SlideShare a Scribd company logo
1 of 63
Copyright	
  ©	
  2015	
  Splunk	
  Inc.
You	
  Can’t	
  Protect	
  
What	
  you	
  Can’t	
  See.
AWS	
  Security	
  Best	
  Practices
Dan	
  Miller,	
  
Director	
  of	
  SplunkCloud,	
  APJ	
  
2
Make	
  machine	
  data	
  accessible,
usable	
  and	
  valuable	
  to	
  everyone.	
  
2
Big	
  Data	
  Comes	
  from	
  Machines
Volume    |    Velocity    |    Variety  |  Variability
GPS,
RFID,
Hypervisor,
Web	
  Servers,
Email,	
  Messaging,
Clickstreams,	
  Mobile,	
  
Telephony,	
  IVR,	
  Databases,
Sensors,	
  Telematics,	
  Storage,
Servers,	
  Security	
   Devices,	
  Desktops	
  
3
Building	
  a	
  Big	
  Data	
  Platform
HA	
  /	
  DR Admin Data	
  Security Apps SDKs/APIScale
Collect
Data
Index
Data
Enrich	
  
Data
Search &	
  
Explore
Analyze
&	
  Predict
Report	
  &
Visualize
Alert	
  &	
  
Action
4
Fully	
  Integrated	
  Enterprise	
  Platform
HA	
  /	
  DR Admin Data	
  Security Apps SDKs/APIScale
Collect
Data
Index
Data
Enrich	
  
Data
Search &	
  
Explore
Analyze
&	
  Predict
Report	
  &
Visualize
Alert	
  &	
  
Action
5
Structured
RDBMS
SQL Search
Schema	
  at	
  Write Schema	
  at	
  Read
Traditional Splunk
Splunk	
  Approach	
  to	
  Machine	
  Data
Copyright © 2014 Splunk Inc.
6
ETL Universal	
  Indexing
Volume Velocity Variety
Unstructured
7
Why	
  Splunk?
FAST TIME-­‐TO-­‐VALUE
ONE	
  PLATFORM,	
  MULTIPLE	
  USE	
  CASES
VISIBILITY	
  ACROSS	
  STACK,	
  NOT	
  JUST	
  SILOS
ASK	
  ANY	
  QUESTION	
  OF	
  DATA
ANY	
  DATA,	
  ANY	
  SOURCE	
  OR	
  DEPLOYMENT	
  MODEL
8
Turning	
  Machine	
  Data	
  Into	
  Business	
  Value
Index	
  Untapped	
  Data:	
  Any	
  Source,	
  Type,	
  Volume
Online	
  
Services Web	
  
Services
Servers
Security GPS	
  
Location
Storage
Desktops
Networks
Packaged	
  
Applications
Custom
ApplicationsMessaging
Telecoms
Online	
  
Shopping	
  
Cart
Web	
  
Clickstreams
Databases
Energy	
  
Meters
Call	
  Detail	
  
Records
Smartphones	
  
and	
  Devices
RFID
On-­‐
Premises
Private	
  
Cloud
Public	
  
Cloud
Ask	
  Any	
  Question
Application	
  Delivery
Security,	
  Compliance	
  
and	
  Fraud
IT	
  Operations
Business	
  Analytics
Industrial	
  Data	
  and
the	
  Internet	
  of	
  Things
IT
Operations
Application	
  
Delivery
Developer	
  Platform	
  (REST	
  API,	
  SDKs)
Business	
  
Analytics
Industrial	
  Data	
  
and	
  Internet	
  of	
  
Things
9
Delivers	
  Value	
  Across	
  IT	
  and	
  the	
  Business
Business	
  
Analytics
Industrial	
  Data	
  
and	
  Internet	
  of	
  
Things
Security,	
  	
  
Compliance
and	
  Fraud
10
Platform	
  for	
  Application	
  Delivery
and	
  IT	
  Operations
ROOT	
  CAUSE	
  
AND ISSUE	
  
RESOLUTION
PROACTIVE
MONITORING	
  
AND	
  REAL-­‐TIME	
  
ALERTING
DELIVER	
  BETTER	
  
QUALITY	
  CODE	
  
FASTER
CLOUD	
  APP	
  AND	
  
INFRASTRUCTURE	
  
MONITORING
MOBILE	
  APP
TROUBLESHOOTING
USER	
  &	
  USAGE	
  
ANALYTICS
Better	
  Code,	
  Faster	
  Development	
  
and	
  Migration	
  to	
  Cloud
• Reduced	
  error	
  rates	
  by	
  2	
  orders	
  of	
  magnitude	
  in	
  a	
  couple	
  of	
  weeks
• Rapidly	
  found	
  and	
  fixed	
  one	
  line	
  of	
  code	
  responsible	
  for	
  30,000+	
  errors
• Real-­‐time	
  dashboards	
  on	
  error	
  rates	
  and	
  production	
  impact	
  
• In-­‐depth	
  visibility	
  as	
  they	
  strategically	
  migrate	
  apps	
  to	
  AWS	
  Cloud
12
Apps	
  for	
  Application	
  Delivery	
  and	
  IT	
  Ops
Splunk	
  Apps	
  
for	
  VMware	
  and	
  
Exchange
300+	
  IT	
  Ops	
  and	
  App	
  
Delivery	
  Apps
*nix
Operational	
  Intelligence	
  
for	
  Mobile	
  Apps
13
Application	
  Delivery	
  &	
  IT	
  Ops	
  Landscape
API
SDKs UI
Server,	
  Storage,	
  
Network
Server	
  
Virtualization
Operating	
  
Systems
Custom	
  	
  
Applications
Business	
  	
  
Applications
Cloud	
  
Services
App	
  Performance	
  
MonitoringTicketing/Other
Web	
  Intelligence
Mobile	
  
Applications
Stream
14
Splunk	
  App	
  for	
  AWS
EC2
EMR
Kinesis
R53
VPC
ELB
S3
CloudFront
CloudTrail
CloudWatch
Redshift
SNS
API Gateway
Config
RDS
CF
IAM
Lambda
Explore Analyze Dashboard Alert Act
AWS	
  Data	
  Sources
End	
  State:	
  Comprehensive	
  AWS	
  Visibility
Splunk	
  IT	
  Service	
  Intelligence	
  at
1
Replaced	
  home-­‐
grown	
  tools
Real-­‐time	
  service	
  
insights to	
  LOBs
Reduced	
  time	
  to	
  
resolution
Splunk	
  IT	
  Service	
  Intelligence	
  at
1
“Splunk IT	
  Service	
  Intelligence	
  was	
  
delivering	
  insights	
  days	
  after	
  
installing,	
  instead	
  of	
  the	
  months	
  it	
  
can	
  take	
  legacy	
  monitoring	
  
solutions.	
  Splunk ITSI	
  helps	
  us	
  
ensure	
  that the	
  claims	
  service	
  stays	
  
up	
  and	
  running at	
  all	
  times.”	
  -­‐ Tyler	
  
Germer,	
  director	
  of	
  information	
  
technology,	
   AdvancedMD.	
  
17
Single	
  Platform	
  for	
  Security	
  Intelligence
SECURITY	
  &	
  	
  	
  	
  	
  	
  	
  	
  	
  	
  
COMPLIANCE	
  
REPORTING
REAL-­‐TIME	
  
MONITORING	
  OF	
  
KNOWN	
  THREATS
DETECT	
  
UNKNOWN	
  
THREATS
INCIDENT	
  
INVESTIGATIONS	
  
&	
  FORENSICS
FRAUD	
  
DETECTION
INSIDER	
  
THREAT
Splunk	
  Complements,	
  Replaces	
  and	
  Goes	
  Beyond	
  Existing	
  SIEMs
How	
  FINRA	
  Uses	
  Splunk	
  Cloud	
  for	
  Security
• Transforms	
  third-­‐party	
  threat	
  intelligence	
  information	
  into	
  security	
  alerts
• Leverages	
  the	
  Splunk	
  App	
  for	
  AWS
• Efficient	
  provisioning	
  dramatically	
  reduces	
  costs
“Splunk	
  Cloud	
  gives	
  you	
  applications	
   which	
  let	
  you	
  get	
  huge	
  amounts	
  of	
  value	
  from	
  your	
  data.”
— Sr.	
  Director	
  of	
  Information	
  Security
API
SDKs UI
Network	
  Traffic	
  
Analysis
Identity	
  &	
  Access	
  
Control
Perimeter	
  
Defense
EmailPayload	
  Analysis
Endpoint	
  Behavior	
  
Analysis
Endpoint	
  Change	
  
Tracking
DLP
Security	
  Analytics
Threat	
  Intelligence
Cloud	
  Security
Security	
  &	
  Compliance	
  Landscape
19
20
Extending	
  Splunk	
  for	
  Business	
  Analytics
Splunk	
  Software	
  Complements	
  Existing	
  BI	
  Solutions
CUSTOMER	
  
EXPERIENCE
PRODUCT	
  
ANALYTICS
BUSINESS	
  
PROCESS	
  
ANALYTICS
DIGITAL
MARKETING
Why	
  Domino’s	
  uses	
  Splunk	
  for	
  Application	
  
Management	
  and	
  Business	
  Analytics
• Understand	
  device	
  and	
  app	
  usage	
  trends	
  for	
  orders
• Real-­‐time	
  reNex insights	
  from	
  store	
  data
• Visibility	
  into	
  online	
  and	
  mobile	
  coupon	
  redemption
• Refine	
  Campaigns	
  for	
  higher	
  conversion
22
Apps	
  &	
  Capabilities	
  for	
  Business	
  Analytics
Apps,	
  Features	
  &	
  Partners
• DB	
  Connect
• Stream
• ODBC	
  Driver
• Data	
  Models
• Pivot
IT
Operations
Security,	
  	
  
Compliance
and	
  Fraud
Application	
  
Delivery
Developer	
  Platform	
  (REST	
  API,	
  SDKs)
Business	
  
Analytics
Industrial	
  Data	
  
and	
  Internet	
  of	
  
Things
23
Delivers	
  Value	
  Across	
  IT	
  and	
  the	
  Business
24
Splunk	
  for	
  Industrial	
  Data	
  &	
  the	
  
Internet	
  of	
  Things
REMOTE
TROUBLESHOOTING	
  
&	
  PREVENTIVE	
  
MAINTENANCE
SECURITY	
  &
COMPLIANCE
DEVICE	
  USAGE	
  &
CUSTOMER	
  
ANALYTICS
OPERATIONAL
EFFICIENCY
Saving	
  Customers	
  $Billions	
  
on	
  Fuel,	
  Operations
• Improved	
  customer	
  operations	
  by	
  mining	
  large	
  volumes	
  of	
  unstructured	
  data
• Moved	
  from	
  monthly	
  batch	
  analysis	
  to	
  flexible	
  real-­‐time	
  reporting
• Delivered	
  value-­‐added	
  services
• Minimized	
  in-­‐train	
  forces
• Optimized	
  operational	
  efficiency
“Thanks	
  to	
  Splunk,	
  our	
  systems	
  allow	
  our	
  customers	
  to	
  provide	
  engineers	
  with	
  real-­‐time	
  feedback	
  
and	
  use	
  operational	
   insight	
  to	
  achieve	
  optimal	
   runs	
  every	
  time.”	
  
— Director	
  of	
  Engineering,	
  Train	
  Dynamic	
  Systems	
  (a	
  division	
  of	
  NYAB)	
  
Apps	
  &	
  Capabilities	
  for	
  Industrial	
  Data	
  
&	
  Internet	
  of	
  Things
• DBConnect
• REST	
  API	
  and	
  SNMP	
  
Modular	
  Inputs
• Universal	
  Forwarder	
  
for	
  Raspberry	
  Pi
Apps,	
  Features	
  &	
  Partners
REST
26
27
All	
  the	
  features	
  of	
  Splunk	
  Enterprise
All	
  the	
  benefits	
  of	
  SaaS
Hybrid
28
Search Head(s)
Indexer(s)
On Premises Private Cloud Public Cloud
Search Head(s)
Indexer(s)
On Premises Private Cloud Public Cloud
Hybrid	
  Search
Single	
  Pane	
  of	
  Glass	
  Visibility
Platform	
  for	
  Operational	
  Intelligence
The	
  Splunk	
  Portfolio
Rich	
  Ecosystem	
  of
Apps	
  &	
  Add-­‐Ons
Splunk	
  Premium
Solutions
Mainframe
Data
Relational
Databases
MobileForwarders Syslog/TCP
IoT
Devices
Network
Wire	
  Data
Hadoop
Dev.splunk.com40,000+	
  questions
and	
  answers
1,000+	
  apps Local	
  User	
  Groups	
  
and
SplunkLive!	
  events
30
Thriving	
  Community
COLLECT	
  DATA	
  
FROM	
  ANYWHERE
SEARCH
AND	
  ANALYZE	
  
EVERYTHING
GAIN	
  REAL-­‐TIME	
  
OPERATIONAL	
  
INTELLIGENCE
The	
  Power	
  of	
  Splunk
31
FREE	
  
CLOUD	
  TRIAL
FREE	
  
DOWNLOAD
FREE	
  
AMAZON	
  MACHINE	
  
IMAGES	
  (AMI)
32
Easy	
  to	
  Try	
  &	
  Get	
  Started
1 32
Thank	
  you
ANDREW WURSTER
Monitor (allthethings)
with Splunk
Monitor
How we use Splunk
Why we chose Splunk
All about Atlassian
with
All About
Atlassian
Journey to the Cloud
Meet the Security
Team
All About Atlassian
Our software helps unleash the potential in every
Growing Quickly
Atlassian’sSecurity Team
All Things Security
Atlassian Embraces the Cloud
Why We
Chose
Splunk Industry Standard
What’s the MVP / MVE for our team?
At what cost?
Partner vs Buy
Buy from someone you know; not just a
single transaction.
Build vs Buy
Onboarding and Interoperability are
key.
COGS Time to Ship Support
Partner vs Buy
Who You Know Integrations Common Users
Industry Standard
Hiring Interoperability Ease of X
How we
Use
Splunk
Integrations
Investigations
Playbook
In the beginning…
Version 1.0 Version 2.0
What we have today.
Security Team VPC
Splunk Clusterw
CloudFormations
Data Archives to S3
Data Feeds
via Kinesis
Search Tier w ELB
Future ProofingSovereigntyScale
What we have today.
Security Intel
Playbook
Investigations
Integrations
Thank you!
Copyright	
  ©	
  2015	
  Splunk	
  Inc.
Splunk App	
  for	
  AWS
Splunk	
  Offerings	
  in	
  AWS
• Splunk	
  App	
  for	
  
AWS:	
  Integrates	
  
w/CloudTrail,	
  
Config	
  and	
  Billing,	
  
VPC	
  Flow	
  Logs
Integrations• Self-­‐managed	
  cloud	
  
deployments
• Self-­‐deploy	
  in	
  AWS
• Integrated	
  with	
  EMR
• Search	
  data	
  in	
  S3
• Hourly	
  pricing	
  
Self-­‐managed
• Cloud	
  service	
  
designed	
  for	
  small	
  IT	
  
environments
• $90	
  a	
  month
• Splunk	
  Enterprise	
  
as	
  a	
  service
• Full	
  app,	
  SDK,	
  API,	
  
platform	
  support
Cloud-­‐service
AWS	
  Architecture	
  Diagram
Amazon	
  Instances
Amazon	
  Logging	
  Layer
Amazon	
  Messaging
Amazon	
  Storage	
  /	
  Queues
Splunk	
  Collects	
  the	
  data	
  
from	
  the	
  AWS	
  SQS	
  and	
  
the	
  S3	
  bucket	
  using	
  the	
  
AWS	
  SDK	
  for	
  python	
  
(Boto3).
S3 Bucket
AWS ConfigAWS CloudTrail
AWS CloudWatch
AWS SQS
AWS SNSSNS Topic
AWS Instance
with CloudWatch
VPC Flow
Logs
Requirements	
  For	
  Splunk	
  App	
  For	
  AWS
• Splunk
• Splunk	
  6.1	
  or	
  later
• Splunk	
  Add-­‐on	
  for	
  Amazon	
  
Web	
  Services
• Splunk	
  Add-­‐on	
  for	
  Amazon	
  
Web	
  Services	
  +1.1.0	
  
required	
  for	
  AWS	
  Config
• AWS
• AWS	
  CloudTrail:	
  Enable	
  CloudTrail	
  
with	
  SQS	
  and	
  SNS.	
  
• AWS	
  Config:	
  Enable	
  Config	
  with	
  
SQS	
  and	
  SNS.	
  
• Billing:	
  Refer	
  to	
  the	
  AWS	
  
documentation	
  to	
  turn	
  on	
  AWS	
  
detailed	
  billing.	
  
• VPC	
  Flow	
  Logs:	
  Enable	
  VPC	
  Flow	
  
log	
  collection.
Install	
  the	
  Splunk	
  Add-­‐on	
  for	
  AWS
1.	
  Configure	
  your	
  AWS	
  accounts	
  and	
  services,	
  or	
  confirm	
  your	
  existing	
  
configurations.
2.	
  Configure	
  your	
  AWS	
  account	
  permissions	
  to	
  match	
  those	
  required	
  
by	
  the	
  add-­‐on.
3.	
  Install	
  the	
  add-­‐on.
4.	
  Set	
  up	
  the	
  add-­‐on	
  on	
  your	
  forwarders	
  or	
  single	
  instance.
5.	
  Configure	
  your	
  inputs	
  to	
  get	
  your	
  AWS	
  data	
  into	
  Splunk Enterprise.
6.	
  This	
  is	
  all	
  very	
  well	
  documented	
  at	
  docs.splunk.com
Permissions
S3	
  Storage
CloudTrail
API	
  Tracking
SNS	
  Notification
SQS	
  Message	
  Queue
splunkuser
Sample	
  permissions	
  for	
  cloudtrail
Splunk	
  Architecture
• Distributed	
  Splunk	
  
Deployment
Single	
  Splunk	
  Deployment
Splunk'server
Indexer
Heavy+Weight+
Forwarder
Splunk+search
IndexerIndexer
Splunk	
  Add-­‐
on	
  for	
  AWS	
  
installed	
  on	
  
Heavy	
  Weight	
  
Forwarder
Splunk	
  App	
  
for	
  AWS	
  
installed	
  on	
  
all-­‐in-­‐one	
  
Splunk	
  server
Setup	
  Interface
Add	
  Your	
  
Account
Add	
  your	
  
AWS	
  
Inputs
Wait	
  5	
  – 10	
  Minutes
• Yes,	
  you’ll	
  need	
  to	
  wait	
  before	
  all	
  the	
  dashboards	
  and	
  reports	
  populate.
Gain	
  Visibility	
  Into	
  AWS	
  Logs
THANKYOU

More Related Content

What's hot

Aws-What You Need to Know_Simon Elisha
Aws-What You Need to Know_Simon ElishaAws-What You Need to Know_Simon Elisha
Aws-What You Need to Know_Simon ElishaHelen Rogers
 
How Splunk and AWS Enabled End-to-End Visibility for PagerDuty and Bolstered ...
How Splunk and AWS Enabled End-to-End Visibility for PagerDuty and Bolstered ...How Splunk and AWS Enabled End-to-End Visibility for PagerDuty and Bolstered ...
How Splunk and AWS Enabled End-to-End Visibility for PagerDuty and Bolstered ...Amazon Web Services
 
Security and Compliance – Most Commonly Asked Questions - Technical 101
Security and Compliance – Most Commonly Asked Questions - Technical 101Security and Compliance – Most Commonly Asked Questions - Technical 101
Security and Compliance – Most Commonly Asked Questions - Technical 101Amazon Web Services
 
AWS re:Invent 2016: The Psychology of Security Automation (SAC307)
AWS re:Invent 2016: The Psychology of Security Automation (SAC307)AWS re:Invent 2016: The Psychology of Security Automation (SAC307)
AWS re:Invent 2016: The Psychology of Security Automation (SAC307)Amazon Web Services
 
Automating nist 800 171 compliance in AWS Govcloud (US)
Automating nist 800 171 compliance in AWS Govcloud (US)Automating nist 800 171 compliance in AWS Govcloud (US)
Automating nist 800 171 compliance in AWS Govcloud (US)Amazon Web Services
 
What Organizational and Governance Changes Do I Need to Make Prior to Migrati...
What Organizational and Governance Changes Do I Need to Make Prior to Migrati...What Organizational and Governance Changes Do I Need to Make Prior to Migrati...
What Organizational and Governance Changes Do I Need to Make Prior to Migrati...Amazon Web Services
 
Opening Keynote - AWS Summit SG 2017
Opening Keynote - AWS Summit SG 2017Opening Keynote - AWS Summit SG 2017
Opening Keynote - AWS Summit SG 2017Amazon Web Services
 
AWS re:Invent 2016: Delighting Customers Through Device Data with Salesforce ...
AWS re:Invent 2016: Delighting Customers Through Device Data with Salesforce ...AWS re:Invent 2016: Delighting Customers Through Device Data with Salesforce ...
AWS re:Invent 2016: Delighting Customers Through Device Data with Salesforce ...Amazon Web Services
 
AWS Security for Financial Services
AWS Security for Financial ServicesAWS Security for Financial Services
AWS Security for Financial ServicesAmazon Web Services
 
AWS Security Enabiling Fintech Pace Security AWS Summit SG 2017
AWS Security Enabiling Fintech Pace Security AWS Summit SG 2017 AWS Security Enabiling Fintech Pace Security AWS Summit SG 2017
AWS Security Enabiling Fintech Pace Security AWS Summit SG 2017 Amazon Web Services
 
Security and Compliance Better on AWS_John Hildebrandt
Security and Compliance Better on AWS_John HildebrandtSecurity and Compliance Better on AWS_John Hildebrandt
Security and Compliance Better on AWS_John HildebrandtHelen Rogers
 
Automating Security in Cloud Workloads with DevSecOps
Automating Security in Cloud Workloads with DevSecOpsAutomating Security in Cloud Workloads with DevSecOps
Automating Security in Cloud Workloads with DevSecOpsAmazon Web Services
 
Accelerate your Cloud Success with Platform Services
Accelerate your Cloud Success with Platform ServicesAccelerate your Cloud Success with Platform Services
Accelerate your Cloud Success with Platform ServicesAmazon Web Services
 
AWS re:Invent 2016: Unlocking the Four Seasons of Migrations and Operations: ...
AWS re:Invent 2016: Unlocking the Four Seasons of Migrations and Operations: ...AWS re:Invent 2016: Unlocking the Four Seasons of Migrations and Operations: ...
AWS re:Invent 2016: Unlocking the Four Seasons of Migrations and Operations: ...Amazon Web Services
 
3 Secrets to Becoming a Cloud Security Superhero
3 Secrets to Becoming a Cloud Security Superhero 3 Secrets to Becoming a Cloud Security Superhero
3 Secrets to Becoming a Cloud Security Superhero Amazon Web Services
 
Architecting Application Services For Hybrid Cloud - AWS Summit SG 2017
Architecting Application Services For Hybrid Cloud - AWS Summit SG 2017Architecting Application Services For Hybrid Cloud - AWS Summit SG 2017
Architecting Application Services For Hybrid Cloud - AWS Summit SG 2017Amazon Web Services
 
Your Business at the Speed of Cloud. Innovate with Cloud-Native App Delivery,...
Your Business at the Speed of Cloud. Innovate with Cloud-Native App Delivery,...Your Business at the Speed of Cloud. Innovate with Cloud-Native App Delivery,...
Your Business at the Speed of Cloud. Innovate with Cloud-Native App Delivery,...Amazon Web Services
 
How Can I Build a Landing Zone & Extend my Operations into AWS to Support my ...
How Can I Build a Landing Zone & Extend my Operations into AWS to Support my ...How Can I Build a Landing Zone & Extend my Operations into AWS to Support my ...
How Can I Build a Landing Zone & Extend my Operations into AWS to Support my ...Amazon Web Services
 

What's hot (20)

Aws-What You Need to Know_Simon Elisha
Aws-What You Need to Know_Simon ElishaAws-What You Need to Know_Simon Elisha
Aws-What You Need to Know_Simon Elisha
 
How Splunk and AWS Enabled End-to-End Visibility for PagerDuty and Bolstered ...
How Splunk and AWS Enabled End-to-End Visibility for PagerDuty and Bolstered ...How Splunk and AWS Enabled End-to-End Visibility for PagerDuty and Bolstered ...
How Splunk and AWS Enabled End-to-End Visibility for PagerDuty and Bolstered ...
 
Security and Compliance – Most Commonly Asked Questions - Technical 101
Security and Compliance – Most Commonly Asked Questions - Technical 101Security and Compliance – Most Commonly Asked Questions - Technical 101
Security and Compliance – Most Commonly Asked Questions - Technical 101
 
AWS re:Invent 2016: The Psychology of Security Automation (SAC307)
AWS re:Invent 2016: The Psychology of Security Automation (SAC307)AWS re:Invent 2016: The Psychology of Security Automation (SAC307)
AWS re:Invent 2016: The Psychology of Security Automation (SAC307)
 
Automating nist 800 171 compliance in AWS Govcloud (US)
Automating nist 800 171 compliance in AWS Govcloud (US)Automating nist 800 171 compliance in AWS Govcloud (US)
Automating nist 800 171 compliance in AWS Govcloud (US)
 
What Organizational and Governance Changes Do I Need to Make Prior to Migrati...
What Organizational and Governance Changes Do I Need to Make Prior to Migrati...What Organizational and Governance Changes Do I Need to Make Prior to Migrati...
What Organizational and Governance Changes Do I Need to Make Prior to Migrati...
 
AWS Security and Compliance
AWS Security and ComplianceAWS Security and Compliance
AWS Security and Compliance
 
Opening Keynote - AWS Summit SG 2017
Opening Keynote - AWS Summit SG 2017Opening Keynote - AWS Summit SG 2017
Opening Keynote - AWS Summit SG 2017
 
AWS re:Invent 2016: Delighting Customers Through Device Data with Salesforce ...
AWS re:Invent 2016: Delighting Customers Through Device Data with Salesforce ...AWS re:Invent 2016: Delighting Customers Through Device Data with Salesforce ...
AWS re:Invent 2016: Delighting Customers Through Device Data with Salesforce ...
 
AWS Security for Financial Services
AWS Security for Financial ServicesAWS Security for Financial Services
AWS Security for Financial Services
 
AWS Security Enabiling Fintech Pace Security AWS Summit SG 2017
AWS Security Enabiling Fintech Pace Security AWS Summit SG 2017 AWS Security Enabiling Fintech Pace Security AWS Summit SG 2017
AWS Security Enabiling Fintech Pace Security AWS Summit SG 2017
 
New Achitectures
New AchitecturesNew Achitectures
New Achitectures
 
Security and Compliance Better on AWS_John Hildebrandt
Security and Compliance Better on AWS_John HildebrandtSecurity and Compliance Better on AWS_John Hildebrandt
Security and Compliance Better on AWS_John Hildebrandt
 
Automating Security in Cloud Workloads with DevSecOps
Automating Security in Cloud Workloads with DevSecOpsAutomating Security in Cloud Workloads with DevSecOps
Automating Security in Cloud Workloads with DevSecOps
 
Accelerate your Cloud Success with Platform Services
Accelerate your Cloud Success with Platform ServicesAccelerate your Cloud Success with Platform Services
Accelerate your Cloud Success with Platform Services
 
AWS re:Invent 2016: Unlocking the Four Seasons of Migrations and Operations: ...
AWS re:Invent 2016: Unlocking the Four Seasons of Migrations and Operations: ...AWS re:Invent 2016: Unlocking the Four Seasons of Migrations and Operations: ...
AWS re:Invent 2016: Unlocking the Four Seasons of Migrations and Operations: ...
 
3 Secrets to Becoming a Cloud Security Superhero
3 Secrets to Becoming a Cloud Security Superhero 3 Secrets to Becoming a Cloud Security Superhero
3 Secrets to Becoming a Cloud Security Superhero
 
Architecting Application Services For Hybrid Cloud - AWS Summit SG 2017
Architecting Application Services For Hybrid Cloud - AWS Summit SG 2017Architecting Application Services For Hybrid Cloud - AWS Summit SG 2017
Architecting Application Services For Hybrid Cloud - AWS Summit SG 2017
 
Your Business at the Speed of Cloud. Innovate with Cloud-Native App Delivery,...
Your Business at the Speed of Cloud. Innovate with Cloud-Native App Delivery,...Your Business at the Speed of Cloud. Innovate with Cloud-Native App Delivery,...
Your Business at the Speed of Cloud. Innovate with Cloud-Native App Delivery,...
 
How Can I Build a Landing Zone & Extend my Operations into AWS to Support my ...
How Can I Build a Landing Zone & Extend my Operations into AWS to Support my ...How Can I Build a Landing Zone & Extend my Operations into AWS to Support my ...
How Can I Build a Landing Zone & Extend my Operations into AWS to Support my ...
 

Viewers also liked

Splunk Distributed Management Console
Splunk Distributed Management Console                                         Splunk Distributed Management Console
Splunk Distributed Management Console Splunk
 
Splunk conf2014 - Splunk Monitoring - New Native Tools for Monitoring your Sp...
Splunk conf2014 - Splunk Monitoring - New Native Tools for Monitoring your Sp...Splunk conf2014 - Splunk Monitoring - New Native Tools for Monitoring your Sp...
Splunk conf2014 - Splunk Monitoring - New Native Tools for Monitoring your Sp...Splunk
 
Beyond the Hype: Security Experts Weigh in on Artificial Intelligence, Machin...
Beyond the Hype: Security Experts Weigh in on Artificial Intelligence, Machin...Beyond the Hype: Security Experts Weigh in on Artificial Intelligence, Machin...
Beyond the Hype: Security Experts Weigh in on Artificial Intelligence, Machin...Ryan G. Murphy
 
AWS on Splunk, Splunk on AWS
AWS on Splunk, Splunk on AWSAWS on Splunk, Splunk on AWS
AWS on Splunk, Splunk on AWSSplunk
 
AWS Black Belt Tips - Technical 401
AWS Black Belt Tips - Technical 401AWS Black Belt Tips - Technical 401
AWS Black Belt Tips - Technical 401Amazon Web Services
 
Seven Key Elements of a Successful Encryption Strategy
Seven Key Elements of a Successful Encryption StrategySeven Key Elements of a Successful Encryption Strategy
Seven Key Elements of a Successful Encryption StrategySirius
 
Driving Efficiency with Splunk Cloud at Gatwick Airport
Driving Efficiency with Splunk Cloud at Gatwick AirportDriving Efficiency with Splunk Cloud at Gatwick Airport
Driving Efficiency with Splunk Cloud at Gatwick AirportSplunk
 
κεφ.33 οι οθωμανοί τούρκοι κατακτούν βυζαντινά εδάφη
κεφ.33 οι οθωμανοί τούρκοι κατακτούν βυζαντινά εδάφηκεφ.33 οι οθωμανοί τούρκοι κατακτούν βυζαντινά εδάφη
κεφ.33 οι οθωμανοί τούρκοι κατακτούν βυζαντινά εδάφηatavar
 
Session Sponsored by Splunk: Splunk for the Cloud, in the Cloud
Session Sponsored by Splunk: Splunk for the Cloud, in the CloudSession Sponsored by Splunk: Splunk for the Cloud, in the Cloud
Session Sponsored by Splunk: Splunk for the Cloud, in the CloudAmazon Web Services
 
Deploying Splunk. Arquitetura e dimensionamento do Splunk
Deploying Splunk. Arquitetura e dimensionamento do SplunkDeploying Splunk. Arquitetura e dimensionamento do Splunk
Deploying Splunk. Arquitetura e dimensionamento do SplunkSplunk
 

Viewers also liked (10)

Splunk Distributed Management Console
Splunk Distributed Management Console                                         Splunk Distributed Management Console
Splunk Distributed Management Console
 
Splunk conf2014 - Splunk Monitoring - New Native Tools for Monitoring your Sp...
Splunk conf2014 - Splunk Monitoring - New Native Tools for Monitoring your Sp...Splunk conf2014 - Splunk Monitoring - New Native Tools for Monitoring your Sp...
Splunk conf2014 - Splunk Monitoring - New Native Tools for Monitoring your Sp...
 
Beyond the Hype: Security Experts Weigh in on Artificial Intelligence, Machin...
Beyond the Hype: Security Experts Weigh in on Artificial Intelligence, Machin...Beyond the Hype: Security Experts Weigh in on Artificial Intelligence, Machin...
Beyond the Hype: Security Experts Weigh in on Artificial Intelligence, Machin...
 
AWS on Splunk, Splunk on AWS
AWS on Splunk, Splunk on AWSAWS on Splunk, Splunk on AWS
AWS on Splunk, Splunk on AWS
 
AWS Black Belt Tips - Technical 401
AWS Black Belt Tips - Technical 401AWS Black Belt Tips - Technical 401
AWS Black Belt Tips - Technical 401
 
Seven Key Elements of a Successful Encryption Strategy
Seven Key Elements of a Successful Encryption StrategySeven Key Elements of a Successful Encryption Strategy
Seven Key Elements of a Successful Encryption Strategy
 
Driving Efficiency with Splunk Cloud at Gatwick Airport
Driving Efficiency with Splunk Cloud at Gatwick AirportDriving Efficiency with Splunk Cloud at Gatwick Airport
Driving Efficiency with Splunk Cloud at Gatwick Airport
 
κεφ.33 οι οθωμανοί τούρκοι κατακτούν βυζαντινά εδάφη
κεφ.33 οι οθωμανοί τούρκοι κατακτούν βυζαντινά εδάφηκεφ.33 οι οθωμανοί τούρκοι κατακτούν βυζαντινά εδάφη
κεφ.33 οι οθωμανοί τούρκοι κατακτούν βυζαντινά εδάφη
 
Session Sponsored by Splunk: Splunk for the Cloud, in the Cloud
Session Sponsored by Splunk: Splunk for the Cloud, in the CloudSession Sponsored by Splunk: Splunk for the Cloud, in the Cloud
Session Sponsored by Splunk: Splunk for the Cloud, in the Cloud
 
Deploying Splunk. Arquitetura e dimensionamento do Splunk
Deploying Splunk. Arquitetura e dimensionamento do SplunkDeploying Splunk. Arquitetura e dimensionamento do Splunk
Deploying Splunk. Arquitetura e dimensionamento do Splunk
 

Similar to You Can't Protect What you Can't See. AWS Security Best Practices - Session Sponsored by Splunk

AWS Summit Auckland - Sponsor Presentation - Splunk
AWS Summit Auckland - Sponsor Presentation - SplunkAWS Summit Auckland - Sponsor Presentation - Splunk
AWS Summit Auckland - Sponsor Presentation - SplunkAmazon Web Services
 
Splunk company overview april. 2015
Splunk company overview   april. 2015Splunk company overview   april. 2015
Splunk company overview april. 2015Timur Bagirov
 
Splunk for IT Operations
Splunk for IT OperationsSplunk for IT Operations
Splunk for IT OperationsSplunk
 
Virtual Gov Day - Application Delivery Breakout - Overview
Virtual Gov Day - Application Delivery Breakout - OverviewVirtual Gov Day - Application Delivery Breakout - Overview
Virtual Gov Day - Application Delivery Breakout - OverviewSplunk
 
What's New in 6.3 + Data On-Boarding
What's New in 6.3 + Data On-BoardingWhat's New in 6.3 + Data On-Boarding
What's New in 6.3 + Data On-BoardingSplunk
 
Splunk live london_grs
Splunk live london_grsSplunk live london_grs
Splunk live london_grsjenny_splunk
 
Webinar splunk cloud saa s plattform für operational intelligence
Webinar splunk cloud   saa s plattform für operational intelligenceWebinar splunk cloud   saa s plattform für operational intelligence
Webinar splunk cloud saa s plattform für operational intelligenceGeorg Knon
 
Don’t Fly Blind – Gain AWS Visibility to Ensure Security and Optimise Operati...
Don’t Fly Blind – Gain AWS Visibility to Ensure Security and Optimise Operati...Don’t Fly Blind – Gain AWS Visibility to Ensure Security and Optimise Operati...
Don’t Fly Blind – Gain AWS Visibility to Ensure Security and Optimise Operati...Amazon Web Services
 
New Splunk Management Solutions Update: Splunk MINT and Splunk App for Stream
New Splunk Management Solutions Update: Splunk MINT and Splunk App for Stream New Splunk Management Solutions Update: Splunk MINT and Splunk App for Stream
New Splunk Management Solutions Update: Splunk MINT and Splunk App for Stream Splunk
 
Splunk for IT Operations Breakout Session
Splunk for IT Operations Breakout SessionSplunk for IT Operations Breakout Session
Splunk for IT Operations Breakout SessionGeorg Knon
 
SplunkLive! - Splunk for IT Operations
SplunkLive! - Splunk for IT OperationsSplunkLive! - Splunk for IT Operations
SplunkLive! - Splunk for IT OperationsSplunk
 
SplunkLive! São Paulo 2014 - Overview by markus zirn
SplunkLive! São Paulo 2014 -  Overview by markus zirnSplunkLive! São Paulo 2014 -  Overview by markus zirn
SplunkLive! São Paulo 2014 - Overview by markus zirnSplunk
 
Real-time Visibility at Scale with Sumo Logic
Real-time Visibility at Scale with Sumo LogicReal-time Visibility at Scale with Sumo Logic
Real-time Visibility at Scale with Sumo LogicAmazon Web Services
 
Splunk for IT Operations
Splunk for IT OperationsSplunk for IT Operations
Splunk for IT OperationsSplunk
 
SplunkLive! München 2016 - Splunk Enterprise 6.3 - Data Onboarding
SplunkLive! München 2016 - Splunk Enterprise 6.3 - Data OnboardingSplunkLive! München 2016 - Splunk Enterprise 6.3 - Data Onboarding
SplunkLive! München 2016 - Splunk Enterprise 6.3 - Data OnboardingSplunk
 
SplunkLive! Splunk for IT Operations
SplunkLive! Splunk for IT OperationsSplunkLive! Splunk for IT Operations
SplunkLive! Splunk for IT OperationsSplunk
 
Splunk Discovery Day Düsseldorf 2016 - Splunk für IT Operations
Splunk Discovery Day Düsseldorf 2016 - Splunk für IT OperationsSplunk Discovery Day Düsseldorf 2016 - Splunk für IT Operations
Splunk Discovery Day Düsseldorf 2016 - Splunk für IT OperationsSplunk
 
SplunkLive! - Splunk for IT Operations
SplunkLive! - Splunk for IT OperationsSplunkLive! - Splunk for IT Operations
SplunkLive! - Splunk for IT OperationsSplunk
 
Splunk introduction
Splunk introductionSplunk introduction
Splunk introductionTruong Cuong
 
Vancouver keynote - AWS Innovate - Sam Elmalak
Vancouver keynote - AWS Innovate - Sam ElmalakVancouver keynote - AWS Innovate - Sam Elmalak
Vancouver keynote - AWS Innovate - Sam ElmalakAmazon Web Services
 

Similar to You Can't Protect What you Can't See. AWS Security Best Practices - Session Sponsored by Splunk (20)

AWS Summit Auckland - Sponsor Presentation - Splunk
AWS Summit Auckland - Sponsor Presentation - SplunkAWS Summit Auckland - Sponsor Presentation - Splunk
AWS Summit Auckland - Sponsor Presentation - Splunk
 
Splunk company overview april. 2015
Splunk company overview   april. 2015Splunk company overview   april. 2015
Splunk company overview april. 2015
 
Splunk for IT Operations
Splunk for IT OperationsSplunk for IT Operations
Splunk for IT Operations
 
Virtual Gov Day - Application Delivery Breakout - Overview
Virtual Gov Day - Application Delivery Breakout - OverviewVirtual Gov Day - Application Delivery Breakout - Overview
Virtual Gov Day - Application Delivery Breakout - Overview
 
What's New in 6.3 + Data On-Boarding
What's New in 6.3 + Data On-BoardingWhat's New in 6.3 + Data On-Boarding
What's New in 6.3 + Data On-Boarding
 
Splunk live london_grs
Splunk live london_grsSplunk live london_grs
Splunk live london_grs
 
Webinar splunk cloud saa s plattform für operational intelligence
Webinar splunk cloud   saa s plattform für operational intelligenceWebinar splunk cloud   saa s plattform für operational intelligence
Webinar splunk cloud saa s plattform für operational intelligence
 
Don’t Fly Blind – Gain AWS Visibility to Ensure Security and Optimise Operati...
Don’t Fly Blind – Gain AWS Visibility to Ensure Security and Optimise Operati...Don’t Fly Blind – Gain AWS Visibility to Ensure Security and Optimise Operati...
Don’t Fly Blind – Gain AWS Visibility to Ensure Security and Optimise Operati...
 
New Splunk Management Solutions Update: Splunk MINT and Splunk App for Stream
New Splunk Management Solutions Update: Splunk MINT and Splunk App for Stream New Splunk Management Solutions Update: Splunk MINT and Splunk App for Stream
New Splunk Management Solutions Update: Splunk MINT and Splunk App for Stream
 
Splunk for IT Operations Breakout Session
Splunk for IT Operations Breakout SessionSplunk for IT Operations Breakout Session
Splunk for IT Operations Breakout Session
 
SplunkLive! - Splunk for IT Operations
SplunkLive! - Splunk for IT OperationsSplunkLive! - Splunk for IT Operations
SplunkLive! - Splunk for IT Operations
 
SplunkLive! São Paulo 2014 - Overview by markus zirn
SplunkLive! São Paulo 2014 -  Overview by markus zirnSplunkLive! São Paulo 2014 -  Overview by markus zirn
SplunkLive! São Paulo 2014 - Overview by markus zirn
 
Real-time Visibility at Scale with Sumo Logic
Real-time Visibility at Scale with Sumo LogicReal-time Visibility at Scale with Sumo Logic
Real-time Visibility at Scale with Sumo Logic
 
Splunk for IT Operations
Splunk for IT OperationsSplunk for IT Operations
Splunk for IT Operations
 
SplunkLive! München 2016 - Splunk Enterprise 6.3 - Data Onboarding
SplunkLive! München 2016 - Splunk Enterprise 6.3 - Data OnboardingSplunkLive! München 2016 - Splunk Enterprise 6.3 - Data Onboarding
SplunkLive! München 2016 - Splunk Enterprise 6.3 - Data Onboarding
 
SplunkLive! Splunk for IT Operations
SplunkLive! Splunk for IT OperationsSplunkLive! Splunk for IT Operations
SplunkLive! Splunk for IT Operations
 
Splunk Discovery Day Düsseldorf 2016 - Splunk für IT Operations
Splunk Discovery Day Düsseldorf 2016 - Splunk für IT OperationsSplunk Discovery Day Düsseldorf 2016 - Splunk für IT Operations
Splunk Discovery Day Düsseldorf 2016 - Splunk für IT Operations
 
SplunkLive! - Splunk for IT Operations
SplunkLive! - Splunk for IT OperationsSplunkLive! - Splunk for IT Operations
SplunkLive! - Splunk for IT Operations
 
Splunk introduction
Splunk introductionSplunk introduction
Splunk introduction
 
Vancouver keynote - AWS Innovate - Sam Elmalak
Vancouver keynote - AWS Innovate - Sam ElmalakVancouver keynote - AWS Innovate - Sam Elmalak
Vancouver keynote - AWS Innovate - Sam Elmalak
 

More from Amazon Web Services

Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...Amazon Web Services
 
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...Amazon Web Services
 
Esegui pod serverless con Amazon EKS e AWS Fargate
Esegui pod serverless con Amazon EKS e AWS FargateEsegui pod serverless con Amazon EKS e AWS Fargate
Esegui pod serverless con Amazon EKS e AWS FargateAmazon Web Services
 
Costruire Applicazioni Moderne con AWS
Costruire Applicazioni Moderne con AWSCostruire Applicazioni Moderne con AWS
Costruire Applicazioni Moderne con AWSAmazon Web Services
 
Come spendere fino al 90% in meno con i container e le istanze spot
Come spendere fino al 90% in meno con i container e le istanze spot Come spendere fino al 90% in meno con i container e le istanze spot
Come spendere fino al 90% in meno con i container e le istanze spot Amazon Web Services
 
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...Amazon Web Services
 
OpsWorks Configuration Management: automatizza la gestione e i deployment del...
OpsWorks Configuration Management: automatizza la gestione e i deployment del...OpsWorks Configuration Management: automatizza la gestione e i deployment del...
OpsWorks Configuration Management: automatizza la gestione e i deployment del...Amazon Web Services
 
Microsoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows WorkloadsMicrosoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows WorkloadsAmazon Web Services
 
Database Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatareDatabase Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatareAmazon Web Services
 
Crea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJSCrea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJSAmazon Web Services
 
API moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e webAPI moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e webAmazon Web Services
 
Database Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatareDatabase Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatareAmazon Web Services
 
Tools for building your MVP on AWS
Tools for building your MVP on AWSTools for building your MVP on AWS
Tools for building your MVP on AWSAmazon Web Services
 
How to Build a Winning Pitch Deck
How to Build a Winning Pitch DeckHow to Build a Winning Pitch Deck
How to Build a Winning Pitch DeckAmazon Web Services
 
Building a web application without servers
Building a web application without serversBuilding a web application without servers
Building a web application without serversAmazon Web Services
 
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...Amazon Web Services
 
Introduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container ServiceIntroduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container ServiceAmazon Web Services
 

More from Amazon Web Services (20)

Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
 
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
 
Esegui pod serverless con Amazon EKS e AWS Fargate
Esegui pod serverless con Amazon EKS e AWS FargateEsegui pod serverless con Amazon EKS e AWS Fargate
Esegui pod serverless con Amazon EKS e AWS Fargate
 
Costruire Applicazioni Moderne con AWS
Costruire Applicazioni Moderne con AWSCostruire Applicazioni Moderne con AWS
Costruire Applicazioni Moderne con AWS
 
Come spendere fino al 90% in meno con i container e le istanze spot
Come spendere fino al 90% in meno con i container e le istanze spot Come spendere fino al 90% in meno con i container e le istanze spot
Come spendere fino al 90% in meno con i container e le istanze spot
 
Open banking as a service
Open banking as a serviceOpen banking as a service
Open banking as a service
 
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
 
OpsWorks Configuration Management: automatizza la gestione e i deployment del...
OpsWorks Configuration Management: automatizza la gestione e i deployment del...OpsWorks Configuration Management: automatizza la gestione e i deployment del...
OpsWorks Configuration Management: automatizza la gestione e i deployment del...
 
Microsoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows WorkloadsMicrosoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows Workloads
 
Computer Vision con AWS
Computer Vision con AWSComputer Vision con AWS
Computer Vision con AWS
 
Database Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatareDatabase Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatare
 
Crea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJSCrea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJS
 
API moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e webAPI moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e web
 
Database Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatareDatabase Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatare
 
Tools for building your MVP on AWS
Tools for building your MVP on AWSTools for building your MVP on AWS
Tools for building your MVP on AWS
 
How to Build a Winning Pitch Deck
How to Build a Winning Pitch DeckHow to Build a Winning Pitch Deck
How to Build a Winning Pitch Deck
 
Building a web application without servers
Building a web application without serversBuilding a web application without servers
Building a web application without servers
 
Fundraising Essentials
Fundraising EssentialsFundraising Essentials
Fundraising Essentials
 
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
 
Introduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container ServiceIntroduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container Service
 

Recently uploaded

The Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptx
The Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptxThe Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptx
The Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptxLoriGlavin3
 
Generative AI for Technical Writer or Information Developers
Generative AI for Technical Writer or Information DevelopersGenerative AI for Technical Writer or Information Developers
Generative AI for Technical Writer or Information DevelopersRaghuram Pandurangan
 
Scale your database traffic with Read & Write split using MySQL Router
Scale your database traffic with Read & Write split using MySQL RouterScale your database traffic with Read & Write split using MySQL Router
Scale your database traffic with Read & Write split using MySQL RouterMydbops
 
(How to Program) Paul Deitel, Harvey Deitel-Java How to Program, Early Object...
(How to Program) Paul Deitel, Harvey Deitel-Java How to Program, Early Object...(How to Program) Paul Deitel, Harvey Deitel-Java How to Program, Early Object...
(How to Program) Paul Deitel, Harvey Deitel-Java How to Program, Early Object...AliaaTarek5
 
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024BookNet Canada
 
Transcript: New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024Transcript: New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024BookNet Canada
 
DevoxxFR 2024 Reproducible Builds with Apache Maven
DevoxxFR 2024 Reproducible Builds with Apache MavenDevoxxFR 2024 Reproducible Builds with Apache Maven
DevoxxFR 2024 Reproducible Builds with Apache MavenHervé Boutemy
 
The Role of FIDO in a Cyber Secure Netherlands: FIDO Paris Seminar.pptx
The Role of FIDO in a Cyber Secure Netherlands: FIDO Paris Seminar.pptxThe Role of FIDO in a Cyber Secure Netherlands: FIDO Paris Seminar.pptx
The Role of FIDO in a Cyber Secure Netherlands: FIDO Paris Seminar.pptxLoriGlavin3
 
Use of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptx
Use of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptxUse of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptx
Use of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptxLoriGlavin3
 
SALESFORCE EDUCATION CLOUD | FEXLE SERVICES
SALESFORCE EDUCATION CLOUD | FEXLE SERVICESSALESFORCE EDUCATION CLOUD | FEXLE SERVICES
SALESFORCE EDUCATION CLOUD | FEXLE SERVICESmohitsingh558521
 
Ryan Mahoney - Will Artificial Intelligence Replace Real Estate Agents
Ryan Mahoney - Will Artificial Intelligence Replace Real Estate AgentsRyan Mahoney - Will Artificial Intelligence Replace Real Estate Agents
Ryan Mahoney - Will Artificial Intelligence Replace Real Estate AgentsRyan Mahoney
 
unit 4 immunoblotting technique complete.pptx
unit 4 immunoblotting technique complete.pptxunit 4 immunoblotting technique complete.pptx
unit 4 immunoblotting technique complete.pptxBkGupta21
 
From Family Reminiscence to Scholarly Archive .
From Family Reminiscence to Scholarly Archive .From Family Reminiscence to Scholarly Archive .
From Family Reminiscence to Scholarly Archive .Alan Dix
 
Rise of the Machines: Known As Drones...
Rise of the Machines: Known As Drones...Rise of the Machines: Known As Drones...
Rise of the Machines: Known As Drones...Rick Flair
 
New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024BookNet Canada
 
What's New in Teams Calling, Meetings and Devices March 2024
What's New in Teams Calling, Meetings and Devices March 2024What's New in Teams Calling, Meetings and Devices March 2024
What's New in Teams Calling, Meetings and Devices March 2024Stephanie Beckett
 
Take control of your SAP testing with UiPath Test Suite
Take control of your SAP testing with UiPath Test SuiteTake control of your SAP testing with UiPath Test Suite
Take control of your SAP testing with UiPath Test SuiteDianaGray10
 
Unraveling Multimodality with Large Language Models.pdf
Unraveling Multimodality with Large Language Models.pdfUnraveling Multimodality with Large Language Models.pdf
Unraveling Multimodality with Large Language Models.pdfAlex Barbosa Coqueiro
 
Visualising and forecasting stocks using Dash
Visualising and forecasting stocks using DashVisualising and forecasting stocks using Dash
Visualising and forecasting stocks using Dashnarutouzumaki53779
 
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)Mark Simos
 

Recently uploaded (20)

The Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptx
The Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptxThe Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptx
The Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptx
 
Generative AI for Technical Writer or Information Developers
Generative AI for Technical Writer or Information DevelopersGenerative AI for Technical Writer or Information Developers
Generative AI for Technical Writer or Information Developers
 
Scale your database traffic with Read & Write split using MySQL Router
Scale your database traffic with Read & Write split using MySQL RouterScale your database traffic with Read & Write split using MySQL Router
Scale your database traffic with Read & Write split using MySQL Router
 
(How to Program) Paul Deitel, Harvey Deitel-Java How to Program, Early Object...
(How to Program) Paul Deitel, Harvey Deitel-Java How to Program, Early Object...(How to Program) Paul Deitel, Harvey Deitel-Java How to Program, Early Object...
(How to Program) Paul Deitel, Harvey Deitel-Java How to Program, Early Object...
 
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
 
Transcript: New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024Transcript: New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
 
DevoxxFR 2024 Reproducible Builds with Apache Maven
DevoxxFR 2024 Reproducible Builds with Apache MavenDevoxxFR 2024 Reproducible Builds with Apache Maven
DevoxxFR 2024 Reproducible Builds with Apache Maven
 
The Role of FIDO in a Cyber Secure Netherlands: FIDO Paris Seminar.pptx
The Role of FIDO in a Cyber Secure Netherlands: FIDO Paris Seminar.pptxThe Role of FIDO in a Cyber Secure Netherlands: FIDO Paris Seminar.pptx
The Role of FIDO in a Cyber Secure Netherlands: FIDO Paris Seminar.pptx
 
Use of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptx
Use of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptxUse of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptx
Use of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptx
 
SALESFORCE EDUCATION CLOUD | FEXLE SERVICES
SALESFORCE EDUCATION CLOUD | FEXLE SERVICESSALESFORCE EDUCATION CLOUD | FEXLE SERVICES
SALESFORCE EDUCATION CLOUD | FEXLE SERVICES
 
Ryan Mahoney - Will Artificial Intelligence Replace Real Estate Agents
Ryan Mahoney - Will Artificial Intelligence Replace Real Estate AgentsRyan Mahoney - Will Artificial Intelligence Replace Real Estate Agents
Ryan Mahoney - Will Artificial Intelligence Replace Real Estate Agents
 
unit 4 immunoblotting technique complete.pptx
unit 4 immunoblotting technique complete.pptxunit 4 immunoblotting technique complete.pptx
unit 4 immunoblotting technique complete.pptx
 
From Family Reminiscence to Scholarly Archive .
From Family Reminiscence to Scholarly Archive .From Family Reminiscence to Scholarly Archive .
From Family Reminiscence to Scholarly Archive .
 
Rise of the Machines: Known As Drones...
Rise of the Machines: Known As Drones...Rise of the Machines: Known As Drones...
Rise of the Machines: Known As Drones...
 
New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
 
What's New in Teams Calling, Meetings and Devices March 2024
What's New in Teams Calling, Meetings and Devices March 2024What's New in Teams Calling, Meetings and Devices March 2024
What's New in Teams Calling, Meetings and Devices March 2024
 
Take control of your SAP testing with UiPath Test Suite
Take control of your SAP testing with UiPath Test SuiteTake control of your SAP testing with UiPath Test Suite
Take control of your SAP testing with UiPath Test Suite
 
Unraveling Multimodality with Large Language Models.pdf
Unraveling Multimodality with Large Language Models.pdfUnraveling Multimodality with Large Language Models.pdf
Unraveling Multimodality with Large Language Models.pdf
 
Visualising and forecasting stocks using Dash
Visualising and forecasting stocks using DashVisualising and forecasting stocks using Dash
Visualising and forecasting stocks using Dash
 
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
 

You Can't Protect What you Can't See. AWS Security Best Practices - Session Sponsored by Splunk

  • 1. Copyright  ©  2015  Splunk  Inc. You  Can’t  Protect   What  you  Can’t  See. AWS  Security  Best  Practices Dan  Miller,   Director  of  SplunkCloud,  APJ  
  • 2. 2 Make  machine  data  accessible, usable  and  valuable  to  everyone.   2
  • 3. Big  Data  Comes  from  Machines Volume    |    Velocity    |    Variety  |  Variability GPS, RFID, Hypervisor, Web  Servers, Email,  Messaging, Clickstreams,  Mobile,   Telephony,  IVR,  Databases, Sensors,  Telematics,  Storage, Servers,  Security   Devices,  Desktops   3
  • 4. Building  a  Big  Data  Platform HA  /  DR Admin Data  Security Apps SDKs/APIScale Collect Data Index Data Enrich   Data Search &   Explore Analyze &  Predict Report  & Visualize Alert  &   Action 4
  • 5. Fully  Integrated  Enterprise  Platform HA  /  DR Admin Data  Security Apps SDKs/APIScale Collect Data Index Data Enrich   Data Search &   Explore Analyze &  Predict Report  & Visualize Alert  &   Action 5
  • 6. Structured RDBMS SQL Search Schema  at  Write Schema  at  Read Traditional Splunk Splunk  Approach  to  Machine  Data Copyright © 2014 Splunk Inc. 6 ETL Universal  Indexing Volume Velocity Variety Unstructured
  • 7. 7 Why  Splunk? FAST TIME-­‐TO-­‐VALUE ONE  PLATFORM,  MULTIPLE  USE  CASES VISIBILITY  ACROSS  STACK,  NOT  JUST  SILOS ASK  ANY  QUESTION  OF  DATA ANY  DATA,  ANY  SOURCE  OR  DEPLOYMENT  MODEL
  • 8. 8 Turning  Machine  Data  Into  Business  Value Index  Untapped  Data:  Any  Source,  Type,  Volume Online   Services Web   Services Servers Security GPS   Location Storage Desktops Networks Packaged   Applications Custom ApplicationsMessaging Telecoms Online   Shopping   Cart Web   Clickstreams Databases Energy   Meters Call  Detail   Records Smartphones   and  Devices RFID On-­‐ Premises Private   Cloud Public   Cloud Ask  Any  Question Application  Delivery Security,  Compliance   and  Fraud IT  Operations Business  Analytics Industrial  Data  and the  Internet  of  Things
  • 9. IT Operations Application   Delivery Developer  Platform  (REST  API,  SDKs) Business   Analytics Industrial  Data   and  Internet  of   Things 9 Delivers  Value  Across  IT  and  the  Business Business   Analytics Industrial  Data   and  Internet  of   Things Security,     Compliance and  Fraud
  • 10. 10 Platform  for  Application  Delivery and  IT  Operations ROOT  CAUSE   AND ISSUE   RESOLUTION PROACTIVE MONITORING   AND  REAL-­‐TIME   ALERTING DELIVER  BETTER   QUALITY  CODE   FASTER CLOUD  APP  AND   INFRASTRUCTURE   MONITORING MOBILE  APP TROUBLESHOOTING USER  &  USAGE   ANALYTICS
  • 11. Better  Code,  Faster  Development   and  Migration  to  Cloud • Reduced  error  rates  by  2  orders  of  magnitude  in  a  couple  of  weeks • Rapidly  found  and  fixed  one  line  of  code  responsible  for  30,000+  errors • Real-­‐time  dashboards  on  error  rates  and  production  impact   • In-­‐depth  visibility  as  they  strategically  migrate  apps  to  AWS  Cloud
  • 12. 12 Apps  for  Application  Delivery  and  IT  Ops Splunk  Apps   for  VMware  and   Exchange 300+  IT  Ops  and  App   Delivery  Apps *nix Operational  Intelligence   for  Mobile  Apps
  • 13. 13 Application  Delivery  &  IT  Ops  Landscape API SDKs UI Server,  Storage,   Network Server   Virtualization Operating   Systems Custom     Applications Business     Applications Cloud   Services App  Performance   MonitoringTicketing/Other Web  Intelligence Mobile   Applications Stream
  • 14. 14 Splunk  App  for  AWS EC2 EMR Kinesis R53 VPC ELB S3 CloudFront CloudTrail CloudWatch Redshift SNS API Gateway Config RDS CF IAM Lambda Explore Analyze Dashboard Alert Act AWS  Data  Sources End  State:  Comprehensive  AWS  Visibility
  • 15. Splunk  IT  Service  Intelligence  at 1 Replaced  home-­‐ grown  tools Real-­‐time  service   insights to  LOBs Reduced  time  to   resolution
  • 16. Splunk  IT  Service  Intelligence  at 1 “Splunk IT  Service  Intelligence  was   delivering  insights  days  after   installing,  instead  of  the  months  it   can  take  legacy  monitoring   solutions.  Splunk ITSI  helps  us   ensure  that the  claims  service  stays   up  and  running at  all  times.”  -­‐ Tyler   Germer,  director  of  information   technology,   AdvancedMD.  
  • 17. 17 Single  Platform  for  Security  Intelligence SECURITY  &                     COMPLIANCE   REPORTING REAL-­‐TIME   MONITORING  OF   KNOWN  THREATS DETECT   UNKNOWN   THREATS INCIDENT   INVESTIGATIONS   &  FORENSICS FRAUD   DETECTION INSIDER   THREAT Splunk  Complements,  Replaces  and  Goes  Beyond  Existing  SIEMs
  • 18. How  FINRA  Uses  Splunk  Cloud  for  Security • Transforms  third-­‐party  threat  intelligence  information  into  security  alerts • Leverages  the  Splunk  App  for  AWS • Efficient  provisioning  dramatically  reduces  costs “Splunk  Cloud  gives  you  applications   which  let  you  get  huge  amounts  of  value  from  your  data.” — Sr.  Director  of  Information  Security
  • 19. API SDKs UI Network  Traffic   Analysis Identity  &  Access   Control Perimeter   Defense EmailPayload  Analysis Endpoint  Behavior   Analysis Endpoint  Change   Tracking DLP Security  Analytics Threat  Intelligence Cloud  Security Security  &  Compliance  Landscape 19
  • 20. 20 Extending  Splunk  for  Business  Analytics Splunk  Software  Complements  Existing  BI  Solutions CUSTOMER   EXPERIENCE PRODUCT   ANALYTICS BUSINESS   PROCESS   ANALYTICS DIGITAL MARKETING
  • 21. Why  Domino’s  uses  Splunk  for  Application   Management  and  Business  Analytics • Understand  device  and  app  usage  trends  for  orders • Real-­‐time  reNex insights  from  store  data • Visibility  into  online  and  mobile  coupon  redemption • Refine  Campaigns  for  higher  conversion
  • 22. 22 Apps  &  Capabilities  for  Business  Analytics Apps,  Features  &  Partners • DB  Connect • Stream • ODBC  Driver • Data  Models • Pivot
  • 23. IT Operations Security,     Compliance and  Fraud Application   Delivery Developer  Platform  (REST  API,  SDKs) Business   Analytics Industrial  Data   and  Internet  of   Things 23 Delivers  Value  Across  IT  and  the  Business
  • 24. 24 Splunk  for  Industrial  Data  &  the   Internet  of  Things REMOTE TROUBLESHOOTING   &  PREVENTIVE   MAINTENANCE SECURITY  & COMPLIANCE DEVICE  USAGE  & CUSTOMER   ANALYTICS OPERATIONAL EFFICIENCY
  • 25. Saving  Customers  $Billions   on  Fuel,  Operations • Improved  customer  operations  by  mining  large  volumes  of  unstructured  data • Moved  from  monthly  batch  analysis  to  flexible  real-­‐time  reporting • Delivered  value-­‐added  services • Minimized  in-­‐train  forces • Optimized  operational  efficiency “Thanks  to  Splunk,  our  systems  allow  our  customers  to  provide  engineers  with  real-­‐time  feedback   and  use  operational   insight  to  achieve  optimal   runs  every  time.”   — Director  of  Engineering,  Train  Dynamic  Systems  (a  division  of  NYAB)  
  • 26. Apps  &  Capabilities  for  Industrial  Data   &  Internet  of  Things • DBConnect • REST  API  and  SNMP   Modular  Inputs • Universal  Forwarder   for  Raspberry  Pi Apps,  Features  &  Partners REST 26
  • 27. 27 All  the  features  of  Splunk  Enterprise All  the  benefits  of  SaaS
  • 28. Hybrid 28 Search Head(s) Indexer(s) On Premises Private Cloud Public Cloud Search Head(s) Indexer(s) On Premises Private Cloud Public Cloud Hybrid  Search Single  Pane  of  Glass  Visibility
  • 29. Platform  for  Operational  Intelligence The  Splunk  Portfolio Rich  Ecosystem  of Apps  &  Add-­‐Ons Splunk  Premium Solutions Mainframe Data Relational Databases MobileForwarders Syslog/TCP IoT Devices Network Wire  Data Hadoop
  • 30. Dev.splunk.com40,000+  questions and  answers 1,000+  apps Local  User  Groups   and SplunkLive!  events 30 Thriving  Community
  • 31. COLLECT  DATA   FROM  ANYWHERE SEARCH AND  ANALYZE   EVERYTHING GAIN  REAL-­‐TIME   OPERATIONAL   INTELLIGENCE The  Power  of  Splunk 31
  • 32. FREE   CLOUD  TRIAL FREE   DOWNLOAD FREE   AMAZON  MACHINE   IMAGES  (AMI) 32 Easy  to  Try  &  Get  Started 1 32
  • 35. Monitor How we use Splunk Why we chose Splunk All about Atlassian with
  • 36. All About Atlassian Journey to the Cloud Meet the Security Team All About Atlassian
  • 37. Our software helps unleash the potential in every
  • 40. Why We Chose Splunk Industry Standard What’s the MVP / MVE for our team? At what cost? Partner vs Buy Buy from someone you know; not just a single transaction. Build vs Buy Onboarding and Interoperability are key.
  • 41. COGS Time to Ship Support
  • 42. Partner vs Buy Who You Know Integrations Common Users
  • 45. In the beginning… Version 1.0 Version 2.0
  • 46. What we have today. Security Team VPC Splunk Clusterw CloudFormations Data Archives to S3 Data Feeds via Kinesis Search Tier w ELB
  • 52. Copyright  ©  2015  Splunk  Inc. Splunk App  for  AWS
  • 53. Splunk  Offerings  in  AWS • Splunk  App  for   AWS:  Integrates   w/CloudTrail,   Config  and  Billing,   VPC  Flow  Logs Integrations• Self-­‐managed  cloud   deployments • Self-­‐deploy  in  AWS • Integrated  with  EMR • Search  data  in  S3 • Hourly  pricing   Self-­‐managed • Cloud  service   designed  for  small  IT   environments • $90  a  month • Splunk  Enterprise   as  a  service • Full  app,  SDK,  API,   platform  support Cloud-­‐service
  • 54. AWS  Architecture  Diagram Amazon  Instances Amazon  Logging  Layer Amazon  Messaging Amazon  Storage  /  Queues Splunk  Collects  the  data   from  the  AWS  SQS  and   the  S3  bucket  using  the   AWS  SDK  for  python   (Boto3). S3 Bucket AWS ConfigAWS CloudTrail AWS CloudWatch AWS SQS AWS SNSSNS Topic AWS Instance with CloudWatch VPC Flow Logs
  • 55. Requirements  For  Splunk  App  For  AWS • Splunk • Splunk  6.1  or  later • Splunk  Add-­‐on  for  Amazon   Web  Services • Splunk  Add-­‐on  for  Amazon   Web  Services  +1.1.0   required  for  AWS  Config • AWS • AWS  CloudTrail:  Enable  CloudTrail   with  SQS  and  SNS.   • AWS  Config:  Enable  Config  with   SQS  and  SNS.   • Billing:  Refer  to  the  AWS   documentation  to  turn  on  AWS   detailed  billing.   • VPC  Flow  Logs:  Enable  VPC  Flow   log  collection.
  • 56. Install  the  Splunk  Add-­‐on  for  AWS 1.  Configure  your  AWS  accounts  and  services,  or  confirm  your  existing   configurations. 2.  Configure  your  AWS  account  permissions  to  match  those  required   by  the  add-­‐on. 3.  Install  the  add-­‐on. 4.  Set  up  the  add-­‐on  on  your  forwarders  or  single  instance. 5.  Configure  your  inputs  to  get  your  AWS  data  into  Splunk Enterprise. 6.  This  is  all  very  well  documented  at  docs.splunk.com
  • 57. Permissions S3  Storage CloudTrail API  Tracking SNS  Notification SQS  Message  Queue splunkuser Sample  permissions  for  cloudtrail
  • 58. Splunk  Architecture • Distributed  Splunk   Deployment Single  Splunk  Deployment Splunk'server Indexer Heavy+Weight+ Forwarder Splunk+search IndexerIndexer Splunk  Add-­‐ on  for  AWS   installed  on   Heavy  Weight   Forwarder Splunk  App   for  AWS   installed  on   all-­‐in-­‐one   Splunk  server
  • 59. Setup  Interface Add  Your   Account Add  your   AWS   Inputs
  • 60. Wait  5  – 10  Minutes • Yes,  you’ll  need  to  wait  before  all  the  dashboards  and  reports  populate.
  • 61. Gain  Visibility  Into  AWS  Logs
  • 62.