Security sources
Firewalls, proxies, Active Directory and endpoints ready for detection.
We onboard your data sources into Splunk properly parsed, normalised to the Common Information Model and with an owner.
A badly onboarded source is worse than a missing one: wrong timestamps, unextracted fields, split or duplicated events. Searches fail silently and security detections miss what they should catch.
Five phases, always in the same order. Select each one to see what happens in it. In full projects they map onto the stages of our method.
We review your platform, your data sources, your searches and your licence consumption to know where you stand.
We design the solution on Splunk Cloud Platform: indexes, retention, ingest paths, apps and access controls.
We configure inputs, sourcetypes, field extraction and CIM mapping, and filter or mask anything that should not be indexed.
We validate timestamps, fields, volume and CIM conformance with verification searches that we hand over to you.
We measure usage, performance and cost after go-live and adjust what isn't adding value.
Firewalls, proxies, Active Directory and endpoints ready for detection.
Logs from internal applications with a custom format.
Logs from AWS, Azure or Google Cloud.
We build one: field extraction, a custom sourcetype and CIM mapping, documented so your team can maintain it.
Yes, by masking or discarding it before indexing, according to what your regulations require.
We validate timestamps, fields, volume and CIM conformance with verification searches that we hand over to you.
Tell us about your situation. If this service is not what you need, we will tell you; if it is, we will propose a concrete first step.
Request this service