Splunk

Splunk

First set series

The First Set Series is a solution provided by combining Macnica 's unique template "Apps," the machine data analysis platform "Splunk Enterprise," and the "Gemini Appliance," a dedicated Splunk server.

+
+
arrow
First set series
First set series

First set series lineup

name
Security log analysis first set
Security log analysis first set
Included Splunk Apps Macnica CSIRT App
Target data source Mainly Proxy logs (regardless of product) * Field extraction corresponding to CIM is required.
Splunk License A separate Splunk license is required depending on the amount of data to be imported/day.
Gemini Appliance We propose the optimal model and configuration according to log size, storage period, and usage.
Delivery method Macnica CSIRT Appの提供基準を満たしたSplunk正規リセラー様経由でのご提供となります。
name
Proxy log analysis first set
Proxy log analysis first set
Included Splunk Apps Macnica Proxy Log Analysis App
Target data source Proxy logs (Target product: Symantec ProxySG)
Splunk License A separate Splunk license is required depending on the amount of data to be imported/day.
Gemini Appliance We propose the optimal model and configuration according to log size, storage period, and usage.
Delivery method Available through Splunk authorized resellers. For construction, a start-up service is available.

Configuration image

  • Configuration image

future expansion

  • In the future, by adding various log sources, the range of analysis will be expanded, and it will be useful for monitoring, investigation, detection, etc. in IT operation and security.
  • After purchasing the set for the first time, by purchasing additional Splunk licenses and Gemini Appliances, it is possible to expand with various configuration patterns such as distributed configuration, indexer cluster configuration, indexer and search head cluster configuration.