Splunk Inc. announced new security innovations aimed at bolstering threat detection and security operations across multiple data sources. These advancements include Splunk Enterprise 8.0, which empowers security teams to proactively manage and mitigate risks effectively, and a new Federated Analytics feature, which analyzes data directly where it?s stored for threat hunting and frequent threat detection. As organizations face increasingly sophisticated security challenges, a unified threat detection, investigation, and response (TDIR) solution is crucial to power the Security Operations Center (SOC) of the future.

Splunk?s latest offerings address this need by fortifying foundational elements, delivering comprehensive security visibility, accurate threat detection, and streamlined workflows for rapid response, ultimately saving time with cost-effective solutions. Splunk Enterprise Security 8.0: Streamlining Threat Detection and Response Now with Mission Control natively integrated, Splunk Enterprise Security 8.0 simplifies how security analysts detect, investigate and respond to threats from one modern interface for additional operational efficiency and speed. With standardized terminology and unified automation via Splunk SOAR, Splunk Enterprise Security 8.0 expedites alert triage and investigations, enhancing detection with advanced analytics.

As a result, security analysts can leverage streamlined workflows, faster responses and improved productivity. With the new enhancements in Splunk Enterprise Security 8.0, security teams can: Leverage a seamless workflow experience: Splunk Enterprise Security 8.0 offers a unified work surface and response plans to help customers identify, assess and respond to threats. Drive more efficient investigations: One click, modern aggregation and triage capabilities to automatically aggregate findings based on preset criteria for a comprehensive view of critical insights.

Save time by focusing on critical incidents: Enhanced detection delivers turnkey capabilities to understand and implement a risk-based alerting strategy, generating high-confidence aggregated alerts for investigations. Communicate more effectively and take rapid action: Clear, concise terms that align to each phase of a security workflow within Splunk Enterprise Security 8.0. Federated Analytics: Empowering Data Analysis Across Splunk and External Data Sources, Beginning With Amazon Security Lake Splunk's Federated Analytics feature, available in private preview on Splunk Cloud Platform and cloud deployments of Splunk Enterprise Security, introduces a new approach to data analysis. This solution enables customers to analyze data directly where it resides, beginning with Amazon Security Lake, a service that automatically centralizes an organization?s security data from across their Amazon Web Services (AWS) environments, leading SaaS providers, on-premises environments, and cloud sources into a purpose-built data lake, for threat hunting and bringing specific data into Splunk for frequent threat detection.

By seamlessly integrating with Amazon Security Lake, Federated Analytics empowers organizations to efficiently detect and investigate security incidents without the need to relocate data. This capability ensures swift, context-rich data analysis and enhances operational agility, setting the stage for future expansions to additional data platforms. With Federated Analytics, security teams can: Analyze data wherever it resides: Ensure timely access to and analysis of data across storage locations, maintaining data integrity and reducing latency. Unify security visibility across your data: Integrate and analyze data from Splunk and Amazon Security Lake with a seamless analyst experience, providing a holistic view of security data, and reducing costs and logistical complexities.

Increase efficiency and cost-effectiveness: Optimize operational costs through smart data management strategies such as data tiering and selective data ingest, significantly lowering expenses associated with data management. Enhancing Security Defense: Cisco Talos Integration with Splunk Security Products Following Cisco?s acquisition of Splunk, security teams will be able to harness the power of Cisco Talos threat intelligence across Splunk Attack Analyzer, Splunk Enterprise Security and Splunk SOAR for enhanced defense against known and emerging threats. Cisco Talos is one of the most trusted threat intelligence teams in the world, composed of world-class researchers, analysts, incident responders and engineers.

Leveraging Talos? extensive intelligence network, Splunk customers can streamline threat detection and response processes, reducing alert fatigue and allowing security analysts to focus on critical threats. This enables quick identification and prioritization of real threats with global real-time outbreaks, contextual insights and advanced correlations.

The technical integration of Talos real-time intelligence is underway across Splunk?s portfolio, including Splunk Enterprise Security, Splunk SOAR and Splunk Attack Analyzer.