Skip to content
fernet.consultores

Splunk Cloud

Splunk Enterprise Security.

Implementation and tuning of Splunk Enterprise Security so your SOC works with less noise and more context.

The problem we solve.

Enterprise Security delivers when its data, its models and its content are well prepared. Without that, the SOC receives hundreds of alerts with no context and ends up ignoring the ones that matter.

What’s included.

  • Implementation or review of Enterprise Security
  • Preparation of CIM data models and their acceleration
  • Asset, identity and threat intelligence frameworks
  • Risk-based alerting
  • Investigation workflows tailored to your SOC

How we work.

Five phases, always in the same order. Select each one to see what happens in it. In full projects they map onto the stages of our method.

We review your platform, your data sources, your searches and your licence consumption to know where you stand.

We design the solution on Splunk Cloud Platform: indexes, retention, ingest paths, apps and access controls.

We prepare data models, assets, identities and threat intelligence, and enable the detection content that matches your sources.

We review the first findings with your analysts and tune risk and thresholds until the alert volume is manageable.

We measure usage, performance and cost after go-live and adjust what isn't adding value.

Technical capabilities.

  • Splunk Enterprise Security
  • Risk-Based Alerting
  • Enterprise Security Content Update
  • Common Information Model
  • Asset & Identity Framework
  • Splunk SOAR integration

Use cases.

Overwhelmed SOC

Reduce alerts and give each one the context needed to investigate it.

New implementation

Get Enterprise Security up and running with prepared data.

Audit or regulation

Demonstrate detection and response for ENS, NIS2 or DORA.

Benefits for your organisation.

  • Fewer, better-prioritised alerts
  • Faster investigations
  • Measurable detection coverage
  • Evidence for audits

Deliverables.

  • Enterprise Security configured
  • Validated data models
  • Detection content enabled
  • SOC operations guide

Frequently asked questions.

Do we need Enterprise Security or is Splunk Cloud enough?

It depends on your team and your obligations. Enterprise Security adds incident management, risk-based alerting and ready-to-use content. We help you decide with data from your environment.

Do you replace our SOC?

We don't operate a 24×7 SOC. We help yours, whether internal or outsourced, work better.

What is risk-based alerting?

Instead of alerting on every single indicator, it adds up the risk from several indicators on the same user or asset and only alerts when the combination warrants it.

Shall we talk about Enterprise Security?

Tell us about your situation. If this service is not what you need, we will tell you; if it is, we will propose a concrete first step.

Request this service