E-commerce retailer / Security
The insider they could not see
One of our first customers, a large brand-name online retailer, had just been breached by a
disgruntled former employee and needed internal detections. We reviewed the existing log sources,
installed and configured Splunk ES, and wrote detections aimed squarely at insider activity.
Log data was plentiful — badge access and authentication among it. ES was a relatively new
product then, so getting datamodels to populate and dashboards to build was the real work. We
built the ES identity lookup tables from HR data covering current and former staff.
Delivered on time and on budget. The customer could now see that a former employee had
exfiltrated data, and could be confident any repeat attempt would be caught immediately.
Email provider / Security
We found the breach before we finished the install
One of the largest email providers in the world licensed Splunk ES and asked us to install and
configure it. Unknown to them, they had already been breached and had lost customer data tied to
email accounts. The attackers had deleted audit trails on the way out.
Before we had finished the tasks we were actually hired for, we were turning up bread crumbs
the attackers had not managed to erase.
The customer was soon using the new SIEM to understand the true scale of the problem. We
completed the ES installation and built the detections that have prevented any successful
attempt since.
Electronics retailer / IT operations
Millions per minute of downtime, predicted away
A large public California company selling consumer electronics, running multi-petabyte
internal operations. If any one of their online services went down, they lost millions of dollars
of revenue per minute. Uptime was not a nice-to-have.
We worked alongside their own engineers to predict service failures before they could affect
business operations.
The largest successful deployment of Splunk IT operational modeling on record.
Social media / Splunk Cloud migration
Petabytes moved, with exactly one attempt
One of the largest social media companies decided to move from on-premise to Splunk Cloud, and
called us in to migrate petabytes of historical buckets.
Before any of that could start there had to be a plan every internal department agreed on —
security, netops, itops. We wrote the operational plan, wrote the scripts that automated bucket
movement, and reconfigured every existing source to send to Cloud.
The operation had one chance to land. It landed — largely because of how much planning and
coordination went in before anyone touched a system.
Credit card / Regulatory compliance
Compliance evidence trapped on a mainframe
A large credit card company needed to satisfy government auditing requirements. Financial
firms routinely have to evidence compliance against various standards, and this customer was no
exception. The problem was that the log data Splunk needed was sitting on mainframes.
We worked with the customer to get that data into Splunk, then wrote the searches that
demonstrated compliance.
Along the way the customer realized the same data could detect fraud and money laundering.
That was never in the original scope — we stayed on to help build it.
Banking / Staff augmentation, IT operations
The contractor the largest US bank did not fire
The largest bank in the United States retained our engineers to manage a set of ultra-large
Splunk stacks. This customer had fired roughly as many contractors as it had hired in the years
before working with us.
The turnover came down to scale and to the bank's own proprietary automation tooling. Those
tools are not publicly available and there is no class or training any consultant can take.
Our engineers learned them on the job. The most valuable consultant is the one who can pick up
an unfamiliar environment quickly — that is the whole skill.
Wholesale / AI / MLTK, security operations
Risk-based alerting with the machine learning toolkit
The nation's largest grocery wholesaler retained us to write Splunk security detections.
We combined Splunk's machine learning toolkit with risk-based alerting to build mechanisms
that accurately identify bad actors, rather than simply generating more alerts.
Alert fidelity went up materially. This approach — branded as AI security — is now in high
demand, and Keos is its author and developer.
Higher education / Platform evaluation
A bake-off run on their own data
A state university was weighing Splunk Cloud and Enterprise Security against Google Chronicle, and getting the usual answer from both vendors: a datasheet.
We ran a proof of value instead — the university's own logs, through both platforms, side by side. The migration plan came out of the POV rather than being written afterward to justify it.
The technical answer was settled before procurement ever opened the conversation.
Enterprise / Platform evaluation
Where Elastic stops scaling
Elastic looks inexpensive right up until it doesn't. The JVM architecture struggles at genuine enterprise volume, and the price climbs steeply once the introductory term lapses.
We ran the comparison against the customer's real ingest rather than a benchmark, so the ceiling was visible up front instead of eighteen months in, after the migration had already been paid for.
Better to find the wall during an evaluation than during an incident.
Multi-cloud / Platform evaluation
Sentinel, and the multi-cloud problem
Microsoft Sentinel is comfortable inside Azure and considerably less so outside it. KQL is also a narrower language than SPL once correlation gets ambitious.
For a multi-cloud estate we mapped exactly where those two limits would bite, on the customer's own architecture rather than in the abstract.
The work became an architecture remediation engagement rather than a migration nobody wanted.
Cruise line / Health check
The Splunk they had decided to abandon
Performance had degraded so badly that the customer had already made the call to migrate off Splunk entirely. We asked to run a health check before they started.
The platform was not the problem. What we found was fixable, and considerably cheaper to fix than to replace.
They stayed, and signed a three-year renewal instead of running a migration.
Federal agency / License optimization
When ingest pricing became workload pricing
A heavily utilized federal deployment came under real cost pressure when Splunk moved from ingest-based to workload-based pricing. The same estate, priced on a different axis, suddenly looked very different.
We tuned the stack against the new model — what runs, how often, and how much of it needed to.
Cost pressure handled as an engineering problem rather than a negotiation.
Utility provider / Use case development
A large license and nothing detecting
The customer had bought plenty of Splunk and could not get Enterprise Security to surface threats worth acting on. That is a common place to be stuck, and it is almost never a capacity problem.
The gap was use cases. We ran a security workshop to work out which detections actually mattered for their environment, then built them.
ES started earning its place before anyone discussed buying more of it.