enterprise
PPTX
SplunkLive! Atlanta Customer Presentation – Intercontinental Exchange
PPTX
Splunk live! customer presentation – zoosk
Managing SCADA Operations and Security with Splunk Enterprise
SplunkLive! Customer Presentation - Penn State Hershey Medical Center
SplunkLive! Customer Presentation - Satcom Direct
SplunkLive! Customer Presentation - Cardinal Health
SplunkLive! Customer Presentation – Harris
Managing SCADA Operations and Security with Splunk Enterprise
SplunkLive! Atlanta Customer Presentation – Intercontinental Exchange
Splunk live! customer presentation – zoosk

What's hot (20)

PPTX
Protect & Defend Your Critical Infrastructure
PPTX
Splunk for ITOA Breakout Session
PDF
Viasat Customer Presentation
PPTX
Splunk live! Customer Presentation – Wellsfargo
PPTX
Getting Started with Splunk Enterprise
PPTX
Splunk for Industrial Data and the Internet of Things
PDF
Splunk for Industrial Data and the Internet of Things
PDF
Splunk @ Adobe
PPTX
Splunk for ITOA Breakout Session
PPTX
SplunkLive! Utrecht - Splunk for IT Operations - Rick Fitz
PPTX
Splunk for ITOA Breakout Session
PPTX
Splunk Discovery Day Düsseldorf 2016
PPTX
Splunk Internet of Things Roundtable 2015
PPTX
Splunk Discovery: Warsaw 2018 - IT Operations Track
PPTX
Customer Presentation
PPTX
SplunkLive! Customer Presentation – athenahealth
PPTX
Splunk EMEA Webinar: Scoping infections and disrupting breaches
PDF
Splunk Sales Presentation Imagemaker 2014
PPTX
Customer Presentation - KCP&L
PPTX
SplunkLive! Austin Customer Presentation - Dell
Protect & Defend Your Critical Infrastructure
Splunk for ITOA Breakout Session
Viasat Customer Presentation
Splunk live! Customer Presentation – Wellsfargo
Getting Started with Splunk Enterprise
Splunk for Industrial Data and the Internet of Things
Splunk for Industrial Data and the Internet of Things
Splunk @ Adobe
Splunk for ITOA Breakout Session
SplunkLive! Utrecht - Splunk for IT Operations - Rick Fitz
Splunk for ITOA Breakout Session
Splunk Discovery Day Düsseldorf 2016
Splunk Internet of Things Roundtable 2015
Splunk Discovery: Warsaw 2018 - IT Operations Track
Customer Presentation
SplunkLive! Customer Presentation – athenahealth
Splunk EMEA Webinar: Scoping infections and disrupting breaches
Splunk Sales Presentation Imagemaker 2014
Customer Presentation - KCP&L
SplunkLive! Austin Customer Presentation - Dell
Ad

Viewers also liked (6)

PPTX
SplunkLive! Customer Presentation - Denver Water
PPTX
SplunkLive! Philadelphia - University of Scranton
PPTX
SplunkLive! Customer Presentation – Ticketmaster
PDF
Exxon Mobil B2B Project
PDF
[AWSマイスターシリーズ] AWS CLI / AWS Tools for Windows PowerShell
SplunkLive! Customer Presentation - Denver Water
SplunkLive! Philadelphia - University of Scranton
SplunkLive! Customer Presentation – Ticketmaster
Exxon Mobil B2B Project
[AWSマイスターシリーズ] AWS CLI / AWS Tools for Windows PowerShell
Ad

Similar to SplunkLive! Customer Presentation - ExxonMobil (20)

PPTX
Single Glass of Pain: See Your World, Maybe You Wish You Hadn't
PPTX
Danfoss - Splunk for Vulnerability Management
PDF
Big Data Workshop: Splunk and Dell EMC...Better Together
PPTX
AdvancedMD Customer Presentation
PPTX
AdvancedMD Customer Presentation
PPTX
SplunkLive! Customer Presentation – Nissan
PPTX
Getting Started with Splunk Breakout Session
PPTX
Splunk at Sabre
PPTX
Customer Presentation, FirstSolar
PDF
Splunk in the Cisco Unified Computing System (UCS)
PPTX
SplunkLive! Tampa: Using Value to Fuel Adoption
PDF
Gartner Catalyst 2015 Customer Presentation - MindTouch
PPTX
Splunk at Aaron's Inc
PPTX
Taking Splunk to the Next Level - Manager
PPTX
Getting Started with Splunk Breakout Session
PDF
PinTrace Advanced AWS meetup
PDF
Splunk in 60 Minutes | Splunk Tutorial For Beginners | Splunk Training | Splu...
PPTX
SplunkLive! Stockholm 2019 - Customer presentation: ISS
PDF
Best Practices for Ensuring SAP ABAP Code Quality and Security
PPTX
Inside SecOps at bet365
Single Glass of Pain: See Your World, Maybe You Wish You Hadn't
Danfoss - Splunk for Vulnerability Management
Big Data Workshop: Splunk and Dell EMC...Better Together
AdvancedMD Customer Presentation
AdvancedMD Customer Presentation
SplunkLive! Customer Presentation – Nissan
Getting Started with Splunk Breakout Session
Splunk at Sabre
Customer Presentation, FirstSolar
Splunk in the Cisco Unified Computing System (UCS)
SplunkLive! Tampa: Using Value to Fuel Adoption
Gartner Catalyst 2015 Customer Presentation - MindTouch
Splunk at Aaron's Inc
Taking Splunk to the Next Level - Manager
Getting Started with Splunk Breakout Session
PinTrace Advanced AWS meetup
Splunk in 60 Minutes | Splunk Tutorial For Beginners | Splunk Training | Splu...
SplunkLive! Stockholm 2019 - Customer presentation: ISS
Best Practices for Ensuring SAP ABAP Code Quality and Security
Inside SecOps at bet365

More from Splunk (20)

PDF
Splunk Leadership Forum Wien - 20.05.2025
PDF
Splunk Security Update | Public Sector Summit Germany 2025
PDF
Building Resilience with Energy Management for the Public Sector
PDF
IT-Lagebild: Observability for Resilience (SVA)
PDF
Nach dem SOC-Aufbau ist vor der Automatisierung (OFD Baden-Württemberg)
PDF
Monitoring einer Sicheren Inter-Netzwerk Architektur (SINA)
PDF
Praktische Erfahrungen mit dem Attack Analyser (gematik)
PDF
Cisco XDR & Splunk SIEM - stronger together (DATAGROUP Cyber Security)
PDF
Security - Mit Sicherheit zum Erfolg (Telekom)
PDF
One Cisco - Splunk Public Sector Summit Germany April 2025
PDF
.conf Go 2023 - Data analysis as a routine
PDF
.conf Go 2023 - How KPN drives Customer Satisfaction on IPTV
PDF
.conf Go 2023 - Navegando la normativa SOX (Telefónica)
PDF
.conf Go 2023 - Raiffeisen Bank International
PDF
.conf Go 2023 - På liv og død Om sikkerhetsarbeid i Norsk helsenett
PDF
.conf Go 2023 - Many roads lead to Rome - this was our journey (Julius Bär)
PDF
.conf Go 2023 - Das passende Rezept für die digitale (Security) Revolution zu...
PDF
.conf go 2023 - Cyber Resilienz – Herausforderungen und Ansatz für Energiever...
PDF
.conf go 2023 - De NOC a CSIRT (Cellnex)
PDF
conf go 2023 - El camino hacia la ciberseguridad (ABANCA)
Splunk Leadership Forum Wien - 20.05.2025
Splunk Security Update | Public Sector Summit Germany 2025
Building Resilience with Energy Management for the Public Sector
IT-Lagebild: Observability for Resilience (SVA)
Nach dem SOC-Aufbau ist vor der Automatisierung (OFD Baden-Württemberg)
Monitoring einer Sicheren Inter-Netzwerk Architektur (SINA)
Praktische Erfahrungen mit dem Attack Analyser (gematik)
Cisco XDR & Splunk SIEM - stronger together (DATAGROUP Cyber Security)
Security - Mit Sicherheit zum Erfolg (Telekom)
One Cisco - Splunk Public Sector Summit Germany April 2025
.conf Go 2023 - Data analysis as a routine
.conf Go 2023 - How KPN drives Customer Satisfaction on IPTV
.conf Go 2023 - Navegando la normativa SOX (Telefónica)
.conf Go 2023 - Raiffeisen Bank International
.conf Go 2023 - På liv og død Om sikkerhetsarbeid i Norsk helsenett
.conf Go 2023 - Many roads lead to Rome - this was our journey (Julius Bär)
.conf Go 2023 - Das passende Rezept für die digitale (Security) Revolution zu...
.conf go 2023 - Cyber Resilienz – Herausforderungen und Ansatz für Energiever...
.conf go 2023 - De NOC a CSIRT (Cellnex)
conf go 2023 - El camino hacia la ciberseguridad (ABANCA)

Recently uploaded (20)

PDF
sustainability-14-14877-v2.pddhzftheheeeee
PDF
OpenACC and Open Hackathons Monthly Highlights July 2025
PDF
Enhancing emotion recognition model for a student engagement use case through...
PDF
Abstractive summarization using multilingual text-to-text transfer transforme...
PPT
What is a Computer? Input Devices /output devices
PPTX
2018-HIPAA-Renewal-Training for executives
PDF
Hindi spoken digit analysis for native and non-native speakers
PDF
A contest of sentiment analysis: k-nearest neighbor versus neural network
PPTX
Final SEM Unit 1 for mit wpu at pune .pptx
PDF
CloudStack 4.21: First Look Webinar slides
PDF
Convolutional neural network based encoder-decoder for efficient real-time ob...
PDF
Two-dimensional Klein-Gordon and Sine-Gordon numerical solutions based on dee...
PDF
How ambidextrous entrepreneurial leaders react to the artificial intelligence...
PPT
Galois Field Theory of Risk: A Perspective, Protocol, and Mathematical Backgr...
PDF
TrustArc Webinar - Click, Consent, Trust: Winning the Privacy Game
PPT
Geologic Time for studying geology for geologist
PDF
sbt 2.0: go big (Scala Days 2025 edition)
PDF
Credit Without Borders: AI and Financial Inclusion in Bangladesh
PDF
1 - Historical Antecedents, Social Consideration.pdf
PDF
A Late Bloomer's Guide to GenAI: Ethics, Bias, and Effective Prompting - Boha...
sustainability-14-14877-v2.pddhzftheheeeee
OpenACC and Open Hackathons Monthly Highlights July 2025
Enhancing emotion recognition model for a student engagement use case through...
Abstractive summarization using multilingual text-to-text transfer transforme...
What is a Computer? Input Devices /output devices
2018-HIPAA-Renewal-Training for executives
Hindi spoken digit analysis for native and non-native speakers
A contest of sentiment analysis: k-nearest neighbor versus neural network
Final SEM Unit 1 for mit wpu at pune .pptx
CloudStack 4.21: First Look Webinar slides
Convolutional neural network based encoder-decoder for efficient real-time ob...
Two-dimensional Klein-Gordon and Sine-Gordon numerical solutions based on dee...
How ambidextrous entrepreneurial leaders react to the artificial intelligence...
Galois Field Theory of Risk: A Perspective, Protocol, and Mathematical Backgr...
TrustArc Webinar - Click, Consent, Trust: Winning the Privacy Game
Geologic Time for studying geology for geologist
sbt 2.0: go big (Scala Days 2025 edition)
Credit Without Borders: AI and Financial Inclusion in Bangladesh
1 - Historical Antecedents, Social Consideration.pdf
A Late Bloomer's Guide to GenAI: Ethics, Bias, and Effective Prompting - Boha...

SplunkLive! Customer Presentation - ExxonMobil

Editor's Notes

  • #4: Long Walks Father of Splunk @ XOM
  • #10: If not, Detecting, alerting, remediating threats Investigations