Nutanix Data Lens Demo
In the Nutanix presentation at AI Field Day 7, Mike McGhee showcased the capabilities of Nutanix Data Lens, a data analytics and cybersecurity tool designed to provide visibility across storage environments, including Nutanix file servers and third-party object stores like AWS S3. The tool collects and analyzes metadata—for example, file names, sizes, and data age—as well as real-time audit trails that track operations like reads, writes, and permission changes. Data Lens is tightly integrated with Nutanix storage solutions and will soon be bundled with their offerings for on-premises deployments, ensuring seamless operational data ingestion and monitoring without reliance on external scanning requests.
A major feature of Data Lens is its ransomware protection, which includes both signature-based detection using known file extensions from open source communities and behavioral analysis that identifies anomalous events like in-place or out-of-place encryption. This allows Data Lens to detect threats from unknown malware using intelligent algorithms trained on customer activity patterns. When threats are detected, Data Lens can log full user activity, block affected users or clients, and provide options for recovery that include restoring individual affected files or entire shares using recommended snapshots taken before the time of compromise. This detailed approach helps reduce false positives and accelerates recovery in the event of an attack.
In addition to its security functions, Nutanix emphasized the need for better tooling and data accessibility for platform engineering and end-users, particularly when supporting AI and DevOps workflows. Speakers stressed the importance of giving end-users API-level access to infrastructure components like databases, Kubernetes platforms, and AI services so they can manage and troubleshoot their workloads autonomously, without bottlenecks from IT. Nutanix’s broader ecosystem—including Nutanix Kubernetes Platform (NKP), Nutanix Database Services (NDB), and Nutanix AI (NAI)—was presented as a robust infrastructure solution with integrated observability and automation features designed to empower users and admins alike with actionable insights and streamlined management.
Recorded live in Santa Clara, California on October 30, 2025 as part of AI Field Day 7. Watch the entire presentation at https://techfieldday.com/appearance/nutanix-presents-at-ai-field-day-7/ or visit https://TechFieldDay.com/event/aifd7/ or https://www.Nutanix.com/enterprise-ai/ for more information.
Transcript
My name is Mike McGee. I'm the tech marketing team with, uh, with Nutanix, um, Nutanix, 11 years I was EMC almost 16 years before, before. Then I've launched into the data lens interface here, what, uh, Vishal was just talking about.
Um, and within this we can analyze object stores, file servers, Nutanix file servers, but also third party object stores as well. So if you notice under object stores here, we have, uh, AWS based S3 object store. So the same way we collect information, the metadata, data age, name of the files, size of the files, and the objects, et cetera.
We could do that across certain third parties like AWS S3. Um, so that's the metadata piece of it, but at the same time, we're also taking in real time audit trails to start to an, to answer your your question Malcolm. Um, so as a part of intaking those audit trails, we understand the patterns.
We, we know what Reed's rights, permission changes, set attributes, et cetera, are coming into the system. So, so Mike, is data lens a separate solution, uh, aside from the storage, or is it bundled in with the storage? Is it bundled in with the Nutanix solution?
I'm not sure. Where does it play? Sure.
Data lens today is a software as a service that runs in the public cloud. It has integrations into what we do. So, for example, when I say data lens does a scan, it doesn't do the scan, it requests the file server to do the scan to collect that met metadata, and then it, it'll send the metadata to, to data lens.
Um, but it, it, like Michelle mentioned, it will also be OnPrem in the not too distant future and it'll be bundled with The same Nest offering. Yes. Right.
Yep. And then same with the audit trails. Like, so we have a, a, a way to publish the audit trails from our systems, either two third parties, so we have third parties that ingest that system as well.
Um, and data lens is just another client to it. Ultimately, when it comes to that, that real-time information as it comes in. So if I pick on a particular FI file server here, you can see some of the metadata.
But again, I want to, I wanna really address that, that question directly. Um, so if I go to the, the ransomware protection page, we really have two forms of protection. Um, one is signature based.
Can You confirm, so is data lens specifically designed for AI workloads or is it just something that's general and can be applied to AI workloads? It it, the latter. It, it could be applied to AI workloads, but it's not specific to ai AI workloads.
It's really looking at any, it could be a VMS solution, reading and writing to the system. It could be end users, it could be an EUC use case, you know, home directories and whatnot. It could be healthcare PAC based data.
It could really be anything that feeds into the system, creates those audit trails that we can then monitor. Um, so it's not exclusive ai, but it would, it could also work with AI clients as well. Okay.
Yep. So two, two real forms. One is signature based.
Um, and this is where we, we kind of, we have a, a, a stock, if you will, uh, list of existing file signatures by the name or by the extension. Uh, and when you first enable data lens, we'll actually go through that metadata and look at the system and see if you have any existing patterns there. And if it does, we'll warn you in fact, the little bar on the top.
You can see in the system, we found existing files that match some of those, um, audit trails, uh, or, or, or I should say file signatures. And because of that, um, we'll actually apply that to the blocking list of the file server. So we don't wanna start blocking files that might actually be okay.
Um, you know, the false positive, uh, prevention like Vishal was mentioning. Um, so we will alert you to that. And then from that point on, you can choose to allow, list those files if you want, or if maybe it was malicious.
You're now aware that you had, you had some activity, some malware, some ransomware operating On this. Mike, just to be clear, the signatures that you're looking for are file extensions or file name signatures Correct. For a particular malware instance.
Right. Based based on historical information and, and those that have been out there in the wild. And then for what you might consider new, uh, or not based on file signature, uh, patterns, um, we look for, I, I would, I would summarize it as two main types of events.
So in, in in place encryption event or an out of place encryption event. And that's where we have algorithms through data lens as it sees these, these audit trails come in, does it look like a, like a read of a file, an override of the file, perhaps at a, at a rename of the file? And did the, the, did the, the mime type of that file change?
So for example, did it go from a PDF or a DOC or a CSV or what have you to like an Octa set or a, or an encrypted file. And we actually interrogate the file on the system to see if it did change to, to a binary scenario. And if that, if that's the case, we consider that a threat and we have ways to look at it in place or out of place.
I'll let you get on real quick. Yeah, yeah. But, um, so are you receiving, are, is this all Nutanix ip?
So in other words, this is all your kind of intelligence and everything wrapped up, or you're receiving sensor feeds from folks like Gray Noise or, you know, you know, Symantec or, or whatever as, you know, as they identify things out in the wild as well so that you have a more globalized view of these are the changes that are happening. 'cause rapid cycling within this industry is massive, right? Sure.
So I, I don't think we have integration with third parties like that, like the pattern detection when it comes to the audit trails. That is something that, okay. That, that we, we have, and it's based on our existing user base.
We have quite a few customers that, that leverage this. So just based on, um, you know, the patterns that we see, um, and there's known applications that write in weird ways that kind of look like an in place like encryption event. So we have intelligence in the system to, to try to prevent flagging that and, and causing a false positive, et cetera.
Yeah. So pure signature based is what we get from the o open source community, like all the known ones that the Lockes and all those file extension based, that we leverage the community for that. The new ones, which we are known, not known signatures, those are the ones where these algorithms that we have built Okay.
Comes into place. Absolutely. So you leverage open source signatures and you develop your Own, that's it.
Correct. Okay. Yeah, the behavioral one is develop, right?
Sorry. Oh, good. Okay.
Awesome. Um, yeah, and so when we do, and you can see in this environment, you know, the test environment. So we detected some operations.
Um, you can see things like, uh, the, the clients we blocked, and I haven't gotten into our audit trail specifically, but because we have those full audit trails, if we detect something and we block that end, end client or user, we can see the full activity of what they've been up to. And, you know, if it turns out to be harmless, we can unblock 'em or we can quarantine, we can export this out, draw reports against this activity for it off to security team or what have you. So get getting those additional insights.
And then for any particular threat, um, you know, we were talking about the timing, right? So we have various threats on, on this system. If I, if I click on threats, so for example, for this, this threat on top, if let's say that's, that's innocuous, that turns out not to be, you know, a, a typical pattern or operation on the system, I can simply say manage and I can allow list that that client, that user against, that share against the whole system or against that particular file type.
So we make it very easy to remediate if, if for some reason there's an existing pattern in in the environment, which is okay that we detect. And then when it comes to impacted files, so again, talking about that timing, we'll actually, uh, log and give you a list of any of the files that we consider that might have been impacted as a part of that overall operation. So for example, if I click on, uh, you know, the affected files in this environment, if I wanted to then, you know, piecemeal restore, maybe I don't have to restore that entire share, maybe I just wanna restore those individual files.
We'll actually recommend to you if you click recover, what snapshot we think would be the best one to recover from because it's older than the event. So, you know, the files were not touched or not encrypted since that point in time. So we would recommend that snapshot to then pull it over.
And then if it's a larger event and you don't want to piecemeal or pick through, um, you can actually go to the impacted shares here and simply say recover. Um, so for example, on that same share, and this is where again, we recommend a snapshot, all you do is click recover, and we'll actually do a, a, you know, a block based fast recovery of that share in place. So if it was a larger, more pervasive event, um, it would get you back to a known state quickly.
So again, going back to what Vishal was saying, part of it is detecting it quickly, stopping it, but also recovering it as quickly as possible to get you back in business. Alright. Carl Fugate, so one of the things that we're really seeing in an incident response now is that, while this is great and this, this really helps from the data plane perspective, what we're seeing is attackers are starting to go after the administrative plane even more.
So having the mutable copy is, is kind of that first step and it's absolutely one of the most important. But one of the others is making sure that from an administrative control perspective, that I can't go and delete that immutable copy. If somebody, if an attacker were to get, uh, access to those administrative credentials, how do you guys handle that in, in your system providing kind of that segmentation of those administrative roles, uh, and still protect the, um, the immutable backup or the bolted backup?
Sure. So if I flip back, um, so I was gonna start this particular demo, DC comic fans here, Uh, with, uh, with, with Prism. So, so we talked about Nutanix Central and, and Prism, which is our management, uh, interface before, um, prism, regardless of, you know, if you're using the file server, the object store, if you're using, um, you know, looking, looking at the underlying infrastructure, the virtualization layer, the Kubernetes layer, um, to access this, we have full, full blown role-based access control.
So if you wanted to really segment the, the underlying user, uh, base to only have access to certain operations, you know, that's one of the, one of the primary things that we would recommend. We also have a, um, security dashboard, which you, which you can see at the, at the bottom here, that that gives you kind of an up-to-date understanding of, you know, did you change your, um, your system, like default passwords? I guess, I guess one, just follow on to Carl's question.
If, if I have, uh, an immutable snapshot, do I have something that, uh, provides a, a guaranteed date where it can't be deleted by, let's say, you know, can I say it can't be deleted for the next 90 days or two years or something like that? And even if you're on admin and I follow through the RAC and I get through all way to prison and I'm there, I'm super user, I still can't touch it. Yeah.
So, so from an object store perspective between object, between worm, uh, and, and versioning, we do, yeah. So, so that would, that, those are prevented like administratively from, from being removed, um, on the file server side, the snapshots are removable are, are, uh, are mutable, but we don't have a necessarily what, what you might consider a secure snap facility where you would block out the administrator for a certain period of time of, of deleting those particular snapshots. Um, we do have worm capabilities for that.
So if you wanted to lock down the file server itself or the file share itself to worm policies, we, we, we do allow you to Do that. But that's the, that's the active file share. That's not the snapshots.
Correct. But I mean, but I mean like administrative access to, to the file server is, is functionally what I'm getting at That answer your question, Carl. Yeah.
So I, so I'd essentially be able to create a vault, uh, a worm vault for these that an administrator, even an administrator would not be able to, to go delete them during whatever the retention policy is that Using, using replication or something like that, or, I don't know. That's what I'm Well no, it, it, it's, so it's because we're, we are locking down that, that object store so that that object store from a worm perspective Understand the object storage perspective, but is it because your object storage is actually a backend for all this stuff? Is that, is that what you're talking about?
No, no. He's talking about a file system or a file share or something like that and he wants to lock down a file share. Yeah.
So, so file share perspective, it would be the worm capability for the file share itself. Yep. Yeah.
So, so I'm specifically talking about the immutable, the immutable snapshot or backup of, of, of the data is making sure that, so this, and there's, there's a lot of different ways that companies have gone about, you know, handling this. Um, but being able to set, uh, an administrator an, a retention policy such that, that even an administrator cannot, um, cannot touch that file during that retention period. Um, such that snapshot Yeah, the snapshot.
So that, um, if an attacker were to go after the backup, um, that, that we would still have access to it. Correct. Yeah.
So on the file server side, we, we don't offer that today. I don't know if there's roadmap items we can There cover that part. So Yep.
In fact, one of the capabilities that we support for the entire platform is the secure snap. That's the capability that we call it, it is primarily a multi-factor authentication based piece where one admin cannot delete it. You need to have a code to delete that piece.
It's already part of the main platform. We are bringing it to the, both the storage, the files and storage offering where it'll require that multifactor authentication before you can delete a Snapshot. That's a and that's a really good feature like that, that definitely helps, uh, provide that segmentation.
Yeah. Yeah. And you're concerned, is somebody coming in and, and, and pretending admin super user.
Yeah. And, and that's what we're seeing, right? So the first, the first thing that an attacker is going after is the backup.
So they, they, they don't want, like, because they, they, so many platforms now have these ransomware capabilities built in, so they've got the detection, so they know as soon as the, as soon as it gets detected it's gonna go into lockdown it, now I want to go, I'm just gonna revert back. Well, the first thing they do is they say, well, I'm gonna go delete the backups. Uh, so that when, when this starts kicking off, now I can't actually go back to that previous point in time 'cause I already dropped that.
So I go after that first and then I can go ahead and, and execute my encryption. Yeah, it makes sense. Or, or attempts to modify the policy.
So for example, on the object side, we have anomaly detection if someone tries to modify the policy of the bucket, like disabled versioning. Yeah, same. Try to try to, you know, to, to expire the worm, uh, like earlier, right?
Like that sort of thing. Absolutely. So we, so if someone tries to do that data lens actually has intelligence to flag that as a threat.
Um, you know, based on, you know, based on its anomaly detection outside of just the actual patterns coming in, like a data exfiltration event, which is another example, which is more common on the object side, less concerned about encryption. But if someone trying to draw data out for maybe blackmail purposes or, or what have you. So there's the, the, the anomaly detection and rans for protection on the object side is more catered to that particular use case.
'cause it's less about in place and more about pulling the data out or modifying policies exactly like you said. Yep. Absolutely.
To go to the other side of the security question, um, giving our users or end users full access to do what they want, not necessarily on the system, but even like in AI workloads or even a secretary running through whatever she's doing to be able to quickly stand something up and build on their own. Um, especially for training, um, models, um, lapping, stuff like that. So what are, what tools are you giving your platform teams to make it easier to build those for their users To, to to build, to build the security controls?
To, to limit? So limit global access. If I'm, if I'm a platform team.
Yep. Okay. I'm looking at having to maintain this under a DevOps operation, but then I also have my developers screaming down my throat.
Oh sure. Because they have to wait two days to get their inference job back online. 'cause they had to submit a damn ticket.
They need to run their own inference pipelines, they need to do their own stuff. Um, and a soapbox a little, um, that's one thing we failed with at cloud and on-prem is providing end users the right tools. We still forced them to go through it with that.
Let's, so the tools, we need to percolate those up to the platform teams so they can develop better solutions for their users. So, so API access to the end user Almost even further. So what packages, what libraries, what tools on top of your API what data are you percolating up from these deep level inspections?
Not necessarily, you can go here and look at it. We don't care about data that's now existing from alerts. What, what, what action are you taking on that data now?
Mm-hmm. And where are you giving it to the user? Yeah, so, so I'll, I'll, I'll approach it a few ways.
So like on this same cluster, for example, and I know we're, we're running short on time, um, and I was gonna go into it. So for example, our Nutanix Kubernetes platform is running here. So an infrastructure administrator would have, you know, to Keith's point earlier around a a a, a simple consolidated platform that is the same operation model regardless where you run, we can do that, but for that end user, they might want direct access into that Kubernetes environment to have or an API endpoint to have a better understanding of what's mm-hmm.
Occurring at that level. And that's where NKP comes in. Okay.
So Kubernetes platform gives its own, you know, API capability management to the end user or an administrator at its level. So while we see it here from an infrastructure perspective, we wanna make sure it performs, you know, if there's inferencing or what have, what have you occurring against it, we'll be able to monitor it the same way we monitor the VIS database or you know, the PG vector or the object store or the file server. But if you wanna then give those end users, you know, those platform engineers access, you could give them access to NMKP.
And the same with N ai. So the Nutanix, you know, enterprise AI platform has its own endpoint, you know, API endpoint for individual users, for developers, for, you know, for those practitioners. And the same with NDB.
So our database platform fully A API compliant, you know, if you're an infrastructure admin, you can monitor it from here, you know, so I literally have pg you know, SQL databases in this environment. But then, you know, for the, the DBA, they, they might need access to the era frontend API to then automate operations there, you know, whether it's consistent deployment, consistent upgrades. So, so Ryan, something Like, like a Python SDK for their API Or no.
Um, so as an end user, if I'm kicking off an inference job or not an inference job, a training job, um, I wanna be able to watch that progress. And like, if I do that, in a very great example of doing this right, is notebook lm, we attached an entire cloud to a Word document. Okay.
And anybody can use it. Now as a user in notebook, lm I mean, um, in CoLab, if I see that inference job fail, I just click retry. And so the notion that we have to go back to an IT team, you know, from anything is ridiculous for this type of stuff, um, that should be passed up to the user.
And so the, the, the platform teams have to build those tools off of the vendor's APIs to, to abstract all that knowledge that the user doesn't care about. Um, and it's not just pushing out an API or just a set of clients to your customers, uh, it's, it's about providing an ecosystem or a framework or something bigger. You, I saw y'all's pipeline tool, um, that y'all talked about at the beginning.
And that's a great start. Like take that pipeline tool, give your admins your DevOps teams superpowers to handle those at a deep level without needing the ML ops experience, but allow your end users to be able to interact with that as well, or get the information out of it to do their job better. Yeah.
Yeah. Anyways, I'll, I'll drop my sim. No, it's Very true.
And that's a big part of the n ai, like I mentioned, like the observe, observability piece of it. Mm-hmm. Um, even down to understanding like GP utilization, et cetera could be bubbled up beyond just that infrastructure team to those end users.
Like, And it goes as simple. 'cause a lot of that too, like everything is very passive to our end users now. So requests just get fired down a long tunnel of a black hole and they never see.
So if they submit a ticket or they say, Hey, retry, do they get the information back that it's actually retrying? Is it doing or is there no reason to retry because services are down? So No, the feedback, yeah, appreciate that perspective.
Yeah, absolutely.