Splunk

Splunk

Dashboard/SPL Creation Pack

当サービスはSplunkの運用に必要不可欠な「設定メンテナンス」や「ダッシュボードの新規作成」を代行実施させて頂くサービスです。Splunkの専門知識と対象ドメインの専門知識をもったエキスパートが要件定義のご支援から設定変更や設定作成の作業遂行までを一貫してご提供させて頂きます。

As a service menu, we have prepared the following two to meet each request: "maintenance of settings" and "creation of new dashboards".

Dashboard/SPL Creation Pack - Pricing Structure

  • Provided at 2,500,000 yen (excluding tax) per pack, with the maximum work volume below as “1 pack”
  • If it does not fit in one pack, purchase multiple packs as needed. It is also possible to purchase multiple combinations of the following "requirement patterns"
  • Remote work in principle (using VPN or RDP)
Requirement pattern work volume limit
  • I want to create SPL artifacts * only
  • Creation of up to 15 individual SPL artifacts (visualization panels/reports/alerts/search)
*Reusable SPL searches are counted as 1
  • I want to implement data ingestion processing and Splunk-base App implementation
  • Ingestion of up to 3 new data sources
  • Deploy up to 3 supported apps or add-ons within Splunk-base
*However, Premium Apps are not eligible (eg ITSI, ES, MLTK, MINT, etc.)
  • I want to implement data import processing and SPL artifact creation *
  • Ingestion processing of up to 1 new data source
  • Creation of up to 8 individual SPL artifacts (visualization panel/report/alert/search)
*Reusable SPL searches are counted as 1
  • I want to implement data acquisition processing, SPL artifact creation *, and Splunk-base App implementation.
  • Ingestion processing of up to 1 new data source
  • Creation of up to 5 individual SPL artifacts (visualization panel/report/alert/search)
  • Deployment of App or Add-On supported in up to 1 Splunk-base
*Reusable SPL searches are counted as 1
*However, Premium Apps are not eligible (eg ITSI, ES, MLTK, MINT, etc.)

* "SPL Artifact" defined in this service means "visualization panel" or "report" or "alert" or "search" on Splunk created based on SPL language.

For those who are worried about personnel and skills when using Splunk

We would like to actively create use cases and solutions using Splunk, but it is also true that there are many customers who have not been able to do so due to the following personnel and skill issues. This service is a "work substitution type" service that solves such customer's worries.

Splunk needs maintenance...

Configuration maintenance is essential for using Splunk. For example, it is necessary to change SIEM rules and tune alert accuracy according to changes in threat trends in order to maintain and improve security levels. It is also necessary to create a new dashboard if the internal infrastructure changes or a device that becomes a data source is added.

On the other hand, it is also true that there are customers who are not able to perform necessary maintenance sufficiently due to lack of operating resources and lack of skills of Splunk engineers. In addition, we often hear that there are many dashboards that are left untouched without being able to change the settings because the documentation at the time of construction is not available.

This service has been released with the aim of resolving such customer concerns, helping them master Splunk, and maximizing their return on investment.

Features of our service

Features: Part 1: Perform work remotely

  • Since there is no on-site work, it is possible to complete the work in a relatively short period of time from request to completion.
  • Use VPN connection or remote desktop connection for remote connection

Media introduction

Dashboard/SPL creation pack was introduced in the media.

Service specification

You can download it from below.

Inquiry/Document request

In charge of Macnica Splunk Co., Ltd.

Mon-Fri 8:45-17:30