SlideShare a Scribd company logo
7
Most read
8
Most read
Copyright © 2014 Splunk Inc.
Justin Dolly
CISO
ServiceNow
ServiceNow + Splunk Integration
2
ServiceNow Overview
ServiceNow is the enterprise IT cloud company. We transform IT by automating and
managing IT across the global enterprise. Organizations deploy our service to create a
single system of record for IT and automate manual tasks, standardize processes, and
consolidate legacy systems. Using our extensible platform, our customers create custom
applications and evolve the IT service model to service domains inside and outside the
enterprise
Founded in 2004
IPO in June 2012
2300+ customers
2100+ employees
2013= $470m revenue
3
ServiceNow Overview
Single system of record for IT
Single Cloud Platform
Robust Suite of IT Applications
Custom Application Development
Enterprise Cloud Infrastructure
Lights-out, zero-touch automation
Powerful Business Intelligence Reporting
Accelerate time-to-value
4
My Background and Role
Justin Dolly, VP & CISO at ServiceNow
Former CISO at VMware
Previously held security and technology leadership roles at
– Kaiser Permanente,
– CNET Networks / CBS Interactive,
– Macromedia
– Wells Fargo Bank
5
Security Challenges
Most Security teams now have budget, staff & tools
Having many tools can be cumbersome & inefficient
Security teams typically work in a Silo
Our Situation, a year ago:
Log Analytics and Service Management were disparate systems
Need threat identification and event correlation
Information is there, but it’s difficult to access
Needed to address compliance and audit reporting needs
6
Splunk @ ServiceNow Today
Collecting over 400GB/ day and growing
Enterprise Security is our SIEM collecting threat intelligence data and
providing actionable results
‘Single pane of glass’ view across enterprise for threat identification and
event correlation
Splunk alerts trigger script actions which push events into ServiceNow
via SOAP and XML
Events are analyzed by a dedicated Security Operations team
7
Splunk @ ServiceNow Today
Syslog Events
• Network
• Firewall
• F5 LTM/ASM
• Wireless IDS Syslog Store and Forward
Splunk Indexers SplunkES
Search Head
Splunk
Search Head
ServiceNow Security Instance
Event Console
8
Integration Overview
Custom built integration using the Splunk REST APIs and ServiceNow APIs
Splunk is periodically queried for security related events
Script actions push event data into ServiceNow instance events table
Business rules extract unique identifiers from the events table for de-
duplication and correlation
Security analyst reviews events in the ServiceNow console and elevates events
to incidents for investigation
New event data received is automatically associated to open incidents
Open incidents drive response activities and workflow across the organization
9
What’s Next
We continue to grow quickly
Big Data analytics also grows in importance
Leveraging the new Splunk integration with ServiceNow Event
Management Console (newly released in Eureka)
Integration with ServiceNow Threat Intelligence Portal
10
Top Takeaways
Embrace the mind-shift in Security
– Re-think the relationship between your systems, processes, and people
– The traditional tools won’t save you
Technology when done right is extremely liberating
– Applying threat intelligence and real-time analytics makes response activity faster
& more accurate
The only metric that matters is how quickly you respond to a security
event
– Don’t chase the information, let it come to you

More Related Content

PPTX
Splunk Architecture
Kishore Chaganti
 
PPTX
Do You Really Need to Evolve From Monitoring to Observability?
Splunk
 
PPTX
Splunk Enterprise Security
Splunk
 
PDF
Solution deck capgemini cloud assessment
Adobe
 
PDF
Observability at Scale
Knoldus Inc.
 
PPTX
Getting Started with Splunk (Hands-On)
Splunk
 
PPTX
Composale DXP with MACH architecture.pptx
Pieter Brinkman
 
PPTX
Monetizing Big Data at Telecom Service Providers
DataWorks Summit
 
Splunk Architecture
Kishore Chaganti
 
Do You Really Need to Evolve From Monitoring to Observability?
Splunk
 
Splunk Enterprise Security
Splunk
 
Solution deck capgemini cloud assessment
Adobe
 
Observability at Scale
Knoldus Inc.
 
Getting Started with Splunk (Hands-On)
Splunk
 
Composale DXP with MACH architecture.pptx
Pieter Brinkman
 
Monetizing Big Data at Telecom Service Providers
DataWorks Summit
 

What's hot (20)

PDF
Splunk 101
Splunk
 
PPTX
Splunk Cloud
Splunk
 
PDF
Travel & Leisure Platform Department's tech info
Rakuten Group, Inc.
 
PPTX
Snowflake Overview
Snowflake Computing
 
PPTX
Splunk Architecture overview
Alex Fok
 
PDF
SOC, Amore Mio! | Security Webinar
Splunk
 
PDF
Splunk-Presentation
PrasadThorat23
 
PPTX
.conf Go 2022 - Observability Session
Splunk
 
PDF
Network Observability: Delivering Actionable Insights to Network Operations
Enterprise Management Associates
 
PPTX
7 Steps to Build a SOC with Limited Resources
LogRhythm
 
PDF
apidays LIVE Australia 2021 - Composing a Headless and Composable Commerce Ar...
apidays
 
PDF
Elastic SIEM (Endpoint Security)
Kangaroot
 
PDF
Inside Kafka Streams—Monitoring Comcast’s Outside Plant
confluent
 
PDF
Observability & Datadog
JamesAnderson599331
 
PDF
Observability
Ebru Cucen Çüçen
 
PDF
Platform of platforms slide
AlessandraAmorim34
 
PPTX
Splunk Overview
Splunk
 
PPTX
Nutanix
Murugesan Arumugam
 
PPTX
Getting started with Splunk - Break out Session
Georg Knon
 
PPTX
Observability
Enes Altınok
 
Splunk 101
Splunk
 
Splunk Cloud
Splunk
 
Travel & Leisure Platform Department's tech info
Rakuten Group, Inc.
 
Snowflake Overview
Snowflake Computing
 
Splunk Architecture overview
Alex Fok
 
SOC, Amore Mio! | Security Webinar
Splunk
 
Splunk-Presentation
PrasadThorat23
 
.conf Go 2022 - Observability Session
Splunk
 
Network Observability: Delivering Actionable Insights to Network Operations
Enterprise Management Associates
 
7 Steps to Build a SOC with Limited Resources
LogRhythm
 
apidays LIVE Australia 2021 - Composing a Headless and Composable Commerce Ar...
apidays
 
Elastic SIEM (Endpoint Security)
Kangaroot
 
Inside Kafka Streams—Monitoring Comcast’s Outside Plant
confluent
 
Observability & Datadog
JamesAnderson599331
 
Observability
Ebru Cucen Çüçen
 
Platform of platforms slide
AlessandraAmorim34
 
Splunk Overview
Splunk
 
Getting started with Splunk - Break out Session
Georg Knon
 
Observability
Enes Altınok
 
Ad

Viewers also liked (20)

PPTX
SplunkLive! London 2017 - Using Machine Learning to Feed Hungry People
Splunk
 
PPTX
Cisco and Splunk: Under the Hood of Cisco IT Breakout Session
Splunk
 
PDF
Splunk at Scotiabank
Splunk
 
PPTX
Splunk Partner+ Program - Partner Marketing e-Learning - France August 2017
Splunk
 
PPTX
SplunkLive! Customer Presentation - Cisco Systems, Inc.
Splunk
 
PPTX
Splunk Ninjas: New Features and Search Dojo
Splunk
 
PPTX
SplunkLive! London 2017 - Building an Analytics Driven Security Operation Cen...
Splunk
 
PPTX
SplunkLive! London 2017 - How to Earn a Seat and the Business Table with Splunk
Splunk
 
PPTX
SplunkLive! Milano 2016 - customer presentation - Unicredit
Splunk
 
PPTX
Danfoss - Splunk for Vulnerability Management
Splunk
 
PDF
Splunk Forum Financial Services Chicago 9/13/17
Splunk
 
PDF
Reactive to Proactive: Intelligent Troubleshooting and Monitoring with Splunk
Splunk
 
PPTX
Using Splunk at MoneyGram International
Splunk
 
PPTX
Splunk for Enterprise Security featuring User Behavior Analytics
Splunk
 
PPTX
Splunk Forum Frankfurt - 15th Nov 2017 - .conf2017 Update
Splunk
 
PPTX
Splunk Forum Frankfurt - 15th Nov 2017 - Building SOC with Splunk
Splunk
 
PPTX
Rage WITH the machine, not against it: Machine learning for Event Management
Splunk
 
PPTX
Splunk Forum Frankfurt - 15th Nov 2017 - GDPR / EU-DSGVO
Splunk
 
PPTX
Splunk Forum Frankfurt - 15th Nov 2017 - Machine Learning For Event Management
Splunk
 
PPTX
Splunk Forum Frankfurt - 15th Nov 2017 - Threat Hunting
Splunk
 
SplunkLive! London 2017 - Using Machine Learning to Feed Hungry People
Splunk
 
Cisco and Splunk: Under the Hood of Cisco IT Breakout Session
Splunk
 
Splunk at Scotiabank
Splunk
 
Splunk Partner+ Program - Partner Marketing e-Learning - France August 2017
Splunk
 
SplunkLive! Customer Presentation - Cisco Systems, Inc.
Splunk
 
Splunk Ninjas: New Features and Search Dojo
Splunk
 
SplunkLive! London 2017 - Building an Analytics Driven Security Operation Cen...
Splunk
 
SplunkLive! London 2017 - How to Earn a Seat and the Business Table with Splunk
Splunk
 
SplunkLive! Milano 2016 - customer presentation - Unicredit
Splunk
 
Danfoss - Splunk for Vulnerability Management
Splunk
 
Splunk Forum Financial Services Chicago 9/13/17
Splunk
 
Reactive to Proactive: Intelligent Troubleshooting and Monitoring with Splunk
Splunk
 
Using Splunk at MoneyGram International
Splunk
 
Splunk for Enterprise Security featuring User Behavior Analytics
Splunk
 
Splunk Forum Frankfurt - 15th Nov 2017 - .conf2017 Update
Splunk
 
Splunk Forum Frankfurt - 15th Nov 2017 - Building SOC with Splunk
Splunk
 
Rage WITH the machine, not against it: Machine learning for Event Management
Splunk
 
Splunk Forum Frankfurt - 15th Nov 2017 - GDPR / EU-DSGVO
Splunk
 
Splunk Forum Frankfurt - 15th Nov 2017 - Machine Learning For Event Management
Splunk
 
Splunk Forum Frankfurt - 15th Nov 2017 - Threat Hunting
Splunk
 
Ad

Similar to SplunkLive! Customer Presentation--ServiceNow (20)

PPTX
Splunk for Enterprise Security Featuring UBA
Splunk
 
PPTX
Splunk for Enterprise Security featuring UBA Breakout Session
Splunk
 
PPTX
Equinix Customer Presentation
Splunk
 
PPTX
Getting Started with Splunk Enterprise
Splunk
 
PPTX
Inside SecOps at bet365
Splunk
 
PPTX
Splunk for Enterprise Security featuring UBA Breakout Session
Splunk
 
PDF
SecOps.pdf
Aelum Consulting
 
PPTX
Splunk Webinar: Webinar: Die Effizienz Ihres SOC verbessern mit neuen Funktio...
Splunk
 
PPTX
Splunk for Security Breakout Session
Splunk
 
PPTX
SplunkLive! - Splunk for Security
Splunk
 
PPTX
Travis Perkins: Building a 'Lean SOC' over 'Legacy SOC'
Splunk
 
PPTX
Splunk for Enterprise Security featuring User Behavior Analytics
Splunk
 
PPTX
Splunk Discovery Day Dubai 2017 - Security Keynote
Splunk
 
PPTX
Splunk for Enterprise Security featuring User Behavior Analytics
Splunk
 
PPTX
Managed security services
manoharparakh
 
PPTX
Splunk for Enterprise Security and User Behavior Analytics
Splunk
 
PPTX
SplunkLive! Overview
Georg Knon
 
PDF
Security Teams & Tech In A Cloud World
Mark Nunnikhoven
 
PDF
SplunkLive! London - Splunk App for Stream & MINT Breakout
Splunk
 
PDF
F_DR_Dark Reading Editorial Report_March 2022.pdf
josbjs
 
Splunk for Enterprise Security Featuring UBA
Splunk
 
Splunk for Enterprise Security featuring UBA Breakout Session
Splunk
 
Equinix Customer Presentation
Splunk
 
Getting Started with Splunk Enterprise
Splunk
 
Inside SecOps at bet365
Splunk
 
Splunk for Enterprise Security featuring UBA Breakout Session
Splunk
 
SecOps.pdf
Aelum Consulting
 
Splunk Webinar: Webinar: Die Effizienz Ihres SOC verbessern mit neuen Funktio...
Splunk
 
Splunk for Security Breakout Session
Splunk
 
SplunkLive! - Splunk for Security
Splunk
 
Travis Perkins: Building a 'Lean SOC' over 'Legacy SOC'
Splunk
 
Splunk for Enterprise Security featuring User Behavior Analytics
Splunk
 
Splunk Discovery Day Dubai 2017 - Security Keynote
Splunk
 
Splunk for Enterprise Security featuring User Behavior Analytics
Splunk
 
Managed security services
manoharparakh
 
Splunk for Enterprise Security and User Behavior Analytics
Splunk
 
SplunkLive! Overview
Georg Knon
 
Security Teams & Tech In A Cloud World
Mark Nunnikhoven
 
SplunkLive! London - Splunk App for Stream & MINT Breakout
Splunk
 
F_DR_Dark Reading Editorial Report_March 2022.pdf
josbjs
 

More from Splunk (20)

PDF
Splunk Leadership Forum Wien - 20.05.2025
Splunk
 
PDF
Splunk Security Update | Public Sector Summit Germany 2025
Splunk
 
PDF
Building Resilience with Energy Management for the Public Sector
Splunk
 
PDF
IT-Lagebild: Observability for Resilience (SVA)
Splunk
 
PDF
Nach dem SOC-Aufbau ist vor der Automatisierung (OFD Baden-Württemberg)
Splunk
 
PDF
Monitoring einer Sicheren Inter-Netzwerk Architektur (SINA)
Splunk
 
PDF
Praktische Erfahrungen mit dem Attack Analyser (gematik)
Splunk
 
PDF
Cisco XDR & Splunk SIEM - stronger together (DATAGROUP Cyber Security)
Splunk
 
PDF
Security - Mit Sicherheit zum Erfolg (Telekom)
Splunk
 
PDF
One Cisco - Splunk Public Sector Summit Germany April 2025
Splunk
 
PDF
.conf Go 2023 - Data analysis as a routine
Splunk
 
PDF
.conf Go 2023 - How KPN drives Customer Satisfaction on IPTV
Splunk
 
PDF
.conf Go 2023 - Navegando la normativa SOX (Telefónica)
Splunk
 
PDF
.conf Go 2023 - Raiffeisen Bank International
Splunk
 
PDF
.conf Go 2023 - På liv og død Om sikkerhetsarbeid i Norsk helsenett
Splunk
 
PDF
.conf Go 2023 - Many roads lead to Rome - this was our journey (Julius Bär)
Splunk
 
PDF
.conf Go 2023 - Das passende Rezept für die digitale (Security) Revolution zu...
Splunk
 
PDF
.conf go 2023 - Cyber Resilienz – Herausforderungen und Ansatz für Energiever...
Splunk
 
PDF
.conf go 2023 - De NOC a CSIRT (Cellnex)
Splunk
 
PDF
conf go 2023 - El camino hacia la ciberseguridad (ABANCA)
Splunk
 
Splunk Leadership Forum Wien - 20.05.2025
Splunk
 
Splunk Security Update | Public Sector Summit Germany 2025
Splunk
 
Building Resilience with Energy Management for the Public Sector
Splunk
 
IT-Lagebild: Observability for Resilience (SVA)
Splunk
 
Nach dem SOC-Aufbau ist vor der Automatisierung (OFD Baden-Württemberg)
Splunk
 
Monitoring einer Sicheren Inter-Netzwerk Architektur (SINA)
Splunk
 
Praktische Erfahrungen mit dem Attack Analyser (gematik)
Splunk
 
Cisco XDR & Splunk SIEM - stronger together (DATAGROUP Cyber Security)
Splunk
 
Security - Mit Sicherheit zum Erfolg (Telekom)
Splunk
 
One Cisco - Splunk Public Sector Summit Germany April 2025
Splunk
 
.conf Go 2023 - Data analysis as a routine
Splunk
 
.conf Go 2023 - How KPN drives Customer Satisfaction on IPTV
Splunk
 
.conf Go 2023 - Navegando la normativa SOX (Telefónica)
Splunk
 
.conf Go 2023 - Raiffeisen Bank International
Splunk
 
.conf Go 2023 - På liv og død Om sikkerhetsarbeid i Norsk helsenett
Splunk
 
.conf Go 2023 - Many roads lead to Rome - this was our journey (Julius Bär)
Splunk
 
.conf Go 2023 - Das passende Rezept für die digitale (Security) Revolution zu...
Splunk
 
.conf go 2023 - Cyber Resilienz – Herausforderungen und Ansatz für Energiever...
Splunk
 
.conf go 2023 - De NOC a CSIRT (Cellnex)
Splunk
 
conf go 2023 - El camino hacia la ciberseguridad (ABANCA)
Splunk
 

Recently uploaded (20)

PPTX
GALILEO CRS SYSTEM | GALILEO TRAVEL SOFTWARE
philipnathen82
 
PDF
Key Features to Look for in Arizona App Development Services
Net-Craft.com
 
PPTX
Odoo Integration Services by Candidroot Solutions
CandidRoot Solutions Private Limited
 
PDF
New Download MiniTool Partition Wizard Crack Latest Version 2025
imang66g
 
PPTX
Maximizing Revenue with Marketo Measure: A Deep Dive into Multi-Touch Attribu...
bbedford2
 
PDF
Salesforce Implementation Services Provider.pdf
VALiNTRY360
 
PPTX
Role Of Python In Programing Language.pptx
jaykoshti048
 
PPTX
Visualising Data with Scatterplots in IBM SPSS Statistics.pptx
Version 1 Analytics
 
PPTX
Explanation about Structures in C language.pptx
Veeral Rathod
 
PPTX
slidesgo-unlocking-the-code-the-dynamic-dance-of-variables-and-constants-2024...
kr2589474
 
PDF
MiniTool Power Data Recovery Crack New Pre Activated Version Latest 2025
imang66g
 
PPTX
ASSIGNMENT_1[1][1][1][1][1] (1) variables.pptx
kr2589474
 
PPTX
classification of computer and basic part of digital computer
ravisinghrajpurohit3
 
PPTX
Can You Build Dashboards Using Open Source Visualization Tool.pptx
Varsha Nayak
 
PDF
vAdobe Premiere Pro 2025 (v25.2.3.004) Crack Pre-Activated Latest
imang66g
 
PDF
lesson-2-rules-of-netiquette.pdf.bshhsjdj
jasmenrojas249
 
PDF
advancepresentationskillshdhdhhdhdhdhhfhf
jasmenrojas249
 
PDF
On Software Engineers' Productivity - Beyond Misleading Metrics
Romén Rodríguez-Gil
 
PPTX
Contractor Management Platform and Software Solution for Compliance
SHEQ Network Limited
 
PPTX
Web Testing.pptx528278vshbuqffqhhqiwnwuq
studylike474
 
GALILEO CRS SYSTEM | GALILEO TRAVEL SOFTWARE
philipnathen82
 
Key Features to Look for in Arizona App Development Services
Net-Craft.com
 
Odoo Integration Services by Candidroot Solutions
CandidRoot Solutions Private Limited
 
New Download MiniTool Partition Wizard Crack Latest Version 2025
imang66g
 
Maximizing Revenue with Marketo Measure: A Deep Dive into Multi-Touch Attribu...
bbedford2
 
Salesforce Implementation Services Provider.pdf
VALiNTRY360
 
Role Of Python In Programing Language.pptx
jaykoshti048
 
Visualising Data with Scatterplots in IBM SPSS Statistics.pptx
Version 1 Analytics
 
Explanation about Structures in C language.pptx
Veeral Rathod
 
slidesgo-unlocking-the-code-the-dynamic-dance-of-variables-and-constants-2024...
kr2589474
 
MiniTool Power Data Recovery Crack New Pre Activated Version Latest 2025
imang66g
 
ASSIGNMENT_1[1][1][1][1][1] (1) variables.pptx
kr2589474
 
classification of computer and basic part of digital computer
ravisinghrajpurohit3
 
Can You Build Dashboards Using Open Source Visualization Tool.pptx
Varsha Nayak
 
vAdobe Premiere Pro 2025 (v25.2.3.004) Crack Pre-Activated Latest
imang66g
 
lesson-2-rules-of-netiquette.pdf.bshhsjdj
jasmenrojas249
 
advancepresentationskillshdhdhhdhdhdhhfhf
jasmenrojas249
 
On Software Engineers' Productivity - Beyond Misleading Metrics
Romén Rodríguez-Gil
 
Contractor Management Platform and Software Solution for Compliance
SHEQ Network Limited
 
Web Testing.pptx528278vshbuqffqhhqiwnwuq
studylike474
 

SplunkLive! Customer Presentation--ServiceNow

  • 1. Copyright © 2014 Splunk Inc. Justin Dolly CISO ServiceNow ServiceNow + Splunk Integration
  • 2. 2 ServiceNow Overview ServiceNow is the enterprise IT cloud company. We transform IT by automating and managing IT across the global enterprise. Organizations deploy our service to create a single system of record for IT and automate manual tasks, standardize processes, and consolidate legacy systems. Using our extensible platform, our customers create custom applications and evolve the IT service model to service domains inside and outside the enterprise Founded in 2004 IPO in June 2012 2300+ customers 2100+ employees 2013= $470m revenue
  • 3. 3 ServiceNow Overview Single system of record for IT Single Cloud Platform Robust Suite of IT Applications Custom Application Development Enterprise Cloud Infrastructure Lights-out, zero-touch automation Powerful Business Intelligence Reporting Accelerate time-to-value
  • 4. 4 My Background and Role Justin Dolly, VP & CISO at ServiceNow Former CISO at VMware Previously held security and technology leadership roles at – Kaiser Permanente, – CNET Networks / CBS Interactive, – Macromedia – Wells Fargo Bank
  • 5. 5 Security Challenges Most Security teams now have budget, staff & tools Having many tools can be cumbersome & inefficient Security teams typically work in a Silo Our Situation, a year ago: Log Analytics and Service Management were disparate systems Need threat identification and event correlation Information is there, but it’s difficult to access Needed to address compliance and audit reporting needs
  • 6. 6 Splunk @ ServiceNow Today Collecting over 400GB/ day and growing Enterprise Security is our SIEM collecting threat intelligence data and providing actionable results ‘Single pane of glass’ view across enterprise for threat identification and event correlation Splunk alerts trigger script actions which push events into ServiceNow via SOAP and XML Events are analyzed by a dedicated Security Operations team
  • 7. 7 Splunk @ ServiceNow Today Syslog Events • Network • Firewall • F5 LTM/ASM • Wireless IDS Syslog Store and Forward Splunk Indexers SplunkES Search Head Splunk Search Head ServiceNow Security Instance Event Console
  • 8. 8 Integration Overview Custom built integration using the Splunk REST APIs and ServiceNow APIs Splunk is periodically queried for security related events Script actions push event data into ServiceNow instance events table Business rules extract unique identifiers from the events table for de- duplication and correlation Security analyst reviews events in the ServiceNow console and elevates events to incidents for investigation New event data received is automatically associated to open incidents Open incidents drive response activities and workflow across the organization
  • 9. 9 What’s Next We continue to grow quickly Big Data analytics also grows in importance Leveraging the new Splunk integration with ServiceNow Event Management Console (newly released in Eureka) Integration with ServiceNow Threat Intelligence Portal
  • 10. 10 Top Takeaways Embrace the mind-shift in Security – Re-think the relationship between your systems, processes, and people – The traditional tools won’t save you Technology when done right is extremely liberating – Applying threat intelligence and real-time analytics makes response activity faster & more accurate The only metric that matters is how quickly you respond to a security event – Don’t chase the information, let it come to you

Editor's Notes

  • #6: Required manual creation of incidents based on Splunk events and alerts Excessive time and effort to duplicate information Needed incident management capabilities to track workflow through closure.
  • #7: Ability to push Splunk events into ServiceNow as either an incident OR as an incident / event in the latest Eureka release Ability to pull in any info from ServiceNow and correlate that with info from any other sources within Splunk
  • #9: New events associated to open incidents; unrelated events that are automatically assigned in error can be split out by the security analyst into separate incidents to be tracked and handled separately