<<

Copyright © 2016 Splunk Inc.

Moving From Data To

Mark Runals Lead Security Engineer, The Ohio State University Disclaimer

During the course of this presentaon, we may make forward looking statements regarding future events or the expected performance of the company. We cauon you that such statements reflect our current expectaons and esmates based on factors currently known to us and that actual events or results could differ materially. For important factors that may cause actual results to differ from those contained in our forward-looking statements, please review our filings with the SEC. The forward- looking statements made in the this presentaon are being made as of the me and date of its live presentaon. If reviewed aer its live presentaon, this presentaon may not contain current or accurate informaon. We do not assume any obligaon to update any forward looking statements we may make. In addion, any informaon about our roadmap outlines our general product direcon and is to change at any me without noce. It is for informaonal purposes only and shall not, be incorporated into any contract or other commitment. Splunk undertakes no obligaon either to develop the features or funconality described or to include any such feature or funconality in a future release.

2 Mark Runals

4 yr Splunk User ArcSight admin for 3 yrs Worked in InfoSec for 10+ yrs 2015 SplunkTrust Member Ø Geng data into Splunk isn’t the end game!

3 Outcomes

Paradigm to rethink data/analysis

Common framework for Admins & ‘Management’

Deeper appreciaon for what Splunk is

4 DIKW Pyramid

Wisdom Applicaon / Applied

Knowledge What the data means

Informaon What the data is

Data Bits & Bytes

5 Typical Business

Management Wisdom Conceptual Views Wisdom Lines of Business Service Health Knowledge Knowledge Data Analysis Gap Informaon

Proxy System Admins System Centric Views N++ Data Component Health ….. Discreet SMEs

Vuln Scan

6 Typical Business

Management Wisdom Conceptual Views Wisdom Lines of Business Microso Service Health Excel Knowledge Knowledge

Informaon

Proxy System Admins System Centric Views N++ Data Component Health ….. Discreet SMEs

Vuln Scan

7 What Splunk Brings

Business insight from Wisdom operaonally enriched data

Knowledge • Enrich data with business context • Powerful analyc plaorm • Correlate data across silos Informaon • Dynamic query Proxy

Data ….. N++

Vuln Scan

8 Splunk Maturity Model

Real-me Business Proacve Operaonal Insight Visibility

Proacve Monitoring Search and Alerng and Similaries to DIKW…. Invesgate

Reacve 9 OSU Mobile App - Data

10 OSU Mobile App - Informaon

11 OSU Mobile App - Knowledge

12 OSU Mobile App - Wisdom

13 Other

• Leverage the Splunk Common Informaon Model (CIM) Common ‘language’ across data types W • Use Knowledge Objects to bridge systems to services lookups, tags, evenypes K

• Make alerts more aconable – not just What happened I Incorporate recipient’s ‘next’ queson (ie where, who) D

14 Final Thoughts

• Understand the difference between Measurements and Metrics Metric = combinaon of 2 or more measurements W • Administer Splunk with end state in • What are your use cases? K • What pain points are you trying to address? I • Help bridge the Informaon and Knowledge analyc gap Ø Key step in leveraging Splunk toward ‘Wisdom’ ends D

15 THANK YOU