Operations | Monitoring | ITSM | DevOps | Cloud

December 2020

Improve DevOps Workflows Using SMLE and Streaming ML to Detect Anomalies

Modern IT & DevOps teams face increasingly complex environments — making it harder to quickly detect and resolve critical issues in real-time. To overcome this challenge, Splunk users can take advantage of ML-powered IT monitoring and DevOps solutions available in a scalable platform with state-of-the-art data analytics and AI/ML capabilities. In this blog, we deploy Splunk’s built-in Streaming ML algorithms to detect anomalous patterns in error logs in real-time.

Dashboards Beta v0.9: All Things Inputs

If you’re new to the Splunk Dashboards app (beta) on Splunkbase and you’re trying to get started with building beautiful dashboards, this blog series is a great place to start. The Splunk Dashboards app (beta) brings a new dashboard framework, intended to combine the best of Simple XML and Glass Tables, and provides a friendlier experience for creating and editing dashboards.

Splunk Connect for Syslog: Turnkey and Scalable Syslog GDI - Part 3

In Part 1 and Part 2 of this series, we explored the design philosophy behind Splunk Connect for Syslog (SC4S), the goals of the design, and the new HEC-based transport architecture, as well as the rudiments of high-level configuration. We'll now turn our attention to the specifics of SC4S configuration, including a review of the local (mounted) file system layout and the areas in which you'll be working.

Splunk Connect for Syslog: Turnkey and Scalable Syslog GDI - Part 4

Previous installments of this series have given you the overview and configuration details you need to ingest any source that is supported by Splunk Connect for Syslog and configure customizations and overrides that match your enterprise. This leaves one key capability of SC4S that we have not yet covered, and that is extending the platform itself. In this installment, we'll walk through the configuration of an entirely new data source – one that SC4S does address out of the box.

Deep Learning Toolkit 3.4: Grid Search, Causal Inference and Process Mining

With a turbulent year and 2020 coming to its end, I’d like to thank you for your continued interest in my blog posts. In my last .conf talks I received a lot of positive feedback combined with the ask to have more posts with such content, so thanks for motivating me and here we go! Recently, my colleague Dimitris wrote about how you can set up DLTK on a AWS GPU Instance.

Splunk AR: Object Detection

The Splunk Augmented Reality (AR) team is excited to share more with you. In our first AR post, "Splunk AR: Taking Remote Collaboration To The Future is Already Here," from .conf20, we talked about our new Remote Collaboration feature, which helps field workers and remote experts collaborate in AR. In today’s post, we'll talk about our advancements in Object Detection. This new feature makes it even easier to deploy Splunk AR with your assets.

Smoothing the Bumps of Onboarding Threat Indicators into Splunk Enterprise Security

This blog is part two of Splunk's Sunburst Backdoor response aimed at providing additional guidance to our customers (you can read part one, "Using Splunk to Detect Sunburst Backdoor," by Ryan Kovar). In this blog, we’ll cover how to ingest threat indicators to combat Sunburst Backdoor in Splunk Enterprise Security (ES).

Recover Lost Visibility of IT Infrastructure With Splunk

The news of the “Sunburst Backdoor” malware delivered via SolarWinds Orion software has organizations choosing to shut down Orion to protect themselves. This includes several U.S. government organizations following the recent CISA guidance. If you are considering a similar response in your own environment, a critical next step is quickly restoring the lost visibility to the health and operations of your infrastructure.

Genesys + Splunk = Complete Control Over Your Contact Center

Genesys is one of the world’s leading Contact Centre platforms, offering their customers the ability to deliver superior experiences. Genesys offers a range of solutions which cover SaaS, multi-cloud, and on-premises options to cater for all of their customer requirements. Splunk is traditionally known for helping customers with challenges around IT monitoring and security requirements regardless of whether they are running an on-premises datacenter or have a cloud first approach.

AWS Well-Architected Workload Recommendations in Splunk

The Well-Architected Tool is a new AWS service that compares the state of your workloads with AWS architectural best practices. Splunking your workload state and improvement recommendations will give you better insights into your applications as well as best practices to follow along your cloud journey. The Well-Architected integration in Grand Central will give you workload insights broken down by the following 5 pillars.

Partner With Splunk on Our Data-To-Everything Journey

As we approach the end of an unpredictable year, it’s a good time to reflect on the ways data has made a positive impact. Data is helping stop human trafficking with Global Emancipation Network, connected relief resources during crises with NetHope, and saved lives during wildfires with Zonehaven. And with our powerful partner ecosystem, and the arrival of the Data Age, there is so much more we can accomplish together.

Predictions: The AI Challenges of 2021

The overall theme of Splunk’s four-part 2021 Predictions report is the rapid acceleration of digital transformation, driven by the specific event of the COVID-19 pandemic, and the momentum of data technologies that have brought us into a true Data Age. Nowhere is that acceleration going to be more transformative than around the application of artificial intelligence and machine learning.

Using Splunk to Detect Sunburst Backdoor

TL;DR: This blog contains some immediate guidance on using Splunk Core and Splunk Enterprise Security to protect (and detect activity on) your network from the Sunburst Backdoor malware delivered via SolarWinds Orion software. Splunk’s threat research team will release more guidance in the coming week. Also please note that you may see some malicious network activity but it may not mean your network is compromised. As always review carefully.

Experience Your Data in 3D with Splunk VR

Ever wanted to see and experience your data in 3D? Splunk VR unlocks the third dimension for data visualizations, so you can naturally interact with visualizations in virtual reality and find insights faster than ever before. Use Splunk VR to give your workflow an infinite canvas, free your data exploration from limited monitor screens, and display as much information as you want around you.

Amazon Connect App for Splunk

The Amazon Connect App for Splunk uses a variety of data sources to help gain insight into your contact center performance both historically and in real-time. In standard Splunk fashion, data is democratized so from DevOps and AppDev teams, to Network and Service Operations Centers, to Contact Center Operations, to Engineering and Capacity Management, there’s something in the app for everyone.

Pipeline Analytics for Code-To-Cloud Visibility

The software delivery chain (SDLC) is the application of applications. If it is not running, you cannot ship code. In this episode of Dissecting DevOps, Dave and Chris cover how you Operate, Measure, and Audit your SDLC to ensure that your organization has Code-To-Cloud Visibility. Because the SDLC is an app for apps, treat it as you would any other application.

The Value of Operationalizing MITRE ATT&CK According to Splunk With Guest Speaker From IDC

The global pandemic has fueled a rapid digital transformation — and led to permanent shifts in cybersecurity. In a recent joint webinar with Bryan McAninch, senior solutions engineer at Splunk, and guest speaker Chris Kissel from IDC, "Sp(e)lunking Security with MITRE ATT&CK® featuring IDC Research," they shared seven overarching trends in cybersecurity for 2021. One notable, but foundational, trend mentioned was the need to understand risk.

Splunk Named a Leader in The Forrester Wave: Security Analytics Platforms, Q4 2020

We’re thrilled to share the news that Splunk has been named a Leader in The Forrester Wave™: Security Analytics Platforms, Q4 2020. It’s an honor to be named a Leader by Forrester. We view it as an affirmation of our commitment to customer success and a reflection of our ability to understand their needs. Through close collaboration with our customers, we have developed innovative solutions to protect their data hosted in on-premises, hybrid or multi-cloud environments.

Splunk TV - Companion App

Introducing Splunk TV Companion, the iPad app that lets you manage all your Splunk TVs, anywhere in the world, all from one place. Centralize content control of your TV displays on your iPad, and remotely display dashboards to any Apple, Android, or Fire TV. Whether you have several TVs in a single location or are remotely managing a collection of TVs across the globe, use Splunk TV to coordinate your workforce around important events from a central location and effortlessly bring dashboards to the attention of those who need it.

Bigger is Better with Splunk TV: Highlights of .conf20

Last year at .conf19, we announced the GA release of Splunk TV, our free app for Apple TV that provides users with a secure, reliable, read-only platform to display Splunk dashboards on their TVs. Splunk TV was built with security in mind, to power your SOCs and NOCs. Using Splunk TV instead of running dedicated computers to power each screen saves money and increases security. The read-only experience eliminates the risk of someone with physical access tampering with your environment.

CI/CD Detection Engineering: Failing, Part 3

It was over a month ago that I promised we would tie together Splunk Security Content and the Splunk Attack Range to automatically test detections. Ultimately, using these projects together in a Continuous Integration / Continuous Delivery (CI/CD) workflow with CircleCI brings the rigors of software development to the SOC and truly treats 🛡detection as code. Well, I want to share how we have failed at achieving this goal.

Something Else To Be Thankful For: Splunk Security Essentials 3.2.2

Well, it’s been a while since you read a blog dedicated to the latest release – okay, the latest several releases – of Splunk Security Essentials (SSE). We have been busy behind the scenes, however, so let’s catch you up on SSE’s latest features, which include the new version of our content API, and externally with updates from MITRE and the release of ATT&CK v7.2 (with Sub-Techniques) and ATT&CK v8.

Ronald van Loon & Sendur Sellakumar | Splunk Cloud Is Rebuilt for the Data Age

Data analyst Ronald van Loon sits down with Splunk’s Sendur Sellakumar to discuss how companies can succeed in the data age. The conversation covers shifting to a cloud-native experience, honing in on a data-to-everything strategy, and customer-centric approach to data and product development. The majority of organizations are not prepared for an influx of data on the scale promised by the dawning data age. To thrive, every organization needs a complete view of its data — real-time insights with the ability to take real-time action.

Splunk Infrastructure Monitoring is AWS Outposts Ready

We are excited to announce that Splunk Infrastructure Monitoring has achieved Outposts Ready designation. This designation recognizes that Splunk provides proven solutions for customers to build, manage and run hybrid cloud applications. AWS Outposts Ready designation establishes Splunk as an AWS Partner Network (APN) member that provides validated integrations with a specific focus on observability and monitoring of AWS Outposts deployments.

Monitor Amazon EKS Distro (EKS-D) with Splunk Infrastructure Monitoring

We are excited to partner with AWS in launching Amazon EKS Distro (EKS-D), the official Amazon Kubernetes distribution, which includes the same secure, validated, and tested components that power Amazon EKS. Splunk Infrastructure Monitoring provides a turn-key, enterprise-grade Kubernetes monitoring solution for Amazon EKS. Additionally, Splunk Infrastructure Monitoring provides out-of-the-box monitoring of Kubernetes Control Plane.