Splunk enhances incident response

Splunk, the cybersecurity and observability provider, has added new product innovations to its unified security and observability platform at the company’s annual user conference, .conf23.

The inability to address incidents - whether a security threat or a customer-impacting disruption - hinders an organisation’s ability to remain competitive, Splunk said. By unifying security and observability processes and technologies, organisations can help ensure their digital systems remain resilient. According to a recent ESG report, 55% of senior IT decision makers say observability enabled them to gain more insight into vulnerabilities, and 51% said observability remediation capabilities enabled their security teams to act faster.

The new capabilities build on Splunk’s unified security and observability platform, and paired with Splunk AI offerings, provide organisations with visibility across their hybrid environments to optimise costs, accelerate detection, investigation and response, as well as drive digital transformation. All are designed to help SecOps, ITOps and engineering teams cut through operational complexity and provide shared visibility across their tech stack to drive efficient incident response. Unified experiences and workflows enable them to detect threats, investigate and respond — quickly, accurately, and at scale, Splunk said.

According to Splunk, today’s security operations teams are overwhelmed by alerts, manual processes and siloed tools and lack the context needed to scope complex attacks. Splunk Security products provide a unified solution that integrates Splunk’s security technologies across detection, investigation and response to simplify these workflows and reduce alert fatigue. With Splunk’s enhanced unified security operations experience, customers can automate 95% of their incident response tasks.

The addition of Splunk Attack Analyzer (formerly TwinWave) to this unified experience enables security teams to automate the analysis of malware and credential phishing attacks to uncover complex attack techniques used to evade detection. Through an integration with Splunk SOAR, Splunk Attack Analyzer enables security analysts to automate threat forensics that provide accurate, timely detections and reduce the time and resources spent on manual investigations.

Centralised workflows and troubleshooting tools foster better customer experiences. With the preview of the OpenTelemetry Collector as a technical add-on (TA), Splunk Platform customers can more easily adopt Splunk Observability Cloud and deploy the Collector alongside their existing forwarders to capture metrics and traces. This new feature eliminates the headaches of deploying and managing two agents by providing customers a unified view of their infrastructure and services. The introduction of the Collector is a milestone in Splunk’s commitment to the OpenTelemetry project and the open-source community by helping customers transmit their data with less complexity and greater flexibility.

With Splunk’s new Unified Identity, ITOps practitioners and engineers can now seamlessly and immediately access Splunk Cloud Platform and Splunk Observability Cloud data with one user identity. As a result, customers can enjoy an improved login experience and instantly access log data from Splunk Cloud Platform data for faster troubleshooting. The integration provides ITOps practitioners and engineers with a common set of visualisations to drive rapid detection and response.

The latest advancements in Splunk Cloud Platform and Splunk Enterprise 9.1 enable SecOps, ITOps and engineering teams to visualise data flows across their entire tech stack to foster deeper collaboration. The enhancements include:

- Ingest Actions now expands capabilities for routing data to multiple, distinct Amazon S3 buckets, enabling greater granularity in data management.

- The new Federated Search for Amazon S3 preview offers a unified search experience of data at rest in Amazon S3 buckets - without having to ingest that data to Splunk - and across Splunk instances and third party data lakes through its integration with Ingest Actions and Edge Processor for better data movement. In turn, customers avoid latency and unnecessary charges.

- Edge Processor featuring Search Processing Language version 2 (SPL2) now enables data ingestion and export to Splunk using HTTP Event Collector (HEC), making it easier to manage data. In addition, to complement data sovereignty and compliance needs, users can set default destinations per Edge Processor for more flexibility in routing.

"We are in the business of delivering happiness, something we can't do without continuous, real-time access to the data and systems we need to keep our business secure and reliable," said Devon Bryan, Global CIO, Carnival Corporation. 

"We want to provide extraordinary customer experiences on our cruises that keep guests coming back again and again. That’s where we are and where we’re headed, and I can’t think of a better partner to help us get there than Splunk.”

"As the digital landscape evolves, organisations really need a holistic approach to security and observability. A comprehensive strategy can help security teams safeguard their valuable assets, detect and address potential threats proactively, ensure regulatory compliance, maintain operational continuity and build trust among their stakeholders," said Jon Oltsik, Distinguished Analyst and Fellow at TechTarget’s Enterprise Strategy Group.

“Splunk's latest innovations can help, as they are designed to empower and speed up IT operations, security operations and engineering teams' work and collaboration for detecting, investigating and remediating security issues.”

“Real-time cross-team collaboration is essential for a digitally resilient business, and SecOps, ITOps and engineering teams all share a need to detect, investigate and respond,” said Tom Casey, SVP & GM of Products and Technology at Splunk.

“At Splunk, we’re excited to announce our latest innovations that empower these teams with shared data context, more unified experiences and the only integrated security and observability platform powered by Splunk AI, so they can work together to make their systems secure and reliable.”

Comments

Popular posts from this blog

Fortinet enhances FortiRecon to align with CTEM framework

SentinelOne recognised as a 2025 Gartner Peer Insights Customers’ Choice for XDR

AWS: AI adoption grows 20% in Singapore