suky bal
“We can generate ad-hoc reports to track any transaction or user activity QSA auditors want to see and easily show we are PCI compliant in minutes. I've decreed Splunk will be a part of all data center build-outs going forward.”
Suky Bal, Director of IT
“Federal agencies should implement Splunk because it’s the only product out there that can bring all the security information together, correlate and bring a coherent picture of your security posture.”
Bill Hornish, Federal Business Development, Splunk
peter bassill
“We chose Splunk for PCI compliance for its ability to collate and report on any form of log file or data stream. It gives us highly granular logging information and turns any data into a concise management report.”
Peter D. Bassill, CISSP, Group Information Security Officer
Meno Schnapauff
“It’s easy to centralize our IT data into Splunk, enabling admins, application developers, the monitoring team—anyone in IT to securely access they data they need to solve problems more quickly.”
Meno Schnapauff, System Engineer
Gavin Reid
“Splunk allows us to quickly consolidate and correlate disparate log sources, enabling previously impractical monitoring and response scenarios.”
Gavin Reid, CSIRT Manager
Peter D. Bassill
“Splunk’s ability to collate and report on any form of log file or data stream is being leveraged for a wide variety of requirements including the need to detect and investigate fraudulent activity.”
Peter D. Bassill, CISSP, Group Information Security Officer
David Jones
“Splunk automated our evidence gathering for SOX compliance, freeing up engineers to work on revenue-generating activities vs. compliance related tasks.”
David Jones, IT Operations Manager
David Hazekamp
“Splunk’s ROI was less than a week. We witnessed a tremendous increase in productivity.”
David Hazekamp, Former Senior Security Analyst
Michael Langhorst
“With Splunk we can complete security investigations in 1.5 hours versus the 1.5 days it used to take to find the log data we needed just to start the investigation.”
Michael Langhorst, Senior Systems Engineer

資訊安全總覽

傳統方法:過載的資料阻礙事件的回應能力

您的組織或許像大部分的組織一樣,已部署各種不同的安全性技術,例如「深層防護」、防火牆、網頁代理伺服器、存取控制系統等多重的IDS系統。這些技術皆會產生大量的資料,可說是幸,也是不幸。

創新思維:所有資料皆相互關聯而集中於一處

您可從單一位置即時搜尋、警示及報告任何使用者、網路、系統或應用程式活動、組態變更,以及其他IT資料。此外,您也能從單一位置免除設置多重主控台的需要,並追查到攻擊者的行蹤。現在您可執行更深入的分析,並快速而徹底地予以回應,降低您風險及危險曝露程度。讓您擁有您一直冀求卻從未想過能真正達成的完整可見性。

優勢

  • 加速事件的回應能力
  • 降低危險曝露程度及風險
  • 在發生曝露情況前,就找出未預料到的潛在威脅
  • 持續觀察不斷變化的威脅趨勢
  • 消除主動錯誤訊息
  • 讓您的員工更聰明且更有效率

Splunk可運用於:

事件回應
在您接獲任何可疑活動的警示或報告時,Splunk將會是您第一個處理的窗口。

安全性監控
讓您輕易地跨越IT藩籬,監控安全性事件,並搜尋您路由器及防火牆記錄檔中的資料流違反情況、尋找伺服器及應用程式上的違反情況,或是尋找未經授權或不安全的組態變更。

詐欺偵測
Splunk讓您擁有偵測精密詐欺的能力。

內部威脅
讓您的組織具備必需的彈性分析能力,以偵測出所有類型的內部威脅。

安全性報告
Splunk可跨越您所有的IT基礎結構及技術,讓您從單一位置即能產生報告。