At Splunk .conf24, Bruce Johnson from TekStream shared details about security practices and tight Splunk integration. There was also a mention of a Splunk tattoo somewhere along the way.
Transcript
Auto-generated captions, lightly cleaned. Speakers are not separately labeled.
hey everyone we’re out here at dotom 24 and I’m talking to Bruce from Tech stream and you guys have won multiple Awards multiple years in a row what makes you such a awesome Splunk partner we’re deeply embedded yeah we have the tattoo we’ve joined the cult um we take the full gamut of Splunk technology and leverage it to its best Advantage uh we’re not uh we’re building to the extent that we’re building solution or IP on top of that um we are not necessarily compromising the ability to sell product um in the IP that we develop and our Solutions are very much uh investment focused as opposed to kind of the proprietary outsourced model so our customers where we have them own the license and we build our IP on top of that platform instead of so when for instance we’re Outsourcing we do MSP Outsourcing uh MDR Outsourcing and in that context then as an investment model they get rid of us they keep what they’ve built right and so every other MDR provider out there when you tear them out runs with everything that they own and you start over right got so it’s a much deeper investment let’s say in uh in a Splunk future yeah yeah and so some of this uh IP that you built uh where has that made a really big impact in one of your customers well uh great question uh for us a lot of what we’re focused on now uh especially in security space because I kind of run the security uh group on delivery side um a lot of that is focused on multi- agency multi-institutional types of environments so um we’ve built a lot of Ip to do propagation of assets across uh disparate multi- uh instance environments and so I know that’s a focus going forward with blunk um we’ve kind of had to craft a lot of that ourselves meaning uh we share incident awareness across all of our customers all the member institutions in a jck in an enclave and so we’re not just doing ioc’s we’re sharing the context for any given threat that’s uncovered M act metadata and all the kind of what users and so forth and so we’re able to propagate uh assets into all of those member institutions so not only are we really sharing thread awareness across institutions using a mom model but we’re then pushing searches up to do iterative kind of coordinated incident response so we have a breakout a log for J for instance we look for long URL strings we pull all of that Telemetry data back we put the you know do successive searches to figure out where the user is do pitting look at the host how deep have they gotten how broad and then we can on a coordinated level do incident response across an entire Enclave so it’s uh it’s paying off a lot for us in the kind of the student Le or student powered socks that we use um and that’s a lot of you know we’re doing a lot of sled work but it also has an applicability in the commercial space so that that’s kind of what we’re what we’re focused on right now obviously we cover the full stack though the full gamut of observability and itsi and pretty much all of the other products we’ve got a Cisco partnership so we’re working with some of the major Cisco Partners to enable them you know they’re realizing that it takes a year to build a a spunk practice so we’re helping to bridge that gap for a lot of like wwt and and presidia and those guys fantastic so lot of great information broad set of capabilities that you have where do I go to get some more information uh tech stream.com tech stream.com Kream yeah that’s right all right thanks BR for your time and thanks for the information