0% found this document useful (0 votes)
121 views4 pages

Splunk and Cisco

Splunk and Cisco

Uploaded by

Maddy Stuart
Copyright
© © All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
121 views4 pages

Splunk and Cisco

Splunk and Cisco

Uploaded by

Maddy Stuart
Copyright
© © All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
You are on page 1/ 4

PARTNER BRIEF

SPLUNK AND CISCO


Operational Intelligence Across Your Cisco Environment and Beyond

categorical record of user behavior, cybersecurity


• Splunk integrations with Cisco products
and networking solutions empower IT risks, application behavior, service levels,
organizations to quickly troubleshoot issues fraudulent activity and customer experience.
and outages, monitor end-to-end service It’s also the fastest growing, most complex and
levels and detect anomalies valuable segment of big data.
• Splunk integrations across Cisco’s security
portfolio help provide a comprehensive, Splunk and Cisco Deliver Operational
continuous view of an organization’s entire Intelligence at Scale
security posture The Splunk platform turns machine data into
• Splunk and Cisco are collaborating across valuable insights. It’s what we call Operational
a range of emerging use cases to enable Intelligence.
business transformation
Splunk has closely aligned with Cisco to help
• Splunk and Cisco deliver exceptional
performance and scale when Splunk organizations gain insights from the vast amounts
software is deployed on Cisco UCS of data generated by Cisco’s industry-leading
Integrated Infrastructure security, networking, wireless, datacenter and
collaboration portfolios. These insights enable
our joint customers to minimize operational and
Organizations today operate in an environment
security risks, improve efficiency and ultimately
that’s mobile and connected, with traditional
transform their organizations.
boundaries expanding into the cloud and to the
very edge of the network. They’re exploring new Turn Silos of Data into Operational Insights
software-defined datacenters and managing an
Today’s IT infrastructure is a complicated,
explosion of data from the Internet of Things—
layered group of siloed and interconnected
industrial data, sensors, wearable devices
technologies. Virtualized and cloud infrastructures
and more. Applications are being delivered
are challenging to control, manage, secure and
continuously, with some organizations releasing
scale. Gaining visibility across the infrastructure
new code multiple times per day.
to identify, diagnose and prevent outages is a
time-consuming, manual task. Traditional, siloed
Every element of the technology infrastructure
tools are ineffective because they can’t access or
running an organization (e.g., the webservers,
analyze all the relevant events across IT to link the
applications, network devices, mobile devices,
various causes of performance issues.
sensors, etc.) generates massive streams of data in
an array of unpredictable formats that are difficult
Splunk software helps organizations gain
to process and analyze by traditional methods or
operational visibility across infrastructure tiers
in a timely manner. This machine data contains a
and dramatically reduce mean-time-to-investigate
PARTNER BRIEF

Splunk apps and add-ons provide ready- “We can do more with our electronic health records
to-use functions for many Cisco products system because we’ve built a solid foundation with
and platforms including: Cisco and Splunk.”

• Cisco Advanced Malware Protection (AMP) Anne Lara, CIO


• Cisco AnyConnect Mobility Client Union Hospital of Cecil County
• Cisco Application Centric Infrastructure
(ACI)
higher infrastructure availability and performance
• Cisco ASR/ISR Routers
while improving management efficiencies.
• Cisco Call Manager
• Cisco Cloud Web Security (CWS)
• Cisco Email Security Appliance (ESA) Infrastructure Snapshot
• Cisco ASA/PIX/FWSM Firewalls • Traditional Network Devices. Search,
alert and report on network events and
• Cisco FireSIGHT (Sourcefire)
transactions in real time across a variety
• Cisco Identity Services Engine (ISE) of Cisco IOS-based routing, switching and
• Cisco IPS wireless devices for visibility across the
• Cisco Meraki Devices complete network stack.

• Cisco Next-Generation Firewall (NGFW) • Software-Defined Networking Controllers.


Provide fine-grained network telemetry,
• Cisco Next-Generation Intrusion Prevention
real-time visibility into dynamic traffic
System (NGIPS)
flows and the ability to optimize network
• Cisco Nexus/MDS/Catalyst Switches resources by taking action in response to
• Cisco pxGrid changing network conditions or security
• Cisco Secure Access Control Server (ACS) events.

• Cisco Unified Computing System (UCS) • Cisco ACI. Simplify troubleshooting,


particularly in multi-tenant environments,
• Cisco Web Security Appliance (WSA)
leveraging rich network statistics generated
• Cisco WLAN Controller by Cisco APIC. Network admins can
proactively avoid incidents with real-
time monitoring and alerting across the
(MTTI) and mean-time-to-resolve (MTTR) to keep environment and underlying infrastructure.
critical services running. • Servers. Proactively monitor UCS server
capacity, look at historical faults over time
Over a dozen free Splunk apps and add-ons for to identify trends, track power and cooling
Cisco products and platforms provide ready- costs and more.
to-use functions ranging from optimized data • Collaboration Tools. Easily browse and
collection to prebuilt visualizations. These report on real-time call data with the ability
integrations help accelerate correlation across to set proactive alerts and automatically
remediate issues to improve operational
infrastructure tiers for comprehensive operational
efficiency.
visibility—from the core to the edge and across
the cloud. Organizations can better detect
problems at their earliest stages, resulting in

Splunk and Cisco 2


PARTNER BRIEF

Accelerate Threat Detection and Response Together, Splunk and Cisco can help organizations
In today’s advanced threat environment, simple transform their businesses across a broad variety
monitoring of traditional security events is of industries and use cases, including:
insufficient. Security teams must be able to
• Helping rail operators improve service by
leverage all machine data for advanced analytics analyzing massive quantities of data from
capabilities and contextual incident response; and heterogeneous sources and geographically
they must be able to rapidly implement new threat dispersed networks of assets. This helps
them track defect forensics, identify the top
detection techniques to reduce time-to-threat-
sources of track defects and improve service
response and make business-centric decisions. reliability.
Your enterprise requires big data security solutions • Optimizing customer interactions for theme
that can adapt to advanced threats, evolving parks seeking to provide better experiences
adversary tactics and changing business demands, for their customers. Splunk’s ability to
analyze data captured by Cisco Meraki
providing your security staff with broader insights
wireless devices can provide insights on line
from new data sources generated at massive scale queues via cell phone pings that ultimately
across IT, the business and the cloud. enable park customers to spend more time
enjoying attractions and less time in line.
Splunk security solutions allow your security
teams to quickly detect and respond to internal Accelerate Time to Insight With Splunk on Cisco UCS

and external attacks, simplify threat management, Splunk software scales to collect and index
and minimize risk. Splunk’s analytics-driven hundreds of terabytes of data per day, across
security solutions are an ideal complement to multi-geography, multi-datacenter and cloud-
Cisco, which has more than 25 years of network based infrastructures. Cisco’s Unified Computing
security experience and one of the broadest System (UCS) Integrated Infrastructure for Big
security portfolios in the industry. Data offers linear scalability along with operation
simplification for single-rack and multiple-rack
Splunk integrations across Cisco’s security deployments.
portfolio facilitate a holistic approach that spans
heterogeneous environments, a range of security Technical Reports and Reference
platforms and all security-relevant data to deliver Architectures
a complete, continuous view of your organization’s • Cisco UCS Single Instance and Distributed
security posture. Architectures for Splunk Enterprise
• Cisco Validated Design: Cisco UCS
Better Insights to Drive Innovation and
Integrated Infrastructure for Big Data with
Business Transformation
Splunk
The Internet of Things is generating enormous
• Cisco Validated Design: Cisco Cloud Security
quantities of data from billions of new connections Virtualized Multiservice Data Center
that are often located beyond traditional
• Cisco “How to” Guide: Integrating and
boundaries. With the explosion of web-based and Monitoring Cisco ISE User-Device Context
cloud applications, the number of data sources in Splunk
has skyrocketed. Every new data source your • Cisco “How to” Guide: Splunk and pxGrid
company creates or accesses has the potential to Adaptive Network Control Mitigation
provide your business in invaluable insights, if it Workflow Actions
can be analyzed effectively.
Splunk and Cisco 3
PARTNER BRIEF

Cisco UCS has a proven ability to deliver


predictable, outstanding performance capable • Network Activity/Security. Integration with
of supporting Operational Intelligence at scale. Cisco firewalls enables advanced monitoring
for network-based attacks and helps
In addition to being validated in more than 100
detect security anomalies. Connections
worldwide industry performance benchmarks,
accepted and denied by port is an example
Cisco UCS delivers exceptional performance of information made easily available by a
and scale in Splunk Enterprise performance popular Splunk add-on that supports data
benchmark assessments. For example, the latest from Cisco ASA, PIX and FWSM firewalls.
release of Splunk software was shown to complete • Web Security. Track and report on web
searches up to six times faster then the previous surfing, conduct forensics evaluations to
release when tested on a 32-core Cisco UCS gather evidence, and correlate web logs with
other communication and authentication
system.
data, such as HR requirements.
To facilitate faster and more predictable • Email Security. Simplify email transaction
deployments, Cisco has published multiple tracing with a form-search dashboard that
reference architectures for Splunk software plus enables organizations to enter information
about the transaction, the sender, recipient
a comprehensive Cisco Validated Design that
and attachments and mine for any email
provides prescriptive, step-by-step guidance for
transaction.
deploying Splunk Enterprise on Cisco UCS.
• Access Identity and Context. Contextual
device and user data can be correlated with
Together, Splunk and Cisco enable organizations
other security event data to make it easier
to realize the potential of Operational Intelligence
and faster to investigate a suspicious event
across the organization and gain real-time business to determine if it is malicious or against
insights that create a strategic advantage. policy. Compromised users or devices can
be instantly quarantined and removed from
quarantine when appropriate.
Security Snapshot
• Endpoints. Streamline the collection and
• Threat Intelligence and Analytics.
reporting of IPFIX flows from laptops
Sourcefire eStreamer integration with Splunk
and other endpoints both on- and off-
delivers intrusion, impact, connection,
premise generated by Cisco AnyConnect
change, application and malware event data
NVM endpoint sensor technology. Get
as well packet data to Splunk, enabling more
granular usage information with drilldowns
comprehensive and up-to-date integration
of destination domains, applications and
than any legacy SIEM can offer. Cisco IPS
endpoint processes.
data that conforms to the Security Device
Event Exchange (SDEE) standard can also
be easily consumed and analyzed.

Download Splunk for free at www.splunk.com/download and check out the full library of Splunk Apps and Add-ons at
https://splunkbase.splunk.com/. For more information about Cisco products, platforms and solutions please visit www.Cisco.com.

[email protected] www.splunk.com

© 2016 Splunk Inc. All rights reserved. Splunk, Splunk>, Listen to Your Data, The Engine for Machine Data, Hunk, Splunk Cloud, Splunk Light, SPL and Splunk MINT are trademarks
and registered trademarks of Splunk Inc. in the United States and other countries. All other brand names, product names, or trademarks belong to their respective owners. PRNB-Splunk-CISCO-103

You might also like