E-commerce retailer / Security
The insider they could not see
One of KEOS' first customers, a large brand-name online retailer, had just been breached by a disgruntled former employee and needed internal detections. KEOS reviewed the existing log sources, installed and configured Splunk ES, and wrote detections aimed squarely at insider activity.
Log data was plentiful — badge access and authentication among it. ES was a relatively new product then, so getting datamodels to populate and dashboards to build was the real work. KEOS built the ES identity lookup tables from HR data covering current and former staff.
Delivered on time and on budget. The customer could now see that a former employee had exfiltrated data, and could be confident any repeat attempt would be caught immediately.
Email provider / Security
KEOS found the breach before KEOS finished the install
One of the largest email providers in the world licensed Splunk ES and asked KEOS to install and
configure the product. Unknown to them, they had already been breached and had lost customer data tied to
email accounts. The attackers had deleted audit trails on the way out.
Before KEOS had finished the tasks KEOS was hired for, KEOS was turning up bread crumbs the attackers had not managed to erase.
The customer was soon using the new SIEM to understand the true scale of the problem. KEOS completed the ES installation and built the detections that have prevented any successful attempt since.
Electronics retailer / IT operations
Millions per minute of downtime, predicted away
A large public California company selling consumer electronics, running multi-petabyte internal operations. If any one of their online services went down, they lost millions of dollars of revenue per minute. Uptime was not a nice-to-have.
KEOS worked alongside their own engineers to predict service failures before they could affect business operations.
The largest successful deployment of Splunk IT operational modeling on record.
Social media / Splunk Cloud migration
Petabytes moved, with exactly one attempt
One of the largest social media companies decided to move from on-premise to Splunk Cloud, and called KEOS in to migrate petabytes of historical buckets.
Before any of that could start there had to be a plan every internal department agreed on — security, netops, itops. KEOS wrote the operational plan, wrote the scripts that automated bucket movement, and reconfigured every existing source to send to Cloud.
The operation had one chance to land. It landed — largely because of how much planning and coordination went in before anyone touched a system.
Credit card / Regulatory compliance
Compliance evidence trapped on a mainframe
A large credit card company needed to satisfy government auditing requirements. Financial firms routinely have to evidence compliance against various standards, and this customer was no exception. The problem was that the log data Splunk needed was sitting on mainframes.
KEOS worked with the customer to get that data into Splunk, then wrote the searches that demonstrated compliance.
Along the way the customer realized the same data could detect fraud and money laundering. That was never in the original scope — KEOS stayed on to help build it.
Banking / Staff augmentation, IT operations
The contractor the largest US bank did not fire
The largest bank in the United States retained our engineers to manage a set of ultra-large Splunk stacks. This customer had fired roughly as many contractors as it had hired in the years
before working with KEOS.
The turnover came down to scale and to the bank's own proprietary automation tooling. Those tools are not publicly available and there is no class or training any consultant can take.
KEOS engineers learned the proprietary tools on the job. The most valuable consultant is the one who can pick up
an unfamiliar environment quickly. Hence KEOS was retained.
Wholesale / AI / MLTK, security operations
Risk-based alerting with the machine learning toolkit
The nation's largest grocery wholesaler retained KEOS to write Splunk security detections.
KEOS combined Splunk's machine learning toolkit with risk-based alerting to build mechanisms that accurately identify bad actors, rather than simply generating more alerts.
Alert fidelity went up materially. This approach — branded as AI security — is now in high demand, and KEOS is its author and developer.
Higher education / Platform evaluation
A bake-off run on their own data
A state university was weighing Splunk Cloud and Enterprise Security against Google Chronicle, and getting the usual answer from both vendors: a datasheet.
KEOS ran a proof of value instead — the university's own logs, through both platforms, side by side. The migration plan came out of the POV rather than being written afterward to justify it.
The technical answer was settled before procurement ever opened the conversation.
Enterprise / Platform evaluation
Where Elastic stops scaling
Elastic works right up until it doesn't. The JVM architecture struggles at genuine enterprise volume, and the price climbs steeply once the introductory term lapses.
KEOS ran the comparison against the customer's real ingest rather than a benchmark, so the ceiling was visible up front instead of eighteen months in, after the migration had already been paid for.
Better to find the wall during an evaluation than during an incident.
Multi-cloud / Platform evaluation
Sentinel, and the multi-cloud problem
Microsoft Sentinel is comfortable inside Azure and considerably less so outside it. KQL is also a narrower language than SPL once correlation gets ambitious.
For a multi-cloud estate KEOS mapped exactly where those two limits would bite, on the customer's own architecture rather than in the abstract.
The work became an architecture remediation engagement rather than a migration nobody wanted.
Cruise line / Health check
The Splunk they had decided to abandon
Performance had degraded so badly that the customer had already made the call to migrate off Splunk entirely. KEOS was asked to run a health check before the customer left the Splunk platform.
The platform was not the problem. What KEOS found was fixable, and considerably cheaper to fix than to replace.
The customer stayed, and signed a three-year renewal instead of running a migration.
Federal agency / License optimization
When ingest pricing became workload pricing
A heavily utilized federal deployment came under real cost pressure when Splunk moved from ingest-based to workload-based pricing. The same estate, priced on a different axis, suddenly looked very different.
KEOS tuned the stack against the new model — what runs, how often, and how much of it needed to.
Cost pressure handled as an engineering problem rather than a negotiation.
Utility provider / Use case development
A large license and nothing detecting
The customer had bought plenty of Splunk and could not get Enterprise Security to surface threats worth acting on. That is a common place to be stuck, and it is almost never a capacity problem.
The gap was use cases. KEOS ran a security workshop to find which detections actually mattered for their environment, then built them.
ES started earning its place before anyone discussed buying more of it.