Presentation to media & analysts at Interop 2013 in Las Vegas. Overview of Cisco's SDN strategy & customer solutions in development. Learn more about how Cisco is moving forward with software solutions and helping our customers build smarter businesses with the new application economy.
Cumbre PR/AR sobre el mercado Telco en America LatinaFelipe Lamus
The document discusses technology transitions in the market and how they are impacting service providers and IT. It covers topics like public clouds, software-defined architectures, white box switches, and the industry shake up. It presents Cisco's strategies and platforms for leading through this transition, including the Application Centric Infrastructure (ACI), Cisco ONE platform, and evolving software and cloud offerings. Cisco aims to lead the next technology transition to the application economy through its platforms, architectures, software, and ability to disrupt markets as it has done previously through innovation.
SplunkLive! London 2017 - DevOps Powered by SplunkSplunk
DevOps is powering the computing environments of tomorrow. When properly configured, the Splunk platform allows us to gain real-time visibility into the velocity, quality, and business impact of DevOps-driven application delivery across all roles, departments, process, and systems. Splunk can be used by DevOps practitioners to provide continuous integration/deployment and the real-time feedback to help the organisation with their operational intelligence. Join us for an exciting talk about Splunk’s current approach to DevOps, and for examples of how Splunk is being used by customers today to transform DevOps initiatives.
Winning Strategy For Hybrid Cloud EnvironmentsCarl De Groote
This document discusses strategies for hybrid cloud environments. It begins by outlining the benefits of hybrid clouds, such as balancing costs, speed, scale, security and control between on-premise and third-party cloud resources. It then discusses elements needed to implement hybrid clouds successfully, such as application integration, an intercloud fabric, and consistent security policies across environments. Finally, it proposes starting with use cases and application requirements, building a secure software-defined private cloud foundation, and focusing on application portability and orchestration across platforms.
Hosted Security as a Service - Solution Architecture DesignCisco Canada
he Hosted Security as a Service session provides in depth discussion on cloud based security services leveraging Cisco security solutions. This session is appropriate for service providers who are interested in delivering managed security services to their customer from their cloud infrastructure. We will provide detailed designs and guidance on: - cloud security services including FW, VPN, web and email services - architecture layers through influence of NfV and SDN - KVM and VMware based solutions - orchestration flexibility and options - Day 0 and Day 1 provisioning - Day 2 monitoring and reporting.
Transform your organization with cisco cloudsolarisyougood
Cisco hosted a bootcamp with sessions on transforming organizations with cloud technologies through automation and management platforms. The bootcamp schedule included sessions on Cisco UCS, virtual desktop infrastructure, private and hybrid clouds, and converged infrastructure at branches. Social events included a Cisco party and partner brunch.
Стратегия Cisco в ЦОД (доклад на английском языке)Cisco Russia
1) The document discusses Cisco's data center architecture and solutions for digitization, IoT, cloud-native applications, and hybrid cloud. It focuses on Cisco's UCS, HyperFlex, ACI, and CloudCenter products.
2) Cisco's data center architecture centers around policy-driven infrastructure with UCS, HyperFlex, ACI, and hybrid cloud solutions. Key products discussed include UCS, HyperFlex, ACI, and CloudCenter.
3) The architecture is designed to provide a foundation for business agility through integrated infrastructure, hyperconvergence, software-defined networking, hybrid cloud, and multi-cloud management.
This document summarizes a presentation about Splunk's platform. It discusses Splunk's mission of helping customers create value faster with insights from their data. It provides statistics on Splunk's daily ingest and users. It highlights examples of how Splunk has helped customers in areas like internet messaging and convergent services. It also discusses upcoming challenges and new capabilities in Splunk like federated search, flexible indexing, ingest actions, improved data onboarding and management, and increased platform resilience and security.
Thanks for coming out to the first PNW user group of 2023, and our first IN PERSON user group in a couple years!
Dan Hogland caught us up on the latest Enterprise Security updates, Melissa Riley brought the best strategies to leverage FREE Splunk Education (and the Academic Alliances program for all you universities who joined us!) and we welcomed new User Group leader Rob de Luna.
See you in a couple of months, in person in Seattle!
1) Cisco has been using Splunk enterprise for over 7 years across many business units and teams, with daily indexing growing from 300GB in 2010 to over 2TB currently.
2) Cisco's Computer Security Incident Response Team (CSIRT) uses Splunk as their security information and event management (SIEM) platform to monitor 350TB of stored data across 60 global users.
3) The presentation discusses how Cisco and some of its customers have successfully deployed Splunk on Cisco Unified Computing System (UCS) servers to scale their Splunk environments and gain benefits of simplified and repeatable deployments.
Multi-Cloud ist in aller Munde. Das Verbinden von Public und Private Cloud Angeboten bis hin zu SaaS Diensten zu einer Lösung bietet die Möglichkeit, das Beste aus allen Welten in einer gemeinsamen Lösung zu integrieren. Allerdings bringt eine entsprechende Lösung auch höhere Komplexität, die es gilt zu beherrschen. Wie erstellt man eine höhere Transparenz, bessere Kostenkontrolle, bessere Übersichten beim Demand- und Kapazitätsmanagement in heterogenen Cloud Umgebung? Was ist in diesem Kontext Splunk Hybrid Search? Wie kann man Azure, AWS, GCP, Docker Container bis hin zu Salesforce und andere SaaS Dienste unter einen Hut bringen? In 45 Minuten werden wir einen einen Überblick über diese Fragestellungen geben.
Splunk provides a unified data platform that can provide global visibility across multi-cloud environments. It collects and analyzes data from various sources, both on-premise and in public clouds, to help users address challenges like lack of visibility, cost control, cloud sizing and vendor lock-in, consistent security, and unknown future questions. Splunk offers features like apps/add-ons for faster time to value, machine learning tools, and a single platform to monitor all deployments. Case studies show how companies use Splunk to enable cloud migration, cost optimization, and security across hybrid infrastructures.
Splunk provides a unified data platform that can provide global visibility across multi-cloud environments. It collects and analyzes data from various sources, both on-premise and in public clouds, to help users address challenges like lack of visibility, cost control, cloud sizing and vendor lock-in, consistent security, and unknown future questions. Splunk offers features like apps/add-ons for faster time to value, machine learning tools, and a single platform to monitor all deployments. Case studies show how companies use Splunk to enable cloud migration, cost optimization, and security across hybrid infrastructures.
This document provides information about sponsor sessions at a NetApp conference in Berlin, including sessions hosted by Cisco, VMware, Brocade, and other sponsors. It summarizes the topics to be covered in each sponsor session, such as FlexPod solutions with Cisco UCS and ACI networking, deploying virtual desktops with Citrix and NetApp storage, and best practices for performance analysis and storage optimization.
CISCO’s Cloud Journey (Keynote at Cloud Symposium) Marcus McEwen
The following slide show details a high level analysis of Cisco’s view of The Cloud. This presentation was given by Kanjal Trevidi from Cisco Cloud and Managed Services Business Development at the Equivoice Cloud Symposium
Cisco has integrated its newly acquired Sourcefire technology into its product portfolio. It has added Sourcefire's Advanced Malware Protection (AMP) capabilities to its content security products. Most importantly, Cisco introduced the Cisco ASA with FirePOWER Services next-generation firewall that combines the ASA firewall with Sourcefire's Next-Generation IPS and AMP technologies. This new offering provides improved visibility into threats, enhanced threat prevention, and a consolidated security platform. While the integration brings benefits, a single management console and tighter integration with other Cisco infrastructure products is still needed.
All Together Now: Connected Analytics for the Internet of EverythingInside Analysis
The Briefing Room with Mark Madsen and Cisco
Live Webcast August 18, 2015
Watch the archive: https://bloorgroup.webex.com/bloorgroup/lsr.php?RCID=0eff120f8b2879b582b77f4ff207ee54
Today's digital enterprises are seeing an explosion of data at the edge. The Internet of Everything is fast approaching a critical mass that will demand a sea change in how companies process data. This new world of information is widely distributed, streaming, and overall becoming too big to move. Experts predict that within two to three years, the bulk of analytic processing will take place on the fringes of information architectures. As a result, forward-thinking companies are dramatically shifting their analytic strategies.
Register for this episode of The Briefing Room to hear veteran Analyst Mark Madsen of Third Nature explain how a new era of information architectures is now unfolding, paving the way to much more responsive and agile business models. He'll be briefed by Kim Macpherson of the Cisco Data and Analytics Business Unit, who will explain how her company's platform is uniquely suited for this new, federated analytic paradigm. She'll demonstrate how edge analytics can help companies address opportunities quickly and effectively.
Visit InsideAnalysis.com for more information.
Cisco and Splunk: Under the Hood of Cisco IT Breakout SessionSplunk
Cisco has a long-standing relationship with Splunk, using its software and services for IT operations, security analytics, and other purposes across its global data centers. Some key points:
- Cisco has used Splunk for over 7 years to monitor over 70 applications and aggregate data from various systems.
- Splunk helps Cisco improve IT operations by reducing issues by 50% and resolution times by 90%, and reducing operational costs by 80%.
- Cisco's security team uses Splunk to conduct investigations, detecting up to 2-3 million security events per day from various sources. This allows for faster investigations and automated tasks.
- Cisco designs and validates architectures for running Splunk on its Cisco UCS servers
Primend Praktiline Konverents - Rakenduse keskne IT infrastruktuur / Cisco Ap...Primend
Andmekeskuse virtualiseerumise ja konvergeerumise tulemusena on tekkinud keskkond, kus seadmete senised haldamise lahendused ja protseduurid ei ole piisavad käideldavuse ja konfidentsiaalsuse tagamiseks. Uue põlvkonna halduslahendused peavad hakkama saama salvestuse, arvutuse ja rakenduste mobiilsusega.
Cisco Connect Halifax 2018 Accelerating the secure digital business through...Cisco Canada
This document summarizes Cisco IT's evolution to accelerate the secure digital business through technology and culture. Cisco IT has transformed its architecture process, moving to a modular, cloud-native approach with automation, continuous delivery, and data-driven operations. It established an eStore platform and consumer-oriented experience to simplify service provisioning. Cisco IT also advanced a global cloud strategy and data center transformation for security, resiliency, speed and capacity. This cultural shift required moving to an agile, self-service model through innovations like ACI and embracing new ways of working like DevOps.
Operating costs decrease and agility increases, allowing you to react quickly to new market opportunities.
http://www.cisco.com/web/offers/sp04/simplifying-operations/index.html?KeyCode=000947566
It is very much likely that most people are aware of Cisco network equipment such as routers and switches and maybe IP telephony too. Few people might have heard that Cisco manufactures servers and even less might have used them, especially in Cyprus. Cisco has been in the server market since nearly 10 years ago though, it is rated among the top server manufacturers and is market leader in blade servers.
Presentation of Cisco UCS server platform during Simplex-Cisco Technology Session that took place at the Londa Hotel in Limassol on 14 March 2018.
CL2015 - Datacenter and Cloud Strategy and PlanningCisco
This document discusses strategies for data center and cloud transformation over the next 5 years. It outlines key digital business trends like data growth, cloud adoption, and security threats that are driving organizations' IT initiatives. These include managing increased data and applications, optimizing cloud strategies, addressing disruptive business models, and securing distributed data and applications. The document advocates adopting flexible consumption models, automation, and supporting edge/IoT applications. It positions Cisco as uniquely able to enable digital transformations through its portfolio of networking, compute, storage, automation, analytics, and security solutions.
computer organization and assembly language : its about types of programming language along with variable and array description..https://www.nfciet.edu.pk/
This document summarizes a presentation about Splunk's platform. It discusses Splunk's mission of helping customers create value faster with insights from their data. It provides statistics on Splunk's daily ingest and users. It highlights examples of how Splunk has helped customers in areas like internet messaging and convergent services. It also discusses upcoming challenges and new capabilities in Splunk like federated search, flexible indexing, ingest actions, improved data onboarding and management, and increased platform resilience and security.
Thanks for coming out to the first PNW user group of 2023, and our first IN PERSON user group in a couple years!
Dan Hogland caught us up on the latest Enterprise Security updates, Melissa Riley brought the best strategies to leverage FREE Splunk Education (and the Academic Alliances program for all you universities who joined us!) and we welcomed new User Group leader Rob de Luna.
See you in a couple of months, in person in Seattle!
1) Cisco has been using Splunk enterprise for over 7 years across many business units and teams, with daily indexing growing from 300GB in 2010 to over 2TB currently.
2) Cisco's Computer Security Incident Response Team (CSIRT) uses Splunk as their security information and event management (SIEM) platform to monitor 350TB of stored data across 60 global users.
3) The presentation discusses how Cisco and some of its customers have successfully deployed Splunk on Cisco Unified Computing System (UCS) servers to scale their Splunk environments and gain benefits of simplified and repeatable deployments.
Multi-Cloud ist in aller Munde. Das Verbinden von Public und Private Cloud Angeboten bis hin zu SaaS Diensten zu einer Lösung bietet die Möglichkeit, das Beste aus allen Welten in einer gemeinsamen Lösung zu integrieren. Allerdings bringt eine entsprechende Lösung auch höhere Komplexität, die es gilt zu beherrschen. Wie erstellt man eine höhere Transparenz, bessere Kostenkontrolle, bessere Übersichten beim Demand- und Kapazitätsmanagement in heterogenen Cloud Umgebung? Was ist in diesem Kontext Splunk Hybrid Search? Wie kann man Azure, AWS, GCP, Docker Container bis hin zu Salesforce und andere SaaS Dienste unter einen Hut bringen? In 45 Minuten werden wir einen einen Überblick über diese Fragestellungen geben.
Splunk provides a unified data platform that can provide global visibility across multi-cloud environments. It collects and analyzes data from various sources, both on-premise and in public clouds, to help users address challenges like lack of visibility, cost control, cloud sizing and vendor lock-in, consistent security, and unknown future questions. Splunk offers features like apps/add-ons for faster time to value, machine learning tools, and a single platform to monitor all deployments. Case studies show how companies use Splunk to enable cloud migration, cost optimization, and security across hybrid infrastructures.
Splunk provides a unified data platform that can provide global visibility across multi-cloud environments. It collects and analyzes data from various sources, both on-premise and in public clouds, to help users address challenges like lack of visibility, cost control, cloud sizing and vendor lock-in, consistent security, and unknown future questions. Splunk offers features like apps/add-ons for faster time to value, machine learning tools, and a single platform to monitor all deployments. Case studies show how companies use Splunk to enable cloud migration, cost optimization, and security across hybrid infrastructures.
This document provides information about sponsor sessions at a NetApp conference in Berlin, including sessions hosted by Cisco, VMware, Brocade, and other sponsors. It summarizes the topics to be covered in each sponsor session, such as FlexPod solutions with Cisco UCS and ACI networking, deploying virtual desktops with Citrix and NetApp storage, and best practices for performance analysis and storage optimization.
CISCO’s Cloud Journey (Keynote at Cloud Symposium) Marcus McEwen
The following slide show details a high level analysis of Cisco’s view of The Cloud. This presentation was given by Kanjal Trevidi from Cisco Cloud and Managed Services Business Development at the Equivoice Cloud Symposium
Cisco has integrated its newly acquired Sourcefire technology into its product portfolio. It has added Sourcefire's Advanced Malware Protection (AMP) capabilities to its content security products. Most importantly, Cisco introduced the Cisco ASA with FirePOWER Services next-generation firewall that combines the ASA firewall with Sourcefire's Next-Generation IPS and AMP technologies. This new offering provides improved visibility into threats, enhanced threat prevention, and a consolidated security platform. While the integration brings benefits, a single management console and tighter integration with other Cisco infrastructure products is still needed.
All Together Now: Connected Analytics for the Internet of EverythingInside Analysis
The Briefing Room with Mark Madsen and Cisco
Live Webcast August 18, 2015
Watch the archive: https://bloorgroup.webex.com/bloorgroup/lsr.php?RCID=0eff120f8b2879b582b77f4ff207ee54
Today's digital enterprises are seeing an explosion of data at the edge. The Internet of Everything is fast approaching a critical mass that will demand a sea change in how companies process data. This new world of information is widely distributed, streaming, and overall becoming too big to move. Experts predict that within two to three years, the bulk of analytic processing will take place on the fringes of information architectures. As a result, forward-thinking companies are dramatically shifting their analytic strategies.
Register for this episode of The Briefing Room to hear veteran Analyst Mark Madsen of Third Nature explain how a new era of information architectures is now unfolding, paving the way to much more responsive and agile business models. He'll be briefed by Kim Macpherson of the Cisco Data and Analytics Business Unit, who will explain how her company's platform is uniquely suited for this new, federated analytic paradigm. She'll demonstrate how edge analytics can help companies address opportunities quickly and effectively.
Visit InsideAnalysis.com for more information.
Cisco and Splunk: Under the Hood of Cisco IT Breakout SessionSplunk
Cisco has a long-standing relationship with Splunk, using its software and services for IT operations, security analytics, and other purposes across its global data centers. Some key points:
- Cisco has used Splunk for over 7 years to monitor over 70 applications and aggregate data from various systems.
- Splunk helps Cisco improve IT operations by reducing issues by 50% and resolution times by 90%, and reducing operational costs by 80%.
- Cisco's security team uses Splunk to conduct investigations, detecting up to 2-3 million security events per day from various sources. This allows for faster investigations and automated tasks.
- Cisco designs and validates architectures for running Splunk on its Cisco UCS servers
Primend Praktiline Konverents - Rakenduse keskne IT infrastruktuur / Cisco Ap...Primend
Andmekeskuse virtualiseerumise ja konvergeerumise tulemusena on tekkinud keskkond, kus seadmete senised haldamise lahendused ja protseduurid ei ole piisavad käideldavuse ja konfidentsiaalsuse tagamiseks. Uue põlvkonna halduslahendused peavad hakkama saama salvestuse, arvutuse ja rakenduste mobiilsusega.
Cisco Connect Halifax 2018 Accelerating the secure digital business through...Cisco Canada
This document summarizes Cisco IT's evolution to accelerate the secure digital business through technology and culture. Cisco IT has transformed its architecture process, moving to a modular, cloud-native approach with automation, continuous delivery, and data-driven operations. It established an eStore platform and consumer-oriented experience to simplify service provisioning. Cisco IT also advanced a global cloud strategy and data center transformation for security, resiliency, speed and capacity. This cultural shift required moving to an agile, self-service model through innovations like ACI and embracing new ways of working like DevOps.
Operating costs decrease and agility increases, allowing you to react quickly to new market opportunities.
http://www.cisco.com/web/offers/sp04/simplifying-operations/index.html?KeyCode=000947566
It is very much likely that most people are aware of Cisco network equipment such as routers and switches and maybe IP telephony too. Few people might have heard that Cisco manufactures servers and even less might have used them, especially in Cyprus. Cisco has been in the server market since nearly 10 years ago though, it is rated among the top server manufacturers and is market leader in blade servers.
Presentation of Cisco UCS server platform during Simplex-Cisco Technology Session that took place at the Londa Hotel in Limassol on 14 March 2018.
CL2015 - Datacenter and Cloud Strategy and PlanningCisco
This document discusses strategies for data center and cloud transformation over the next 5 years. It outlines key digital business trends like data growth, cloud adoption, and security threats that are driving organizations' IT initiatives. These include managing increased data and applications, optimizing cloud strategies, addressing disruptive business models, and securing distributed data and applications. The document advocates adopting flexible consumption models, automation, and supporting edge/IoT applications. It positions Cisco as uniquely able to enable digital transformations through its portfolio of networking, compute, storage, automation, analytics, and security solutions.
computer organization and assembly language : its about types of programming language along with variable and array description..https://www.nfciet.edu.pk/
How iCode cybertech Helped Me Recover My Lost Fundsireneschmid345
I was devastated when I realized that I had fallen victim to an online fraud, losing a significant amount of money in the process. After countless hours of searching for a solution, I came across iCode cybertech. From the moment I reached out to their team, I felt a sense of hope that I can recommend iCode Cybertech enough for anyone who has faced similar challenges. Their commitment to helping clients and their exceptional service truly set them apart. Thank you, iCode cybertech, for turning my situation around!
[email protected]
By James Francis, CEO of Paradigm Asset Management
In the landscape of urban safety innovation, Mt. Vernon is emerging as a compelling case study for neighboring Westchester County cities. The municipality’s recently launched Public Safety Camera Program not only represents a significant advancement in community protection but also offers valuable insights for New Rochelle and White Plains as they consider their own safety infrastructure enhancements.
This comprehensive Data Science course is designed to equip learners with the essential skills and knowledge required to analyze, interpret, and visualize complex data. Covering both theoretical concepts and practical applications, the course introduces tools and techniques used in the data science field, such as Python programming, data wrangling, statistical analysis, machine learning, and data visualization.
Thingyan is now a global treasure! See how people around the world are search...Pixellion
We explored how the world searches for 'Thingyan' and 'သင်္ကြန်' and this year, it’s extra special. Thingyan is now officially recognized as a World Intangible Cultural Heritage by UNESCO! Dive into the trends and celebrate with us!
1. Cisco and Splunk
Innovation through the Power of Innovation
Douglas Hurd | Cisco Security Technical Alliances PM
Colin Lowenberg | Cisco Meraki Platform Partnerships PM
Karthik Karupasamy | Cisco UCS Technical Marketing Engineer
Robert Novak | Cisco Big Data Technical Solutions Architect
September 28, 2017 | Washington, DC
4. ▶ Splunk will run on almost anything (even my laptop)
▶ Standalone servers have lower admin overhead
▶ Build up your clusters and you have to keep them consistent
▶ Grow your data sources (and uses) and you have to add servers
▶ Cluster constipation is bad, mmmkay?
Why Does Hardware Still Matter?
4
5. ▶ Cisco customer big data pools tend to grow 2-3x/year
▶ Cisco customer IT staff doesn’t grow as fast
▶ The Cisco Unified Computing System (UCS) provides scalable, repeatable, predictable,
and manageable deployments across dozens to thousands of servers for any application
deployment
▶ Pallet to production in hours, not days or weeks
▶ Deep engineering integration between Cisco and Splunk with tested and proven
configurations
More on this later…
Why Does Hardware Still Matter?
5
6. ▶ 10s of thousands of employees, contractors, devices
▶ 100s of offices, business apps, audiences
▶ Lots of data in lots of places
▶ No one tool (not even Splunk) can do everything for everyone all the time
▶ High volume, low value, low shelf life
• Stealthwatch (formerly Lancope), Hadoop feed into Splunk
▶ Low to moderate volume, high value, (any) shelf life
• Splunk on its own, sometimes with fronting dashboards
▶ Additional visualizations with Platfora, Tableau, etc
Big Data at a Big Customer: Cisco
6
7. ▶ Customer for 8+ years, strategic
partner for 4+ years
▶ Geographically disparate data
collection and analysis
▶ Over 70 business
applications/use cases across
the company
• Around 20 teams using Splunk
including Cisco IT and CSIRT
▶ Nearly 10x growth in search
volume from 2014-2016
A closer look at Splunk within Cisco
7
8. 8
Dozens Of Apps And Add-ons At Splunkbase
Always more being added and
updated, by Cisco, Splunk,
partners, third party
developers, and end users!
9. Splunk and Cisco API-based Integrations
Programmable Operational Analytics at Scale
Security
Collaboration
Business Analytics
Infrastructure
Identity Services
(ISE/pxGrid)
FirePOWER Next
Gen Firewall
Umbrella (DNS)
CloudLock
ThreatGrid*
Cisco UCS
ACI / APIC
Call Manager
Spark
and many more here https://splunkbase.splunk.com/apps/#/search/Cisco/
Nexus 9k
Wireless / CMX
11. Splunk & Cisco Security – “Better Together”
• Largest security footprint in the industry
• Produces broad range of security telemetry
across most security technologies
• Ubiquitous network footprint enables bi-
directional integration for executing security
automation
• High investment in Splunk apps for serving
joint customers
• Voluminous, context-rich Cisco data sources
drive license volumes while enabling improved
security & compliance, more effective SIEM
use cases and new use cases beyond security
• Automated actions in Cisco network environs
• Proven, supported integrations accelerate time
to value
Security Breadth, Customer Reach,
Infrastructure for Automation
Analytics Efficacy, Ability to
Automate, Committed Customers
12. 12
Cisco Splunk Integrations
ü CVD: Cisco UCS Integrated Infrastructure for Splunk Enterprise
(Distributed Deployment, High Capacity) (link)
ü CVD: Cisco Application Centric Infrastructure with Splunk (link)
ü Splunk on UCS Reference Architecture (link)
ü Cisco Cloud Security for VMDC 1.0 Design Guide (link)
Security
IPS
Identity Services Engine/pxGrid
FireSIGHT (including AMP)
ASA/PIX/FWSM Firewalls
Web Security Appliance (WSA)
Email Security Appliance (ESA)
Stealthwatch
Umbrella Investigate
Cloud Web Security (CWS)
AnyConnect
CloudLock
ThreatGrid
Data Center / ACI
Cisco UCS
UCS Director Express for Big Data
Application Centric Infrastructure
(ACI - APIC)
Nexus 9K
Tetration (planned)
Enterprise Networking
Nexus and Catalyst Switches
Nexus 1000V
NGN Routers (CRS, ASR, ISR)
Meraki Wireless
Open SDN
Network Controller
CMX Wireless
Network Data Platform (planned)
Collaboration
Call Manager
Spark
AppDynamics
ü Inaugural SIEM & Threat Defense Partner
ü Inaugural pxGrid partner
ü Inaugural member of Cisco Security Tech Alliances program
ü Inaugural ACI Partner
ü Inaugural Data Analytics Partner
Cisco
Security
Suite
App
Cisco
Networks
App
16. Threat Defense Security
DURING
Detect
Block
Defend
AFTER
Scope
Contain
Remediate
BEFORE
Discover
Enforce
Harden
Unified Threat Management
FirePOWER Services
FirePOWER Appliances
Secure Access & Identity
Next Generation Firewall Next Generation IPS
Email Security
Web Security
Advanced Malware Protection
Sandboxing & Threat Analysis
Network Anomaly Detection
FirePOWER Services
FirePOWER Appliances
AMP for Endpoints
AMP for Networks
Meraki Appliances Wired & Wi-Fi
Meraki Cloud Management
Email Security Appliance
Cloud Email Security
AMP ThreatGRID Cloud & Appliance
OpenDNS Investigate
Identity Services Engine (ISE)
TrustSec, AnyConnect VPN
OpenDNS Umbrella
Cloud Web Security, Web Security
Appliance
CloudLock
StealthWatch
Cognitive Threat Analytics
Threat Intelligence
17. ▶ Firepower-Splunk mutual customer base expanding
• ASA to Firepower Threat Defense – More FMCs
▶ Add-Ons for Firepower available on Splunkbase
▶ Cisco’s Firepower TA & App built in 2014, based on v.5.4
• Over 6000 downloads
• Not recommended with FMC V6.x
▶ ‘Community Supported’ model facing challenges
▶ Focused on new business model for this critical integration
▶ Resources directed at Firepower 6.x customers
Background on Firepower and Splunk
18. ▶ Firepower-Splunk mutual customer base
expanding
• ASA to Firepower Threat Defense – More
FMCs
▶ Add-Ons for Firepower available on
Splunkbase
▶ Cisco’s Firepower TA & App built in
2014, based on v.5.4
• Over 6000 downloads
• Not recommended with FMC V6.x
▶ ‘Community Supported’ model facing
challenges
▶ Focused on new business model for this
critical integration
▶ Resources directed at Firepower 6.x
customers
Background on Firepower and Splunk
19. Data Consumption – Eat In or Delivery?
Expectations and User Roles are Changing
21. ▶ Scalable app with major improvements
▶ TAC Support option will be offered
• Free for customers that do not want TAC support
• Chargeable for customers that want TAC support
▶ Official GA Release: End of June
▶ Beta II underway during May thru June 2017
▶ PID: FP-SPLUNK-SW-K9
▶ Description: “Cisco eStreamer eNcore for Splunk
• Software downloads: software.cisco.com
New Cisco eStreamer ‘eNcore’ for Splunk
Free Version
Pay Version
App Cost Free $$$
Community
Support
Yes Yes
TAC Support
No Yes
App Updates Yes Yes
22. Improvements and Enhancements
Feature Benefit
Built from scratch in Python • No Perl dependencies
• Python very popular
• Completely up to date with entire 6.2 API schema
Multi-process • Highly scalable
Multi-FMC Support • Connect multiple FMCs to one instance
• Reduce complexity
Fully Qualified Event Output • Encoded event info is written out in text
Event de-duplication (Future) • Avoid paying Splunk for redundant event data
• Gives Firepower HA configurations more flexibility
TAC Supported option available • End to End support for Firepower Splunk customers
Forward Compatible • Ongoing maintenance to support new eStreamer API
versions
25. Branch office
Cisco Cloud Security
Umbrella
Secure access to the internet
Cloudlock
Secure usage of cloud apps
Investigate
Threat Intelligence
HQ Roaming
26. API
Automatically enrich security alerts
inside Splunk, allowing analysts to
discover the connections between the
domains, IPs, and file hashes in an
attacker’s infrastructure.
domains, IPs, ASNs, file hashes
Splunk Add-on for Cisco Umbrella Investigate
INVESTIGATE
27. ▶ Manage Cloud Security incidents
within Splunk
▶ Seamless extend Security
Operations to cloud environments
while maintaining existing
workflows
▶ Leverage Splunk’s rich data
visualization, alerting and
reporting functionality
▶ Two leaders - Partnership
Strength
Splunk App for Cisco Cloudlock
28. ShadowIT for Cisco FP and Splunk Customers
CLOUDLOCK
SHADOW IT
ENGINE
Cisco Web Security
Cisco NGFW
FirePOWER
3rd party Security
Appliances
SIEM:
29. Correlating Network
And Infrastructure
Data Around The
World
Using open APIs monitor and manage connectivity and
security for the largest Latin American country
Colin Lowenberg
31. ▶ Managed WiFi in all Mexican Gov’t buildings: libraries,
health centers, community buildings, etc.
▶ Indoor and outdoor APs for gov’t and public use
▶ 22K+ sites across Mexico
Cisco Meraki + Splunk
México Conectado connects all Mexican government buildings using Meraki
33. Your Splunk
Environment:
Better on Cisco UCS
Automate deployment, correlate with your entire
datacenter, and optimize for management and scalability
With Karthik Karupasamy
35. ▶ Splunk-built rewrite of original UCS add-on
▶ Aggregates, monitors, trends and analyzes
all relevant data from Cisco UCS Manager
instances
▶ Enables proactive capacity and performance
monitoring/ management, fault trending,
power and cooling, and more
▶ Works with other Splunk add-ons and data
sources (including Enterprise Security and
PCI Compliance add-ons) to aggregate and
correlate data across your enterprise
Splunk Add-On for Cisco UCS
35
Application
s
Operating Systems
Hypervisors
UCS server,
storage,
network
37. Cisco Unified Computing System
Unified
Management
▶ Faster deploy/
provision
▶ Unification leads to
reduced complexity
▶ Management via a
single interface
Simplified
Architecture
▶ Networking with fewer
components
▶ Lower cost and easier
scaling
▶ Fewer management
touch points
▶ Stateless: any
resource, any time
▶ Better TCO/ROI
Scale
▶ Ultimate Scalability
Enhanced design
capability
▶ Designed for the future,
today
Higher
Performance
▶ Brings out the best of
x86 architecture
▶ Optimized resource
utilization for
compute, networking,
and management
A differentiated, revolutionary approach
38. SingleConnect: LAN,
SAN and Management
UCS 6200 and 6300 Series Fabric
Internments,
Installed in pairs, active-active.
UCS Manager is embedded
Pre-tested and pre-validated
configuration
Fabric-based infrastructure integrates
computing, networking, and storage
resources
Designed for high performance and
availability
Cisco UCS Integrated Infrastructure for
Big Data Topology
Provisioning
Monitoring
Maintenance
Growth
Support for direct
connectivity to Fabric
Interconnects
40. Features:
▶ Complete automation of industry-leading validated solution for Splunk Enterprise
▶ Indexer clustering – customizable Replication and Search Factors
▶ Search Head clustering
▶ Shared License Master, Deployer for SHC
▶ Ability to grow the Search head, Indexer clusters.
▶ Monitoring console
UCS Director Express for Big Data
Deploy your Splunk Enterprise Cluster in hours – not in days or weeks
41. UCSD Express For Big Data – Two Ways to Create
Unified Management Platform for Highly Available Distributed Splunk Clusters
Use
Bundled
Templates
(Instant)
Create
your
Custom
Template
Select
Size
Splunk
Version
OS
IP
Address
Binding
Ready-to-
Use
Splunk
Cluster
42. Instant Splunk Cluster Under One Management
Decisions
Insights
Marketing LOB
Shadow IT for Big
Data
Supply Chain
LOB
IT Team
Marketing
Splunk Cluster
Supply Chain
Splunk Cluster
Sales Splunk
Cluster
Decisions
Insights
Sales LOB
• Faster Turnaround Time
• No Shadow IT team
• No Growing Pains
• Scalable performance and Enterprise
Grade system
• Unified Data Center Management
• Optimal Resource Utilization
• Simplified Compliance and
Governance
UCSD Express
43. UCSD Express
UCS 6200/6300 Series
Fabric Interconnect
UCS Manager
UCS C220/C240 M4/M5
Series Rack Servers
UCS S3260 Storage
Server
Cisco UCS
Service Profile
NIC MACs
HBA WWNs
Server UUID
VLAN Assignments
VLAN Tagging
FC Fabrics
Assignments
FC Boot
Parameters
Number of vNICs
Boot order
PXE settings
IPMI Settings
Number of vHBAs
QoS
Call Home
Template
Association
Org & Sub Org
Assoc.
Server Pool
Association
Statistic
Thresholds
BIOS scrub actions
Disk scrub actions
BIOS firmware
Adapter firmware
BMC firmware
RAID settings
Advanced NIC
settings
Serial over LAN
settings
BIOS Settings
Splunk Enterprise
Unified Management with UCS Director Express for Big Data
Programmability, Scalability and Automation
44. • Industry leading tool to provision, manage and monitor all software and hardware
components
• Policy and model-based management, with service profiles, that improves agility
and reduces risk
• Utilizes auto-discovery to detect, inventory, manage, and provision system components
• Offers a comprehensive open XML API, which facilitates integration with third-party
management tools
UCS
Manager
• Manages multiple, globally distributed Cisco UCS domains with thousands of
servers from a single pane
• Provides global configuration capabilities for pools, policies, and firmware
UCS
Central
Management
UCS
Director
• Delivers a unified converged infrastructure management solution
• Provides programmable application containers across computing, networking, and
storage resources and extend automation benefits to the entire infrastructure stack
UCS Director
Express for
Big Data
• Delivers scalable and reliable Hadoop deployment on UCS Big Data clusters
• Offers centralized visibility across Hadoop and physical infrastructure
• Provides greater IT agility resulting in increased IT impact on business
Abstraction of all configuration and identity information into a service profile speeds deployment, reduces
errors, lowers costs
Programmable Infrastructure
Policy based Management
UCS Management Software provides:
Provisioning
Monitoring
Maintenance
Growth
Speed
Ease of
experimentation
Consistency Simplicity Visibility
45. UCS Director Express for Big Data
End-to-end provisioning, deployment and management
4
Associate Hadoop and
Infrastructure Profiles to
create Hadoop Clusters
3 Service Profile Templates
Create Service Profiles
2
Policies Used to Create
Hadoop and Infrastructure
Service Profile Templates
Network
SME
Namenode, data node configuration
Configure Hadoop services
Setup heap size and memory buffers
HDFS, MapReduce configuration
Setup other Hadoop services
Uplink and server port configuration
Network interface card (NIC)
configuration: MAC address, VLAN,
and QoS settings; worldwide names
(WWNs), and bandwidth constraints;
and firmware revisions
Unique user ID (UUID), firmware
revisions, and RAID controller settings
Service profile assigned to server,
chassis slot, or pool
1 Subject Matter Expert
Define Policies
Create Infrastructure
Profile
Create Hadoop Profile
Create Hadoop
Application Profile
Server
SME
Storage
SME
Hadoop
SME
47. Splunk Cluster customizations
Optionally add another NIC for Replication Traffic
Select custom RAID policy for each Role Customize Storage Tiers
Select physical infrastructure options
48. Creating a Splunk cluster
▶ Cluster Name
▶ OS (RHEL)
▶ Splunk version
▶ UCS Manager
▶ Organization
49. Creating a Splunk Cluster
▶ Server-pools (per role)
▶ Map vNIC to IP-Pools.
• Mgmt, (and ingest)
• Data1 for Replication
(optional),
▶ Click Submit
PXE VLAN
Replication
Factor,
Search
Factor
Server
Pools
Networking
50. Creating a Splunk Cluster -- Server Pool Selection
Server
Pools
Server
Count
Hostname
Prefix
51. Creating a Splunk Cluster -- VNIC configuration
▶ Map vNIC to IP-Pools.
NOTE: eth0 à MGMT pool binding shown.
▶ Click Submit
52. ▶ Splunk Cluster is powered by Underlying UCS HW Template
▶ Splunk’s UCS HW Template comes with Flexible RAID Policy
▶ RAID Policies Supported:
• RAID1, RAID0
• RAID5, RAID6
• RAID10 (default)
• Future (RAID50, RAID60)
▶ Separate RAID policies for HOT/WARM, COLD and Frozen
Flexible RAID config via UCS HW Profiles
58. ACI app center
Aci-splunk: What Is New?
Cisco ACI App & Add-on for Splunk Enterprise version 4.0 – Splunk Certified
Multi-Pod
visibility
Micro-Segmentation
support
Multiple APIC
monitoring
Enhanced user interface with
drill down capabilities
ACI App Center
integration
Supported on APIC 1.3 and higher Compatible with Splunk 6.4 & above
Available on splunkbase
59. Cisco Tetration App & Add-on for Splunk Enterprise version 1.0
Central Proactive
Monitoring
Operational
Analytics
Cross tier
Visibility
Real-time Application
Monitoring
Accelerated RCA & deeper visibility Policy Enforcement
Tetration App for
Splunk V1.0
Cisco Tetration
Analytics
Use Tetration APIs to receive ADM,
Endpoints, Inventory data
Send Configuration data, health & performance
metrics, syslog and fault information
Enforce policies using Tetration sensors
Tetration Analytics App for Splunk
60. Why You Never See
Tacos Mounted On
Drones In The Real
World
Wrapping up the Cisco and Splunk innovation story
With Robert Novak
63. Cisco Technology Description SplunkBase URL
Cisco Security Suite The Cisco Security Suite provides a single pane of glass interface into Cisco security data. https://splunkbase.splunk.com/app/525/
Cisco Firepower™
Management Center
Splunk Add-on for Cisco FirePower Management Center leverages data collected via Cisco eStreamer to
allow a Splunk Admin to analyze and correlate reports from Cisco through the Splunk Common
Information Model.
https://splunkbase.splunk.com/app/1808
Cisco eNcore for Splunk
Comprehensive eStreamer ‘Client’ or Splunk ‘TA’ that collects all ten event types in their entirety from
Firepower Management Center 6.x
https://splunkbase.splunk.com/app/3662/
Cisco Umbrella
Automatically enrich security alerts inside Splunk, allowing analysts to discover the connections between
the domains, IPs, and file hashes in an attacker’s infrastructure
https://splunkbase.splunk.com/app/3324/
Cisco ISE
Splunk App for Cisco ISE. Collects data from ISE via Syslog and provides Adaptive Network Control
(ANC) Mitigation Actions via pxGrid.
https://splunkbase.splunk.com/app/1589/
https://splunkbase.splunk.com/app/1915/
Cisco CloudLock
The CloudLock Cloud Access Security Broker harnesses crowd-sourced, actionable cybersecurity
intelligence to enable enterprises to securely leverage the cloud.
https://splunkbase.splunk.com/app/3043/
https://www.cloudlock.com/blog/tag/cloudlock-
for-splunk/
Cisco eStreamer
eStreamer log collection and comprehensive selection of dashboards optimized for Sourcefire System
5.2+ and Splunk 6.
https://splunkbase.splunk.com/app/1629/
Cisco IPS
The Splunk Add-on for Cisco IPS allows a Splunk software administrator to consume, analyze, and
report on Cisco IPS data that conforms to the Security Device Event Exchange (SDEE) standard.
https://splunkbase.splunk.com/app/1903
Cisco CWS
The Cisco Cloud Web Security (CWS) Add-on for Splunk allows a Splunk administrator to analyze and
correlate Cisco Cloud Web Security (CWS) log data through the Common Information Model in Splunk
Enterprise
https://splunkbase.splunk.com/app/2791
Cisco ESA
The Splunk Add-on for Cisco ESA allows a the Splunk software administrator to leverage Textmail,
HTTP, and Authentication logs of Cisco ESA.
https://splunkbase.splunk.com/app/1761
Cisco AnyConnect
The Cisco AnyConnect Network Visibility (NVM) App for Splunk
allows IT administrators to analyze and correlate user and endpoint behavior in Splunk Enterprise.
https://splunkbase.splunk.com/app/2992/
Cisco ASA
The Splunk Add-on for Cisco ASA allows a Splunk software administrator to map Cisco ASA devices,
Cisco PIX, and Cisco FWSM events to the Splunk CIM.
https://splunkbase.splunk.com/app/1620