Q: You'll be at Black Hat Asia. Have you found there are security issues that are faced more in Asian markets and how can Splunk technology face them?
Joe Goldberg: Actually Asian organizations face the same threats that organizations in other countries do. Asian organizations possess confidential data, whether it is intellectual property or customer data, and they need to protect it from advanced cyber threats such as nation states, cybercriminals, or hacktivists. Industry research consistently confirms that among the top countries targeted by advanced threats, several Asian countries are among the top 10.
To protect confidential data, security teams in Asia have security use cases that include log management, incident investigation and response, forensics, security and compliance reporting, fraud detection and real-time detection of known and unknown threats.
In order to perform these use cases, IT Security teams need to be able to index all their structured and unstructured machine data, including "non-traditional security" IT data. This is because all data can be security relevant and contains the minute details of cyber security threats. IT Security teams also need a fast way to search through this massive amount of machine data, turn it into useful reports and visualizations to identify threats and measure risk, and correlate on the data to detect threats in real-time.
Splunk technology can help organizations with these challenges. Splunk is a big data security intelligence platform, used by over 2500 security customers.
Splunk can index all the machine data in an organization and make it available for SIEM-like use cases including threat detection, advanced correlations and alerting, incident investigation, and reporting. Splunk can also perform statistical baselining and analysis to identify outliers and abnormal behavior that may represent advanced, unknown threats. We are much more flexible, faster, and scalable then traditional SIEMs.
Q: What are you excited about at Black Hat Asia? And how can companies/attendees connect with your company while at the show?
Goldberg: Asian organizations are beginning to see the promise of big data security analytics as a next-generation approach to detect and defeat advanced threats. As such, we are seeing a phenomenal amount of interest in big data for security use cases in Asia and we are excited to attend Black Hat Asia to further educate the market here on how they can use big data to improve their security and compliance posture.
Companies and attendees can connect with Splunk at our booth in the Sponsor Hall. At our booth, attendees can speak with Splunk security experts to see how Splunk is used as a big data security intelligence platform or SIEM. Attendees can also see demos highlighting the Splunk App for Enterprise Security, the Splunk App for PCI Compliance and many other security-related apps from our partners including Palo Alto Networks, Cisco, FireEye and Blue Coat. Also, they can talk with Splunk technical experts to get answers on their toughest deployment and product questions.