Splunk Enterprise Security Premier recently became Generally Available which simplifies analysts workflows, introduces new AI capabilities, and helps with speed and efficiency. While at RSAC, I had a chance to chat with Dan Christiansen, CISSP about what’s new and actionable today. Dan shares the expanded functionality and AI capabilities in the video below.
Transcript
Auto-generated captions, lightly cleaned. Speakers are not separately labeled.
Hey everybody, we’re out here at RSA and I ran into Dan and you’ve been telling me about ES Premiere and all the cool things that are coming up in there. Can you give us some more information about that? >> Sure, absolutely. So, you might be familiar with enterprise security, which is our world-class SIM that Splunk has, but ES Premiere kind of takes it to the next level. Imagine not having to be, you know, constrained by how many licenses you need for SOAR, how many licenses you need for UEBA. ES Premiere allows you to have unlimited SOAR licenses, unlimited user behavior, you know, user behavior analytics licenses, our UEBA product, which allows you to look for more advanced threats. So, use this unsupervised machine learning to be able to detect anomalous events, find users and devices that are, you know, in the network that are exhibiting anomalous behavior. And then also we have a full threat intel framework as well that’s fully baked in as well. Now, ES Premiere is a gift that keeps on giving. It allows you to be able to have additional products that get added at no cost to our customers in the future. So, not only do they get, you know, the the world-class SIM today, but they get additional products down the road that continue to increase the amount of value they get out of the product as well. So, that’s really exciting. It’s been shipping, it’s been, you know, GA now for it since late last year. Our customers are loving it and we have a lot of customers who are upgrading their existing infrastructure from Splunk Cloud and on-prem to ES Premiere right now. >> Now, we’re out here at the RSA conference and everything is AI. And now we were talking earlier about some of the AI improvements in the AI. Can you give us some information about what we’re doing there? >> Absolutely. So, Splunk, you know, we have put a lot of time and effort into creating the best of the best from the AI perspective. So, we have agents like the AI agent for security. It can do a number of things. One, it can write SPL for you. So, if you’re not familiar with how to write Splunk SPL, you just type in natural spoken language, “Hey, show me all my indicators coming from China or give me the all the research I have on this IP address historically for the last year.” It’ll go out and it’ll find that for you and write that search for you. On the opposite way, you can take a search, paste it in, and it’ll actually do line by line documentation for you. In addition, it can summarize investigations. It can go out as a co-pilot and go out and find things for you. So, “Take this hash that I found, go find any other remnants of it that are in my endpoint logs or in my email, and see if there’s any attachments.” And it’ll go out and do those things for you. >> That’s really amazing. A lot of advancements and bundling we’re doing there now. If I want to go get some more information about all of this stuff, where can I go find that? >> Absolutely. So, out on splunk.com, we have a whole security section. There’s going to be click-throughs and walk-throughs that you can look at, and it’ll also have a little bit of information about our SIM, our Enterprise Security Premier, all the things that are included into it as well. >> That’s really amazing. Appreciate the information. Thank you. Pleasure. >> Thank you.