Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Incident Response

Splunk Unveils New Threat Detection, Analytics Offerings

Splunk, a provider of software that helps organizations gather and make use of machine data from a various sources, this week released Splunk Enterprise Security 4.0 (formerly Splunk App for Enterprise Security) and Splunk User Behavior Analytics (UBA) security solutions.

Splunk, a provider of software that helps organizations gather and make use of machine data from a various sources, this week released Splunk Enterprise Security 4.0 (formerly Splunk App for Enterprise Security) and Splunk User Behavior Analytics (UBA) security solutions.

The new Splunk Enterprise Security 4.0 is meant to help organizations track an attacker’s steps through ad hoc analysis, while Splunk UBA offers out-of-the-box capabilities for detection of cyberattacks and insider threats. According to Splunk, Enterprise Security 4.0 (ES) offers improved breach detection and better response to multi-stage attacks, while also offering collaboration capabilities through an extensible analytics framework. The release also offers a series of new features and benefits, such as Investigator Journal, which monitors ad hoc searches and activities to streamline analysis of multi-stage attacks.

Splunk Logo at HQES, which requires Splunk Cloud or version 6.3 of Splunk Enterprise, also comes with Investigator Timeline, which makes it possible to place events, activities and annotations within an investigation timeline for improved understanding and visualization of cause and effect. The features allows different members of a security team to place elements into the timeline to share their perspective of the event when collaborating on incident and breach investigations.

With Enterprise Security Framework, customers, vendors and third parties can extend the ES functionality with new applications that can run within ES. In addition to access to these apps, they also receive access to features such as alert management, risk, threat intelligence, and identity and asset frameworks.

Splunk UBA, which was built using technology gained from its $190 million acquisition of Caspida earlier this year, helps businesses improve breach detection based on machine learning, behavior baseline, and peer group analytics. According to Splunk, the solution was designed to provide security analysts with a kill chain visualization to help them focus on meaningful threats with malicious activities. By getting data into Splunk UBA quickly, organizations can operationalize security and streamline incident response, the company said.

“When critical networks are under assault, every second counts. Splunk security solutions give an edge to security teams by improving attack and breach detection and incident response,” said Haiyan Song, senior vice president of security markets, Splunk. 

“Many customers consider Splunk solutions to be their nerve center for security because they help enable teams to leverage their entire security technology stack and utilize their data to detect, understand and take rapid, coordinated action across the organization,” she added. 

Advertisement. Scroll to continue reading.

Both products will be generally available by the end of October this year, the company said.

Written By

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Delve into big-picture strategies to reduce attack surfaces, improve patch management, conduct post-incident forensics, and tools and tricks needed in a modern organization.

Register

Organizations are investing heavily in third-party risk management, but breaches, delays, and blind spots continue to persist. Join this live webinar as we examine the gap between how organizations think their third-party risk programs are performing and what’s actually happening in practice.

Register

People on the Move

Anurag Jain has been appointed Senior Vice President of Engineering at CodeHunter

CTERA has appointed Tal Sarfaty as Senior Vice President of Cybersecurity.

Quantum Secure Encryption has named Michael Massing as Chief Technology Officer.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.