Splunking Microsoft Azure Network Watcher Data
Microsoft has released a new service in Azure called Network Watcher. Network Watcher is a network performance monitoring, diagnostic, and analytics service which enables you to monitor your network...
View ArticleFrom API to easy street within minutes
30? 20? …15? It all depends on how well you know your third-party API. The point is that polling data from third-party APIs is easier than ever. CIM mapping is now a fun experience. Want to find out...
View ArticleSSL Proxy: Splunk & NGINX
Who is this guide for? It is a best practice to install Splunk as a non-root user or service account as part of a defense in depth strategy. This installation choice comes with the consequences of...
View ArticleSplunking Microsoft Azure Network Watcher Data
Microsoft has released a new service in Azure called Network Watcher. Network Watcher is a network performance monitoring, diagnostic, and analytics service which enables you to monitor your network...
View ArticleSplunk DB Connect 3 Released
Splunk DB Connect has just gotten a major upgrade! Let’s take a look at it. What’s New Splunk DB Connect 3.0 is a major release to one of the most popular Splunk add-ons. Splunk DB Connect enables...
View ArticleUsing machine learning for anomaly detection research
Over the last years I had many discussions around anomaly detection in Splunk. So it was really great to hear about a thesis dedicated to this topic and I think it’s worth sharing with the wider...
View ArticleSplunk AWS Quick Start: Deploy Your AWS Splunk Environment In Minutes
If I told you that a fully operational Splunk Enterprise deployment in AWS could be yours in a matter of minutes, would you be interested? Sit down, relax, and I’ll tell you all you need to know to...
View ArticleEverything You Need to Know About Splunk ITSI
With the latest version of Splunk IT Service Intelligence (ITSI), you can apply machine learning and advanced analytics to: Simplify operations with machine learning Prioritize problem resolution with...
View ArticleYour Splunk Workspace
What is a Workspace? In my mind, it’s a well defined area within which one can construct and create without impact to and by externalities. Implemented in Splunk, it’s a user logging into Splunk,...
View ArticleHow to stream AWS CloudWatch Logs to Splunk (Hint: it’s easier than you think)
At AWS re:Invent 2016, Splunk released several AWS Lambda blueprints to help you stream logs, events and alerts from more than 15 AWS services into Splunk to gain enhanced critical security and...
View ArticleHow to Stop Playing the Blame Game in Your IT Department
It’s a familiar scenario: a problem is discovered, and a Service Desk Team gets a help ticket. The Service Desk Team tells Operations that there’s an outage. The Operations Team suggests that the...
View ArticleImplementation of Incentive Driven User Access
Out of the box, a Splunk user has the capabilities to do some powerful stuff – but as Uncle Ben tells us, “with great power comes great responsibility“. In my prior post, we reviewed the scenario and...
View ArticleAnalyzing BotNets with Suricata & Machine Learning
Since the official rollout at the year’s. conf of the Machine Learning Toolkit(MLTK), Splunkers have been pursing some interesting use cases ranging from IT operations, planning, security and business...
View ArticleCarrot vs Stick: A Case for Incentive Driven User Access
Houston, We’ve Got A Problem Out of the box, a Splunk user has the capabilities to do some powerful stuff – but as Uncle Ben tells us, “with great power comes great responsibility“. Scenario: Bort is a...
View ArticleEnhancing Enterprise Security for Ransomware Detection
Ransomware isn’t going away Ransomware is a profitable business model for cyber criminals with 2016 payments closed at the billon dollar mark. According to a recent survey by IBM, nearly 70% of...
View ArticleVisual link analysis with Splunk and Gephi
As cyber-security risks and attacks have surged in recent years, identity fraud has become all too familiar for the common, unsuspecting user. You might wonder, “why don’t we have the capabilities to...
View ArticleImproving Visibility in Security Operations with Search-Driven Lookups
Looking back on 2016, Splunk Enterprise Security added significant capabilities to its platform for security operations, including Adaptive Response, User & Entity Behavior Analytics (UEBA)...
View ArticleDashboard Digest Series – Episode 5: Maps!
“A map does not just chart, it unlocks and formulates meaning; it forms bridges between here and there, between disparate ideas that we did not know were previously connected.” ― Reif Larsen, The...
View ArticleSplunk and AWS: Monitoring & Metrics in a Serverless World
Bill Bartlett (fellow Splunker) and I have recently had the distinct pleasure of moving some workloads from AWS EC2 over to a combo of AWS Lambda and AWS API Gateway. Between the dramatic cost savings,...
View ArticleSmart AnSwerS #83
Hey there community and welcome to the 83rd installment of Smart AnSwerS. After a dry spell, Splunk HQ is finally experiencing a good amount of rain in the San Francisco Bay Area. As per usual, people...
View Article