Process-ITFrançais

Splunk expertise

We work across the full lifecycle of a Splunk platform: licensing, complex and hybrid architectures, Enterprise Security, SOAR automation, application development, cost optimisation and turning data into value.

Anatomy of an engagement

  1. Audit

    We measure the real state of the platform: architecture, indexer health, volumes, source quality, ingestion cost. The deliverable is a list of actions ordered by payoff.

  2. Architecture

    Designing or reworking the architecture, on-premise, cloud or hybrid. Log normalisation, migration from another SIEM, integration with existing tooling.

  3. Enterprise Security

    Implementing and tuning ES: detection use cases mapped to MITRE ATT&CK, noise reduction, alert quality over alert volume.

  4. Automation and development

    SOAR playbooks, custom Splunk applications, business-oriented dashboards, automation of repetitive operational work.

The applications we build

We develop and publish our own Splunk applications. They are publicly available on Splunkbase, installable by any organisation.

Before / after

Cyberwatch vulnerability data in SplunkBefore: what the Cyberwatch API produces once collected, eleven thousand nine hundred and twenty-seven raw events, one per asset and CVE, with no data model and no order of priority.After: the same index seen through our app, current exposure, severity, exploitation probability and triage state, on one screen.
Before — Cyberwatch vulnerability data in Splunk
After — Cyberwatch vulnerability data in Splunk