Virtualization Technology News and Information
Article
RSS
Splunk and Palo Alto Networks Join Forces to Enhance Enterprise Security Intelligence

Splunk Inc., the leading software platform for real-time operational intelligence, and Palo Alto Networks, the network security company, today announced a joint solution that takes security intelligence across the enterprise to a new level. Working together, Splunk and Palo Alto Networks have created the Splunk App for Palo Alto Networks 3.0, which enables users to leverage their machine-generated big data to analyze risk, improve security posture and compliance and address a number of additional operational and regulatory concerns. By using the unique and context-rich data generated by Palo Alto Networks in the Splunk application, users can gain better insights and automatically improve their security posture. Splunk and Palo Alto Networks will demonstrate the Splunk App for Palo Alto Networks at the RSA Conference 2013 this week at Moscone Center in San Francisco.

"Palo Alto Networks is widely recognized as one of the most innovative network security companies in the world," said Bill Gaylord, senior vice president of business development, Splunk. "By combining our knowledge in one solution, it enhances our respective commitment to providing customers a new level of insight into their security posture."

"Splunk is a disruptive force in analytics, reshaping the capability to gain insight from data in IT and the business," said Chad Kinzelberg, senior vice president of business and corporate development, Palo Alto Networks. "Our mutual customers view this joint solution as a significant advantage to creating actionable insights to assess risk, prevent threats, and improve security. We are also confident that this strategic partnership will continue to lead our industry in security intelligence for enterprise organizations."

Splunk App for Palo Alto Networks

The Splunk App for Palo Alto Networks takes a context-rich information feed in network security, now including information on APTs from WildFire, to provide valuable insights and improve visibility. With traditional network security devices, the data generated is limited to port, protocol, and IP address information. With Palo Alto Networks, more useful data such as applications, users, and threat content is available within Splunk(r) Enterprise. With a few clicks, administrators can visualize all of this information together and take rapid action on threats and trends, directly from the app interface. The app also introduces key, new capabilities including:

  • Ability to Directly Configure Palo Alto Networks Devices: The new App enables Splunk searches to easily, and where appropriate, automatically change configurations on Palo Alto Networks next-generation firewalls, from within the Splunk interface. For example, an administrator analyzing data from an Exchange server could identify a potential security risk in message logs and trigger an update to that user's profile on the device, resulting in an automated, improved security posture.
  • Improved Scalability and Performance for Large Deployments: The new App can handle significantly more data per day by leveraging new features in Splunk Enterprise 5. The improved scalability gives the Palo Alto Networks user the depth and breadth of visibility needed to make use of the massive amounts of data in context to find advanced threats hiding in a sea of network traffic. Splunk's new indexing techniques quickly turn this data into meaningful visualizations providing decision support and faster detection of complex threats.
Published Tuesday, February 26, 2013 8:33 AM by David Marshall
Filed under:
Comments
There are no comments for this post.
To post a comment, you must be a registered user. Registration is free and easy! Sign up now!
top25
Calendar
<February 2013>
SuMoTuWeThFrSa
272829303112
3456789
10111213141516
17181920212223
242526272812
3456789