Operations | Monitoring | ITSM | DevOps | Cloud

June 2024

Mastering Fortinet FortiGate Firewall Logs - Part 1 Overview

Fortinet FortiGate firewalls are crucial network security devices that help manage and protect your network by monitoring and controlling incoming and outgoing traffic. They do this based on a set of predetermined security rules. The logs generated by FortiGate firewalls are rich with information about network activities and security events, making them indispensable for both security and DevOps teams in enterprises.

Oberservo AI Demo Natural Language Searchable Data Lake

In this demo first shown at Splunk.conf24, we look at the data-lake creation feature of Observo. Data is stored in the parquet format - a open columnar format. We also support searching the data-lake based on natural language search - under the hood this functionality uses LLM for text to SQL functionality. Use the rehydrate function to send any subset of data to the analytics platform of choice, on-demand. Consider keeping a smaller Splunk index, and use the lake for retention - retain more data, longer, for a lot less cost, all in a flexible format.

Observo AI Data Enrichment Demo

In this demo first aired at Splunk.conf24, we showed the flexible enrichment capabilities of the Observo AI pipeline. A common enrichment scenario for security teams is GeoIP enrichment - it involves adding geographical information to IP addresses. Among other things, GeoIP enrichment can be very useful for location based customization, threat analysis & network traffic pattern mining. Let us see how we do it.

Observo AI Sentiment Analysis

Observo sentiment analysis recognizes patterns of normal data and anomalies that need more investigation using our machine learning models. Alert fatigue happens when your teams are inundated with alerts that may have little to no important information in them. By using sentiment analysis, they can prioritize the alerts that need attention right away and which can be looked at later - resolve critical incidents faster before they spiral into a bigger problem. Our customers have reported 40% or more boost in incident resolution speeds.

Unleashing the Power of Data: Announcing the Official Partnership Between Observo AI and Splunk

Observo AI is excited to announce that we are an official partner with Splunk, a Cisco company. Pairing Splunk Enterprise with Observo AI's observability and security data pipeline enhances the capabilities and efficiencies of security and DevOps teams even further. By optimizing data before it hits a Splunk index and creating a fully searchable data lake for long-term retention, Observo AI can optimize customers’ infrastructure costs including storage, cloud egress, and compute.