Operations | Monitoring | ITSM | DevOps | Cloud

Latest posts

Approaching Azure Kubernetes Security

The Splunk Security Research Team has been working on Kubernetes security analytic stories mainly focused on AWS and GCP cloud platforms. The turn has come now for some Azure Kubernetes security monitoring analytic stories. As outlined in my "Approaching Kubernetes Security — Detecting Kubernetes Scan with Splunk" blog post, when looking at Kubernetes security, there are certain items within a cluster that must be monitored.

I interviewed 200 CTOs from growing startups - here's what came up

Between late 2019 and early 2020, I interviewed more than 200 CTOs of growing US and EU startups on the topics of the Cloud and their working methodologies. I discovered that 86% of these SMB startups use the Cloud and that 48% started their business on Heroku and then migrated to a Cloud provider - especially AWS (Amazon Web Services).

Splunk: Operationalize MITRE ATT&CK with Risk Based Alerting (RBA)

Why is alert fatigue accepted as "normal" in Security Operations Centers (SOC)? There has to be a shift in perspective. Splunk has worked with customers to build a reference architecture called Risk Based Alerting within Splunk Enterprise Security. It introduces a layer of abstraction between the detection analytics and the alerting process while aligning with the MITRE ATT&CK™ framework to account for user/system/service specific context when scoring anomalous behavior.

Splunk: My Start Will Go On: Splunk's TA for Windows Part 1

This IT Edition Tech Talk will focus on our technical add-on (TA) for Windows OS. Over the next two talks, we'll introduce the Windows TA, showing you how you can gain rapid insights and operational visibility into Windows environments. The TA for Windows makes management of many data sources-like eventlog, performance sources, registry and of course standard logfiles-easier. It offers CIM compliant knowledge objects, normalizing your data and providing a unified view across the entire data domain. This arms administrators with a powerful ability to quickly identify performance and capacity bottlenecks and outliers in Windows environments.

Key Fortinet and Flowmon Integrations: Automated Incident Detection and Response

Flowmon has recently joined Fortinet’s Open Fabric Ecosystem by integrating with FortiGate and FortiSIEM. This cooperation brings automated system for threat detection and response, blocking security risks in their infancy, and giving time to administrators to carry out forensics.