Splunk Focuses on Resilience – Mike Horn, Splunk
Mike Horn, GM of the Splunk security business, joins Mike Rothman to discuss recent announcements that help customers build more resilient infrastructures. Splunk recently announced a unified user experience called Mission Control and released an edge processor to help customers better control the data going to Splunk Cloud.
Transcript
This is texturing TV. Hi everybody, Mike Rothman here general manager of text wrong research and I'm joined today on techstrom TV by Mike horn who is now general manager. We're both general managers, you will this huge thing and me of this little thing but my core general manager Splunk security long time entrepreneur.
I've known Mike for you know, many years back from his first startup, I guess with universal net Citadel. I was a person that's right. Yeah, so back from the net Citadel days of pioneer and security automation well ahead of his time, but now things are starting to catch up.
So Mike welcome to the show. How are you today? Thanks, Mike.
I'm doing great. I'm excited to be here and tell you a little bit more about what we're up to at Splunk. Yeah, so that's interesting.
Let's kind of take a step back before I know you recently joined Splunk as part of the acquisition of your startup twin wave. So let's just give us a minute interview a minute overview of twin wave and and really white fits into you know, kind of the spunk security structure. Yeah.
That's a great question and one I got a lot, you know, so twin wave it was myself and two other co-founders we came out of proof point where we were analyzing billions of things a day. And what we saw was there was a gap in some of the the tooling that Enterprise security teams had when they wanted to analyze threats that had gotten through so, you know think the advanced attacks where people are attackers or you know, doing all sorts of stuff cure codes, you know, intermediate websites, you got to click through weird, you know, file formats all those kinds of things that we're really You know kind of making it challenging for Enterprise security teams to do their analysis that quickly and accurately and so we saw an opportunity to create a new platform kind of on that automation theme. We automated a ton of the the things that you need to do to analyze a modern attack chain.
So, you know scanning QR codes clicking through links visiting web pages identifying, you know, weird file formats and all the Optus station that attackers do we did that and kind of one unified place that they could then analyze all the threats that they were that they were seeing and getting reported by their users. So how that fits with Splunk is most 90% of our customers were Splunk customers. They were taking alerts from things like Enterprise security our Sim product.
They were using their sore to send us the rats and so we were already doing a bunch of integration. We had a Splunk store integration connector that we had. And security teams were managing this flow all the way from the alert through the analysis and then the response and so it was a really natural fit when I started talking to some of the Splunk folks about you know what we were doing and what they were doing and just kind of rounds out the portfolio in terms of providing that end-to-end, you know, all the things that a sock needs in order to successfully, you know detect investigate respond to threats.
Right and they got him out, you know a senior management team were a little bit of experience in security to come in and you know help run the whole business. So now you're in charge of you know, kind of the entire security portfolio and you guys make some announcements last week so I know want to tell us a little bit about mission control that seems to me and you correct me if I'm wrong and I'm usually wrong. Um so seems to me that you know, it's finally the, you know, kind of integration of a lot of these pieces that Splunk is tap for a long time.
Not just yes, right, but also sore in in the you know this right Intel side all within up consistent user experience. Did I get that sorta right? You got it a lot, right.
So yeah, it was it's been you know, really the unification of pulling all these pieces together. So we have an industry leading soon. We have a sore we have this great threat Intel and how do we help security teams leverage that in one place again back to that detect.
Investigate and respond, you know set of activities that they need to do without having to go pivot between different applications, you know, having all the context that seamlessly at your fingertips so that you know, when you're investigating an alert, you have all the information of where did what were the events that originated around that alert? What's the contextual information I have for around things like threat Intel. What do I know about the artifacts that we're generated during the investigation so really just giving an analyst to kind of the complete view of things that they need to understand in order to decide what to do next.
Yeah, and and I would imagine, you know, helping them along the path, right and obviously with the skills Gap era Tucker. This goes around, you know, four million jobs are out there. And you know, if you've got kids tell them to do security, they're good, you know assured employment which there may be some truth to that.
But with all the same, right, you know part of the success that you know, we really need to get to you know, moving forward as a security practice is really to help the folks that don't have a lot of that experience, right? You know, we've been in the coal mine for you know decades at this point, right? We kind of know our way around a lot of these things.
We've been a lot of new folks entering the business and we need them right but we need to help them right and and provide I call it technology assisted, you know, kind of detection or technology assisted response not trying to get rid of these folks. We still need these folks, but we have to make them more efficient a lot faster. So I would assume a lot of the integration going on with mission control and Just the whole portfolio is really about you get making these folks a lot more productive than they've been in the past.
Yeah, you hit the nail on the head, which is really how do we help people again understand more quickly not require as much in-depth industry experience in order to start like making good decisions. That was a foundation of some of the work that we did at Twin wave, which I think again is why it appealed the Splunk, you know, we really focused on how do we make this easy for a tier one analyst who's new in career new and job, but then also provide all the rich details that a tier three, you know, I got two decades of experience and I'm looking for you know, the nitty-gritty details. You know, how do you surface both those things at the same time in a way that's usable for both populations, you know the new to role and and the experience folks and that's certainly something that mission control is is designed to help because as you said when you come in you don't want to have to go to three different places.
You don't want to have to understand like hey, where do I get that piece of information? Station you want that already pre-presented to you and all the important bits to be highlighted and and identified and so a huge part of Mission Control and the vision that we have there for the future is to continue to bring more and more of those capabilities and high in that automation. I think you touched on this, you know, it's not just helping them see what's happening.
But now what do I do to respond and so by being able to tie in these response capabilities? So we have sore fully integrated into Mission Control you can start taking these automated response automated or analyst-driven responses. So hey, I've got a take this workstation, you know, I got a quarantine it because I'm concerned that there's maybe ransomware or some piece of malware that got on that machine.
How do I quickly and efficiently do that? Right with all sorts of Integrations right with you know, kind of and and that brings up, you know kind of another another big topic right that I'll hit the third because I do want to make sure we get around to data because that's obviously a huge I don't see impediment but certainly a challenge to tell you guys are animated announcement around there, but I don't want to go there yet, right because what's been interesting and being a long time security professional and and kind of working with with companies for a long time. Right?
It's kind of how we're starting to blur the lines between what had traditionally been a security oriented role. You know, now we've got folks that are kind of security right within a lot of these applications stacks and we've got you know agile, you know kind of environment and really this is kind of where a lot of the intersection of what we get Tech strong focus on you know, kind of how devops and Cloud native infrastructure and security all have to you know, kind of work together in order to you know, really provide a Secure and resilient and scalable Next Generation infrastructure, right? But so it's not just the folks looking at the security screen anymore.
Like we used to you know, kind of know we've got to figure out what's happening. And I think that's a lot of what the observability piece and spunks made a number of Acquisitions over the last, you know, four or five years to kind of get into that business because I mean to me right at data rights of data whether I'm looking for security stuff, whether I'm you know, kind of trying to understand and isolate it performance issues, whether I'm you know, kind of isolating, you know, kind of date issues or transaction issues. I mean all of these things, you know kind of are driven by data, right?
So if you're good at you know handling aggregating, you know kind of normalizing and and then processing and searching data that would seem to be the leverage and you're getting it since you've been back it's bloke a couple of you know a month or so now maybe a couple months if you started to see that where folks are really starting to bring these practices. Other or we still have these silos of you know, kind of those are the app folks and these insecurity books. And yeah, maybe we share the same data, but we don't really like each other and you know kind of we don't share information as much as we should.
Yeah, it's a great point. I think I think it's still early days. You know, I was talking to somebody the other day about what does devsecops mean and what is SEC devops me, you know, which which is which and you know how to all these pieces start to fit together.
I do think you're to the point that you were bringing up. We don't often know at the beginning of an event whether it's a security event or you know, a network or a performance event when a server goes offline is that you know, because somebody is doing something malicious or is that because it you know ran out of memory and something that happened and so I was just talking to the CSO at a big pharmaceutical company and really what he's focused on is resilience, right? How do I introduce resilience into our organization which is really about security and reliability so that we you know, whichever problem it turns out to be that we're able to absorb the shocks that come to the system that could be the shocks from a big attack that could be the shocks that come from, you know, a major spike in activity because we just announced and launch something, you know, they're really all about trying to absorb those shocks.
And you know, I think that's where Splunk really comes to shine is the fact that we have this. Amazing data platform that can consume a ton of data can provide a lot of Rich insights and context and information. One of the things that we announce was our Edge processor.
So that also helps with being able to filter and mask and do routing at the edge. So now you can have a lot more control over. What's the data that you're bringing into into Splunk.
How do you want to leverage and use that data? So really interesting things I think that are happening here and in the market would just create it. All right and one of the frustrating things and it's you know, yeah, I wouldn't say it's Unique to Splunk, but it certainly it's both the hardest earliest was just the explosion of data and based on ingest processing, you know, you had a whole mess of folks that we're in the position of having that basically sell off their first born in order to scale up, you know, kind of their environment which created all sorts of angst and and kind of challenges in terms of and really forced them to get to a point where they're making Is about what data they wanted to aggregate again being an old school security person.
I'm just like no. No, we want all the data all the time because we don't know what we don't know until we know it right so growing a whole bunch of data out seeing a little bit counterproductive. So, you know Edge processor gives me, you know, the ability and make sure I'm characterizing this right, you know to be a little bit more selective and intelligent about you know, what I'm sending up to Splunk what I'm keeping in object storage, you know kind of on my own and I in order to make sure that I can both optimize kind of my monitoring infrastructure yet not necessarily have to make compromises on the amount of data that I'm actually collecting.
So you see that you see some folks that are sending a stream to you know, object storage really for forensics purposes and you know sending a subset of that off to you know, the monitoring platform to give them the insights that they need. Yeah. We we do we definitely do see that and you know, one of the things that you said that really resonates with me is as the security guy, I don't Want to have to decide ahead of time what data I'm in a store.
You know how long I'm going to keep it like we all want all data forever, right and then granted that that's not a reality, you know just doesn't want a lot of things. I don't get most of the things that exactly but yeah, I think that that's the sentiment and so part of what Spontane's been doing whether you look at our workload-based pricing, which is really how are you accessing the data and thinking about consumption differently, so it's not about just ingest but now it's about you know, what are you doing with that data? Hey, if you're just storing it and you don't need to access it very often and not for a long time that you know, it shouldn't be driving up your costs.
And so, you know, I think this is another step forward and and that, you know with Edge processor to be able to again filter out, you know, which is the data is relevant which things should go or should be stored where and then oh, there's a lot of work that we've been doing around Federation and and different announcements that we've made and that you'll see coming up around and how do we deal with data where it lives and and you know handling these diverse different data stores. Yeah. Yeah.
And again, yeah, you know kind of where we're starting to integrate and and let's kind of dig into the resilience thing a little bit because you know and every time somebody brings up a word, you know, like resilience. I To a cold sweat going. Okay.
Now I know what you know, every vendor is gonna be talking about it RSA in a month. All right, you know, it's it's gonna be something along the lines of you know deaf secops and resilience, right so that those could be the early themes that we start to see but you know outside of Pokemon it you know kind of the industry marketing Machinery that you know kind of drives a lot of what we do and I guess I shouldn't, you know bite the hand that feeds me for the most part since we are enough marketing Services role at this point, you know the idea about actually kind of both reliability availability and security being, you know, kind of this concept of you know, kind of a more resilient type of environment again, that's kind of how application folks right that's kind of how it obstacles really think about the world. So to me, although I'm resistant to anything that feels a little overly marketing on that front.
I do think the concept is is you know, Increasingly important because we as security folks can't just sit, you know kind of on the side telling everybody how screwed up everything is right. We actually have to get in we have to engage we have to be productive and we have to add value right? It's starting to align our vernacular I think is really the first steps that we can start talking the language of these Ops folks start talking the language of these, you know developer folks and really get to this mythical day of secops and there's funny you mentioned have off because you can always tell whether it was a security person that came up with that because they always start right they have Ops, right, you know, and the fact that it's not devops and security kind of somewhere out there like, you know, two or three miles away, you know, that's gonna be how it how it works out but we did manage to get it right in the middle.
So, you know directionally that seems to be, you know, kind of the right place to be yeah. Yeah, and you know, I think that we've insecurity have been doing Billions for decades right? We just didn't maybe we didn't call it that but if you think about what we've been doing in terms of protecting organizations, if you think about all the things that that happen like hey, if there's you know, I backup systems in place.
Do I have patching in place? So I have all these different pieces in place that I can again be resilient in the face of a changing threat landscape. Like I think it's so baked into what we do and how we think that we don't even think about it as a as a term because it's like oh, of course you've got to be resilient because look at how the attack landscape is constantly changing and you know, we can't be ready for yesterday's attack.
We have to be preparing for tomorrow's attack. And so I think I think resilience is just kind of in our nature and so it's interesting to see, you know, more coalescing around around this world and this word and as you mentioned, you know what I think in it, we kind of have a sense of what that means I think about it is survivability adaptability, right? So which are again two key elements of what we do and security.
You know, how do I help the organization adapt to changes in the threat landscape? How do I help them survive in the face of some sort of a attack? And so, you know, I like to I like to think that they're coming to us rather than we're going to them.
You know, so I'll tune that a little bit in that most security folks never really thought about stuff within the context of the business. And the reason the word is kind of important is because it forces you to think about you know resilience thing is not just you know, hey, make sure my stuff doesn't end up in a dark website in chechnya. Right?
I mean it really is about making sure that you can be there to support and add value to your customers. And and I think that framing is actually really important for most security folks that you know, again just get caught up in the you know, I'm a good side and they're the bad side and we're gonna fight, you know kind of the evil all day. It's just like yeah that's important.
But only to be able to serve customers, right? You know, if you're not worried about serving customers that you're really worried about yourself showing up the church here, maybe not. I don't know right.
So he you know, I like the framing of Brazilians from from that standpoint. But again a lot of it gets back to Right, you know what are the value that we're bringing from a lot of these different things and and now that we've got, you know, what looks to be whether it's a full-on, you know kind of Disconnect whether it's you know, kind of a true Global recession whether it's you know, just a slow down we're all in a position that we've got a kind of prove our Wares the little bit more effectively. So when you sit with a big customer, how do you kind of say this is how we're at Splunk adding value, you know, what you do to pay off again the crap ton of money.
I got to spend the store all my data and get the insights that I need from it. Yeah, that's a really good point and and it does all come back to the business because at the end of the day and customers, right? That's who we're serving.
We're serving customers and those customers are serving the businesses that they that they live within and I think that's really where it comes back to things. Like, you know, how do we prove that value? That's where Innovations like what we're doing with mission control the updates to observability Cloud, you know.
Edge processor we're constantly innovating and trying to help make sure that we're staying in lockstep with what the customers are telling us that they need and I'm super you know, the entrepreneur and in me is always like hey, we've got to show value every day, right? We've got to go out and and prove that and that certainly part of the ethos that I bring to to the security the role here at Splunk, you know, I think you're gonna see us continue to really focus on delivering value integrating. How do we bring that unified experience, you know back to you know, people need to do some core set of things in order to support the business.
How do we help them do that more efficiently, which is one of the reasons. I'm just so excited to be here. It's been it's been amazing meeting, you know, all the Splunk customers and partners and all of our splunkers here.
There's just so much energy and passion for helping solve these kinds of problems that it's just been a ton of fun. Well good. That's fantastic.
Well, let's Mike really great to see you. First of all, really appreciate, you know kind of the time you spent with us Tech strong TV, um today, so, yeah. So again my corn GM of splunks Enterprise, and I guess when we just security business, I guess this belong security business on that front here to talk about a couple of the recent announcements Mission Control some observability capabilities and Edge processor.
So once again my really appreciate the time, thank you very much. My pleasure. Thank you so much.
All right. Let's go back to the studio for our next interview.