SlideShare une entreprise Scribd logo
1  sur  16
Copyright © 2015 Splunk Inc.
Splunk Cloud at Equinix
Brian Lillie, CIO
2
Brian Lillie
Chief Information Officer,
Equinix
@coachlillie
3
About Equinix
As the world's largest data center
company, we provide global leaders
the power of interconnection: the
ability to connect to many customers
and partners in many regions—
accelerating business performance
and creating new opportunities.
4
About Coach Lillie
My role at Equinix
My team’s mission
My favorite Splunk tee-shirt tag line
One fun fact about me
5
Equinix Global InfoSec Program Drivers
6
Equinix Vision for SIEM
SIEM is key to any security
platform today
We were very early in adopting a
“SIEM in the Cloud” vision and
strategy
With a traditional on premise
SIEM, we didn’t think we would
have value right out of the box
Been searching for awhile…
“…we pushed the
vision of SIEM in
the Cloud for
years…”
7
Why did we want a Cloud SIEM Solution?
Flexibility
Subscription Model
Eliminates the need
to feel ‘married’ to a
system – easier to
unsubscribe if it
doesn’t fit
Price
Less Expensive
At least 50% lower
TCO compared to
deploying an on-
premises SIEM
Ease/Speed
Minimal PS
Easy data ingestion
and easy
deployment that
doesn’t require an
army to set-up
(when most data is generated on-premises)
8
What Cloud SIEM Was Right for Equinix?
Splunk Cloud with ES gave us a starting point
Met a variety of our use cases: ability to handle multiple types
of data (and speeds and feeds), apps marketplace, correlation
rules engine, and enterprise-level security view
We gained VALUE immediately out of the box; now a platform
to build upon
+
9
Why we selected Splunk Cloud
Databases
Networks
Servers
Web
Services
Smartphones
and Devices
Custom
Applications
Security
Universal SearchApp Ecosystem Single Pane of
Glass
Certified Guaranteed
100%
Uptime
SLA
And More…
10
“…Our goal is to protect customers, employees &
data.”
How We Use Splunk Cloud
Malware Protection
User Account Protection
Data Leakage Protection
11
Splunk Cloud Deployment @Equinix
Aggregation Correlation
Collection
Validation
12
Promising Results
Before
Individual Silos
Time-Consuming Reporting
Manual Troubleshooting
Monitoring
20 Billion
Raw Events
After
20 Billion
Raw Events
Reduced
toThrough
12,000 Events
Reduced
to
20 Actionable Alerts
13
My CIO Dashboard
14
What’s Next for Equinix
Global Security Team standardizing on Splunk Cloud
Use insights to build out a Security Operations Center
Expand use of Splunk Cloud to the Global Server and
Network teams
Use Splunk to help integrate acquisitions
15
Top Takeaways
SIEM in the cloud is the way to go
SIEM with an Enterprise-level “Helicopter view” for the CIO is a
must
Splunk Cloud is a GREAT choice to meet these needs:
– Splunk Cloud is a service and requires much less staff to operate (less cost)
– Splunk Cloud is less complex to implement and operate
– Splunk Cloud with ES is a true security SIEM – SOC 2 Type II certified, 100
percent uptime SLA
– Splunk Cloud reduced the time to resolve/respond to security incidents –
out of the box
Q
1
&
A

Contenu connexe

Tendances

Equinix Corporate Presentation 2015
Equinix Corporate Presentation 2015Equinix Corporate Presentation 2015
Equinix Corporate Presentation 2015
Josh Collis
 

Tendances (20)

Equinix Performance Hub gives Enterprise Networks a Giant Boost
Equinix Performance Hub gives Enterprise Networks a Giant BoostEquinix Performance Hub gives Enterprise Networks a Giant Boost
Equinix Performance Hub gives Enterprise Networks a Giant Boost
 
EVOLUTION Chicago
EVOLUTION Chicago EVOLUTION Chicago
EVOLUTION Chicago
 
Unleash the Power of Equinix: Digital Transformation through Interconnection
Unleash the Power of Equinix: Digital Transformation through InterconnectionUnleash the Power of Equinix: Digital Transformation through Interconnection
Unleash the Power of Equinix: Digital Transformation through Interconnection
 
Equinix and Customers to Present on "Mobility" at PTC '13.
Equinix and Customers to Present on "Mobility" at PTC '13.Equinix and Customers to Present on "Mobility" at PTC '13.
Equinix and Customers to Present on "Mobility" at PTC '13.
 
CIO Event - Equinix - Architecting an Enterprise from the Future
CIO Event - Equinix - Architecting an Enterprise from the FutureCIO Event - Equinix - Architecting an Enterprise from the Future
CIO Event - Equinix - Architecting an Enterprise from the Future
 
EVOLUTION Denver
EVOLUTION Denver EVOLUTION Denver
EVOLUTION Denver
 
2019 microsoft sales enablement why equinix
2019 microsoft sales enablement   why equinix2019 microsoft sales enablement   why equinix
2019 microsoft sales enablement why equinix
 
EVOLUTION San Francisco
EVOLUTION San Francisco EVOLUTION San Francisco
EVOLUTION San Francisco
 
Equinix Performance Hub & Cloud Exchange
Equinix Performance Hub & Cloud Exchange Equinix Performance Hub & Cloud Exchange
Equinix Performance Hub & Cloud Exchange
 
Winning with Hybrid IT IBC 2015
Winning with Hybrid IT IBC 2015Winning with Hybrid IT IBC 2015
Winning with Hybrid IT IBC 2015
 
Equinix microsoft 2019 use case playbook
Equinix microsoft 2019 use case playbookEquinix microsoft 2019 use case playbook
Equinix microsoft 2019 use case playbook
 
EVOLUTION Seattle
EVOLUTION Seattle EVOLUTION Seattle
EVOLUTION Seattle
 
IBC 2015 Technology In Action Presentation
IBC 2015 Technology In Action PresentationIBC 2015 Technology In Action Presentation
IBC 2015 Technology In Action Presentation
 
Solving the Digital Edge
Solving the Digital EdgeSolving the Digital Edge
Solving the Digital Edge
 
The IDC and Equinix Webinar - 2018 - The Year of the Intelligence Ready Digit...
The IDC and Equinix Webinar - 2018 - The Year of the Intelligence Ready Digit...The IDC and Equinix Webinar - 2018 - The Year of the Intelligence Ready Digit...
The IDC and Equinix Webinar - 2018 - The Year of the Intelligence Ready Digit...
 
Cloud Managed Services
Cloud Managed ServicesCloud Managed Services
Cloud Managed Services
 
Equinix - supporting Cloud opportunities in Europe
Equinix - supporting Cloud opportunities in EuropeEquinix - supporting Cloud opportunities in Europe
Equinix - supporting Cloud opportunities in Europe
 
Optimizing Oracle Cloud Infrastructure through Interconnection
Optimizing Oracle Cloud Infrastructure through Interconnection Optimizing Oracle Cloud Infrastructure through Interconnection
Optimizing Oracle Cloud Infrastructure through Interconnection
 
Equinix Corporate Presentation 2015
Equinix Corporate Presentation 2015Equinix Corporate Presentation 2015
Equinix Corporate Presentation 2015
 
An Insider's View on What It Takes to Be Digital Ready
An Insider's View on What It Takes to Be Digital ReadyAn Insider's View on What It Takes to Be Digital Ready
An Insider's View on What It Takes to Be Digital Ready
 

En vedette

En vedette (9)

Exploring Interconnection Oriented Architectures with AWS
Exploring Interconnection Oriented Architectures with AWSExploring Interconnection Oriented Architectures with AWS
Exploring Interconnection Oriented Architectures with AWS
 
Sephora Customer Presentation
Sephora Customer PresentationSephora Customer Presentation
Sephora Customer Presentation
 
Equinix Big Data Platform and Cassandra - A view into the journey
Equinix Big Data Platform and Cassandra - A view into the journeyEquinix Big Data Platform and Cassandra - A view into the journey
Equinix Big Data Platform and Cassandra - A view into the journey
 
Sephora: A Brand Case Study
Sephora: A Brand Case StudySephora: A Brand Case Study
Sephora: A Brand Case Study
 
RightScale Webinar: Best-in-Class Hybrid Cloud Solutions from Equinix and Rig...
RightScale Webinar: Best-in-Class Hybrid Cloud Solutions from Equinix and Rig...RightScale Webinar: Best-in-Class Hybrid Cloud Solutions from Equinix and Rig...
RightScale Webinar: Best-in-Class Hybrid Cloud Solutions from Equinix and Rig...
 
Peering 101
Peering 101Peering 101
Peering 101
 
Digital Realty Investor Day Presentation
Digital Realty Investor Day PresentationDigital Realty Investor Day Presentation
Digital Realty Investor Day Presentation
 
Becoming an interconnected enterprise
Becoming an interconnected enterpriseBecoming an interconnected enterprise
Becoming an interconnected enterprise
 
Datwyler dcs it_safe_the modular compact data centre_ Info Tech Middle East
Datwyler dcs it_safe_the modular compact data centre_ Info Tech Middle EastDatwyler dcs it_safe_the modular compact data centre_ Info Tech Middle East
Datwyler dcs it_safe_the modular compact data centre_ Info Tech Middle East
 

Similaire à Equinix Customer Presentation

CipherCloud_Corporate Overview
CipherCloud_Corporate OverviewCipherCloud_Corporate Overview
CipherCloud_Corporate Overview
Scott Dierks
 
Keys-to-Success-and-Security-in-the-Cloud
Keys-to-Success-and-Security-in-the-CloudKeys-to-Success-and-Security-in-the-Cloud
Keys-to-Success-and-Security-in-the-Cloud
patmisasi
 

Similaire à Equinix Customer Presentation (20)

SplunkLive! Customer Presentation--ServiceNow
SplunkLive! Customer Presentation--ServiceNowSplunkLive! Customer Presentation--ServiceNow
SplunkLive! Customer Presentation--ServiceNow
 
Splunk for Enterprise Security featuring UBA Breakout Session
Splunk for Enterprise Security featuring UBA Breakout SessionSplunk for Enterprise Security featuring UBA Breakout Session
Splunk for Enterprise Security featuring UBA Breakout Session
 
Demystifying Cloud Security: Lessons Learned for the Public Sector
Demystifying Cloud Security: Lessons Learned for the Public SectorDemystifying Cloud Security: Lessons Learned for the Public Sector
Demystifying Cloud Security: Lessons Learned for the Public Sector
 
The End of Security as We Know It - Shannon Lietz
The End of Security as We Know It - Shannon LietzThe End of Security as We Know It - Shannon Lietz
The End of Security as We Know It - Shannon Lietz
 
Seeing More Clearly: How Essilor Overcame 3 Common Cloud Security Challenges ...
Seeing More Clearly: How Essilor Overcame 3 Common Cloud Security Challenges ...Seeing More Clearly: How Essilor Overcame 3 Common Cloud Security Challenges ...
Seeing More Clearly: How Essilor Overcame 3 Common Cloud Security Challenges ...
 
Private Cloud Computing - Get the best for your business | Sysfore
Private Cloud Computing - Get the best for your business | SysforePrivate Cloud Computing - Get the best for your business | Sysfore
Private Cloud Computing - Get the best for your business | Sysfore
 
Cloud Seminar Feb 4 2010
Cloud Seminar Feb 4 2010Cloud Seminar Feb 4 2010
Cloud Seminar Feb 4 2010
 
To cloud or not to cloud
To cloud or not to cloudTo cloud or not to cloud
To cloud or not to cloud
 
Splunk for Enterprise Security Featuring UBA
Splunk for Enterprise Security Featuring UBASplunk for Enterprise Security Featuring UBA
Splunk for Enterprise Security Featuring UBA
 
Cloud Innovation Tour - Discover Track
Cloud Innovation Tour - Discover TrackCloud Innovation Tour - Discover Track
Cloud Innovation Tour - Discover Track
 
Practical Cloud - Stephen Betts (Avanade)
Practical Cloud - Stephen Betts (Avanade)Practical Cloud - Stephen Betts (Avanade)
Practical Cloud - Stephen Betts (Avanade)
 
bishu pdf1
bishu pdf1bishu pdf1
bishu pdf1
 
Tirez pleinement parti d'Elastic grâce à Elastic Cloud
Tirez pleinement parti d'Elastic grâce à Elastic CloudTirez pleinement parti d'Elastic grâce à Elastic Cloud
Tirez pleinement parti d'Elastic grâce à Elastic Cloud
 
CipherCloud_Corporate Overview
CipherCloud_Corporate OverviewCipherCloud_Corporate Overview
CipherCloud_Corporate Overview
 
Shared responsibility - a model for good cloud security
Shared responsibility - a model for good cloud securityShared responsibility - a model for good cloud security
Shared responsibility - a model for good cloud security
 
Features of cloud
Features of cloudFeatures of cloud
Features of cloud
 
Getting Started with Qlik Sense® Cloud: Understanding the Basics
Getting Started with Qlik Sense® Cloud: Understanding the BasicsGetting Started with Qlik Sense® Cloud: Understanding the Basics
Getting Started with Qlik Sense® Cloud: Understanding the Basics
 
Keys to success and security in the cloud
Keys to success and security in the cloudKeys to success and security in the cloud
Keys to success and security in the cloud
 
Keys-to-Success-and-Security-in-the-Cloud
Keys-to-Success-and-Security-in-the-CloudKeys-to-Success-and-Security-in-the-Cloud
Keys-to-Success-and-Security-in-the-Cloud
 
J Tobolski Cloud Computing
J Tobolski Cloud ComputingJ Tobolski Cloud Computing
J Tobolski Cloud Computing
 

Plus de Splunk

Plus de Splunk (20)

.conf Go 2023 - Data analysis as a routine
.conf Go 2023 - Data analysis as a routine.conf Go 2023 - Data analysis as a routine
.conf Go 2023 - Data analysis as a routine
 
.conf Go 2023 - How KPN drives Customer Satisfaction on IPTV
.conf Go 2023 - How KPN drives Customer Satisfaction on IPTV.conf Go 2023 - How KPN drives Customer Satisfaction on IPTV
.conf Go 2023 - How KPN drives Customer Satisfaction on IPTV
 
.conf Go 2023 - Navegando la normativa SOX (Telefónica)
.conf Go 2023 - Navegando la normativa SOX (Telefónica).conf Go 2023 - Navegando la normativa SOX (Telefónica)
.conf Go 2023 - Navegando la normativa SOX (Telefónica)
 
.conf Go 2023 - Raiffeisen Bank International
.conf Go 2023 - Raiffeisen Bank International.conf Go 2023 - Raiffeisen Bank International
.conf Go 2023 - Raiffeisen Bank International
 
.conf Go 2023 - På liv og død Om sikkerhetsarbeid i Norsk helsenett
.conf Go 2023 - På liv og død Om sikkerhetsarbeid i Norsk helsenett .conf Go 2023 - På liv og død Om sikkerhetsarbeid i Norsk helsenett
.conf Go 2023 - På liv og død Om sikkerhetsarbeid i Norsk helsenett
 
.conf Go 2023 - Many roads lead to Rome - this was our journey (Julius Bär)
.conf Go 2023 - Many roads lead to Rome - this was our journey (Julius Bär).conf Go 2023 - Many roads lead to Rome - this was our journey (Julius Bär)
.conf Go 2023 - Many roads lead to Rome - this was our journey (Julius Bär)
 
.conf Go 2023 - Das passende Rezept für die digitale (Security) Revolution zu...
.conf Go 2023 - Das passende Rezept für die digitale (Security) Revolution zu....conf Go 2023 - Das passende Rezept für die digitale (Security) Revolution zu...
.conf Go 2023 - Das passende Rezept für die digitale (Security) Revolution zu...
 
.conf go 2023 - Cyber Resilienz – Herausforderungen und Ansatz für Energiever...
.conf go 2023 - Cyber Resilienz – Herausforderungen und Ansatz für Energiever....conf go 2023 - Cyber Resilienz – Herausforderungen und Ansatz für Energiever...
.conf go 2023 - Cyber Resilienz – Herausforderungen und Ansatz für Energiever...
 
.conf go 2023 - De NOC a CSIRT (Cellnex)
.conf go 2023 - De NOC a CSIRT (Cellnex).conf go 2023 - De NOC a CSIRT (Cellnex)
.conf go 2023 - De NOC a CSIRT (Cellnex)
 
conf go 2023 - El camino hacia la ciberseguridad (ABANCA)
conf go 2023 - El camino hacia la ciberseguridad (ABANCA)conf go 2023 - El camino hacia la ciberseguridad (ABANCA)
conf go 2023 - El camino hacia la ciberseguridad (ABANCA)
 
Splunk - BMW connects business and IT with data driven operations SRE and O11y
Splunk - BMW connects business and IT with data driven operations SRE and O11ySplunk - BMW connects business and IT with data driven operations SRE and O11y
Splunk - BMW connects business and IT with data driven operations SRE and O11y
 
Splunk x Freenet - .conf Go Köln
Splunk x Freenet - .conf Go KölnSplunk x Freenet - .conf Go Köln
Splunk x Freenet - .conf Go Köln
 
Splunk Security Session - .conf Go Köln
Splunk Security Session - .conf Go KölnSplunk Security Session - .conf Go Köln
Splunk Security Session - .conf Go Köln
 
Data foundations building success, at city scale – Imperial College London
 Data foundations building success, at city scale – Imperial College London Data foundations building success, at city scale – Imperial College London
Data foundations building success, at city scale – Imperial College London
 
Splunk: How Vodafone established Operational Analytics in a Hybrid Environmen...
Splunk: How Vodafone established Operational Analytics in a Hybrid Environmen...Splunk: How Vodafone established Operational Analytics in a Hybrid Environmen...
Splunk: How Vodafone established Operational Analytics in a Hybrid Environmen...
 
SOC, Amore Mio! | Security Webinar
SOC, Amore Mio! | Security WebinarSOC, Amore Mio! | Security Webinar
SOC, Amore Mio! | Security Webinar
 
.conf Go 2022 - Observability Session
.conf Go 2022 - Observability Session.conf Go 2022 - Observability Session
.conf Go 2022 - Observability Session
 
.conf Go Zurich 2022 - Keynote
.conf Go Zurich 2022 - Keynote.conf Go Zurich 2022 - Keynote
.conf Go Zurich 2022 - Keynote
 
.conf Go Zurich 2022 - Platform Session
.conf Go Zurich 2022 - Platform Session.conf Go Zurich 2022 - Platform Session
.conf Go Zurich 2022 - Platform Session
 
.conf Go Zurich 2022 - Security Session
.conf Go Zurich 2022 - Security Session.conf Go Zurich 2022 - Security Session
.conf Go Zurich 2022 - Security Session
 

Dernier

Dernier (20)

Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdfUnderstanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
 
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
 
Tech Trends Report 2024 Future Today Institute.pdf
Tech Trends Report 2024 Future Today Institute.pdfTech Trends Report 2024 Future Today Institute.pdf
Tech Trends Report 2024 Future Today Institute.pdf
 
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
 
The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 
Boost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfBoost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdf
 
Scaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationScaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organization
 
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
 
Strategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a FresherStrategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a Fresher
 
2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...
 
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdfThe Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
 
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
 
What Are The Drone Anti-jamming Systems Technology?
What Are The Drone Anti-jamming Systems Technology?What Are The Drone Anti-jamming Systems Technology?
What Are The Drone Anti-jamming Systems Technology?
 
🐬 The future of MySQL is Postgres 🐘
🐬  The future of MySQL is Postgres   🐘🐬  The future of MySQL is Postgres   🐘
🐬 The future of MySQL is Postgres 🐘
 
08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking Men08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking Men
 
GenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdfGenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdf
 
Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)
 
Handwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed textsHandwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed texts
 
Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024
 

Equinix Customer Presentation

  • 1. Copyright © 2015 Splunk Inc. Splunk Cloud at Equinix Brian Lillie, CIO
  • 2. 2 Brian Lillie Chief Information Officer, Equinix @coachlillie
  • 3. 3 About Equinix As the world's largest data center company, we provide global leaders the power of interconnection: the ability to connect to many customers and partners in many regions— accelerating business performance and creating new opportunities.
  • 4. 4 About Coach Lillie My role at Equinix My team’s mission My favorite Splunk tee-shirt tag line One fun fact about me
  • 5. 5 Equinix Global InfoSec Program Drivers
  • 6. 6 Equinix Vision for SIEM SIEM is key to any security platform today We were very early in adopting a “SIEM in the Cloud” vision and strategy With a traditional on premise SIEM, we didn’t think we would have value right out of the box Been searching for awhile… “…we pushed the vision of SIEM in the Cloud for years…”
  • 7. 7 Why did we want a Cloud SIEM Solution? Flexibility Subscription Model Eliminates the need to feel ‘married’ to a system – easier to unsubscribe if it doesn’t fit Price Less Expensive At least 50% lower TCO compared to deploying an on- premises SIEM Ease/Speed Minimal PS Easy data ingestion and easy deployment that doesn’t require an army to set-up (when most data is generated on-premises)
  • 8. 8 What Cloud SIEM Was Right for Equinix? Splunk Cloud with ES gave us a starting point Met a variety of our use cases: ability to handle multiple types of data (and speeds and feeds), apps marketplace, correlation rules engine, and enterprise-level security view We gained VALUE immediately out of the box; now a platform to build upon +
  • 9. 9 Why we selected Splunk Cloud Databases Networks Servers Web Services Smartphones and Devices Custom Applications Security Universal SearchApp Ecosystem Single Pane of Glass Certified Guaranteed 100% Uptime SLA And More…
  • 10. 10 “…Our goal is to protect customers, employees & data.” How We Use Splunk Cloud Malware Protection User Account Protection Data Leakage Protection
  • 11. 11 Splunk Cloud Deployment @Equinix Aggregation Correlation Collection Validation
  • 12. 12 Promising Results Before Individual Silos Time-Consuming Reporting Manual Troubleshooting Monitoring 20 Billion Raw Events After 20 Billion Raw Events Reduced toThrough 12,000 Events Reduced to 20 Actionable Alerts
  • 14. 14 What’s Next for Equinix Global Security Team standardizing on Splunk Cloud Use insights to build out a Security Operations Center Expand use of Splunk Cloud to the Global Server and Network teams Use Splunk to help integrate acquisitions
  • 15. 15 Top Takeaways SIEM in the cloud is the way to go SIEM with an Enterprise-level “Helicopter view” for the CIO is a must Splunk Cloud is a GREAT choice to meet these needs: – Splunk Cloud is a service and requires much less staff to operate (less cost) – Splunk Cloud is less complex to implement and operate – Splunk Cloud with ES is a true security SIEM – SOC 2 Type II certified, 100 percent uptime SLA – Splunk Cloud reduced the time to resolve/respond to security incidents – out of the box

Notes de l'éditeur

  1. George wanted SIEM in the Cloud solution. (ES) SIEM is major achievements of any security system Going into ES, we realized that any SIEM solution – there’s going to be a lot of work. We knew going in that there would be a considerable effort building it out. We knew it wasn’t going to be SIEM out of the box.
  2. WHY DID YOU CHOOSE a CLOUD BASED? Cost was number one. Capex vs. Opex. Wanted something that we could turn up quickly and manage easily. Minimize costs for storage, systems monitoring, managing data bases Cloud vs. on-prem value prop Didn’t want anything I had to deploy manually Subscribe, use it, marry myself and then unmarry myself. Subscription is a lot easier
  3. VALUE out of the Box? Every organization has different use cases…but every solution would help us frame our use cases. (uptime, sensitivity of data, systems vulnerability) Needed a starting point. That’s what ES gave us out of the box From there, we produced a final list that allowed us to operate a system based on our use cases.
  4. COMPARED to other CLOUD SOLUTIONS As a SIEM in the cloud, what drew me into ES. We have APPs marketplace. Most of the other customers don’t have the APPs or lenses into the data. Most are free. Other vendors, don’t have those. If we had engaged with other vendors, we would have to build those out. Apps are great, but they help you frame the data. Now we can compare it and add in our own use cases. As you get through the process of getting operational, were there other areas of differentiation? Ability to search…across all data sets. Ability to do this across all data sets is really powerful. Searching is 101.
  5. USE CASES TODAY Malware protection – across all platforms (laptops, mobile, …) Protecting user accounts – if a user logs in SF and Hong Kong simultaneously – detecting account compromise Data leakage protection (SFDC app) – preventing malicious employee behavior High priority: Care about data. Care about business being able to function. Target the things that typically have negative impact. Malware. We have a security infrastructure that shows us malware on desk tops and servers ES alerts us to systems with malware – phoning home or ES allows us to protect users. If a user is logging on in silicon valley and log in 10 seconds later in hong kong…compromised system? How do we monitor the security of our users
  6. Had significant global structure – Firewall, VPN, active directory, but no SIEM… Operating with a security infrastructure…splunk allowed us to aggregate this. One dashboard. Splunk ES. Allows my guys to not have to go out to each different security system to monitor Before, we didn’t have a way to correlate between the security systems. Big value add is correlation. Aggregation and correlation. Get everything into a single place and then correlate… Data feeds/sets – Qualys security, Cisco firewalls, load balancers, salesforce.com, tripwire, open VPN, Unyx and Windows (Splunk App), Juniper Firewalls, Palo Alto Salesforce – data leakage protection – very sensitive and critical to the business. Manage malicious employees who may be forklifting data. Certain algorythms and data that looks suspicious Salesforce App – gives you good data but doesn’t really provide enough intelligence to determine Separate from security use cases, Salesforce app is pretty slick. How we accomplish this (New Slide) Log aggregation Log correlation Data sources: (Qualys, Palo Alto Networks, Cisco, F5, Salesforce.com, Tripwire, Open VPN, Unix, Windows, Application logs, Juniper)
  7. We had almost 20 billion raw events to monitor. Within Splunk Cloud we built 50 correlation rules. Now we look at critical and high only priority events only. This reduced the 20 billion to 12,000. That’s the story.”
  8. Talk about your personal CIO Dashboard and the operational intelligence it provides you.
  9. ARE OTHER TEAMS USING SPLUNK at Equinix? Security – Now – How many folks. 6 people. Infrastructure for monitoring app performance DevOps…looking to Splunk to bake prcesses into development. Triggered alerts. Service down, KPIs,   LOOKING AT HURRICANE LABS TO HELP OPERATE BETTER IN THIS ENVIRONMENT.   Help manage Splunk. Write correlation events as we define them in terms of use cases. Use a service skilled in that work rather than doing it themselves. Security ops center  
  10. NOTIONAL DEPLOYMENT COST savings?   Vs. arcsight, maybe saved half. Splunk Cloud is half of what the cost of something like arcsight. Value: One of the biggest factors is how the environment is managed. With arcsight, you have to hire an army of professional services to get it set up, manage data bases, and then tune it. On going work. Cannot tune it and leave it. Data sources into Splunk…then turning correlation and mapping to use cases. We are a little easier because we can work to define the use cases and then do the code. More complexity on the arcsight side – less on the Splunk ES COMPLIANCE/CERTIFICATIONS IMPORTANT   Really use this for security use cases   SPLUNK CLOUD – SOC 2 Type II certified Very important Very sensitive Certifications that attest to the protection of the data   100 PERCENT UPTIME Didn’t track that with others? SLA still going Never seen anywhere else offer that