Services

Deep in a narrow stack, on purpose.

Everyone at KEOS holds the highest level of Splunk technical certification — not just the few. Everyone! KEOS is who you call when you need Splunk expertise above beyond a generalist

01 / Security products

Detections that survive contact with a SOC.

Where KEOS engineers spend most of their time — SIEM migrations, fresh installs, and security stacks that are not living up to their potential.

Splunk ES

Enterprise Security

Splunk's SIEM, and a product that has added real capability year over year. Every customer should be making full use of risk-based alerting, data modeling, and machine learning. Most are not.

Risk-based alerting

Fewer alerts, better ones

Rather than one detection firing something your SOC must look at now, RBA scores behavior across a wide set of users and entities. False positives fall away and genuinely concerning patterns rise to the top. An absolute must in ES 8.x — KEOS enables the framework and write your custom alerts.

Anomaly detection

No more magic numbers

Detections should not contain arbitrary thresholds. if (num_failed_logins > 3) — what is special about three? Nothing, and that alert will generate thousands of false positives. The tools to do it properly ship in the box with SPL and MLTK. Using them well is a different matter.

Splunk SOAR

Automation worth trusting

The out-of-the-box playbooks are inspiration, not production. The playbooks worth building are the ones you find by watching your own analysts repeat the same task. KEOS implements them in Python.

Datamodels

The Datamodel Dictionary

Datamodels are Splunk's crown jewel and the reason you can search enormous volumes in seconds. Out of the box they do not populate, and defaults need changing per customer. KEOS maintains a field repository that maps your datamodels to your log sources — so they keep working, and so your team can write their own tstats searches.

Splunk UEBA

User & entity behavior

Splunk's unsung hero. Underneath sits a sophisticated set of ML models that must be trained on a lot of data before they detect anything. Powerful, and genuinely difficult to stand up.

AI & machine learning

AI in the detection, not the pitch deck

In most security marketing "AI" is a label. In practice it is specific models doing specific jobs: baselining what an entity normally does, scoring risk across a window of behavior instead of a single event, and surfacing the few sequences worth an analyst's attention.

KEOS combines Splunk's machine learning toolkit with risk-based alerting to raise alert fidelity rather than alert volume — and KEOS developed that approach on their own rather than buying it. The same scoring drives remediation: once a detection is trustworthy enough to act on, it can hand off to a SOAR playbook instead of a human.

Cisco AND SPLUNK AI

Agentic SOC, AIOps and Data Fabric

Thanks to KEOS' elite status with Cisco and Splunk, KEOS has had access to advanced technologies before most companies have heard of them. These technologies and products are game changers. Evert Splunk (and non-Splunk) customer needs to see the latest and greatest. Not just in slideware. Actual demonstrations of the products.

What we don't do

The rest of the Cisco line

In regards to Cisco products, KEOS supports XDR, ThousandEyes and Cisco log ingestion into Splunk.


02 / IT operations products

Getting data in is less a skill than an art form.

Every customer monitors the health of their own infrastructure. The challenge is getting the data into the platform and reporting problems before they become outages.

AI & machine learning

Adaptive thresholds and predicted failures

A static threshold is wrong in both directions. It pages someone at 3am for a spike that did not matter, and it stays silent through the slow drift that did. Adaptive thresholding learns what normal looks like for each service — by hour, by day of week — and alerts on departure from that rather than on a number somebody typed in years ago.

The same models run forward. Watching saturation, error-rate drift, and dependencies degrading lets us flag a service trending toward failure while there is still time to do something about it. That is the honest version of prediction: catching the failure modes that announce themselves, not the novel ones nobody sees coming.

Splunk Observability Cloud

Where most of our training goes

More Keos training hours go into Observability Cloud than any other Splunk product. Full-stack tracing, metrics, and real-user monitoring built on OpenTelemetry, and it does things ITSI was never designed to do.

It is also complicated enough that professional services are not really optional.

AppDynamics

AppDynamics or Observability Cloud?

Our consultants hold AppDynamics certifications, which matters less for the deployment work than for the question that comes before it: which of the two platforms should be watching which part of your estate.

That decision is genuinely complicated. The products overlap, they overlap differently depending on what you are running, and both vendors have an answer ready. We do not sell either one, so we can work through it with you on the technical merits and tell you plainly where each belongs and what to anticipate going forward.

Splunk ITSI

IT Service Intelligence

Splunk's first premium IT Operations product, effectively rewritten in recent years. Today it is capable and full-featured — and very complicated to set up and run. ITSI is a platform. Wonderfully versatile and customizable with KEOS services.

Splunk Cloud

Migration since day one

We have been migrating customers to Splunk Cloud since Splunk Cloud existed. Two jobs sit inside every migration: getting logs in, and getting knowledge objects over. Not everyone chooses Splunk Cloud. KEOS supports ALL of Splunk's products, either on-prem or in the cloud.

Splunk MLTK

Machine learning toolkit

MLTK has been sitting in the shadows for over a decade, and only in the AI era are customers noticing what it can do. It is complicated, and typically needs services..

Edge Processor

Pipeline control

Splunk has made several attempts at a Cribl competitor; Edge Processor is the current one. And it appears to be successful, KEOS has instrumented it successfully Edge and Cribl for several large customers.

Kubernetes & AWS

Container and cloud plumbing

Getting container logs into Splunk, and continerizing Splunk itself. KEOS mostly use AWS services to move data and manage forwarder deployment. Note: KEOS consultants hold AWS , Azure and Google CLoud certifications.

Microsoft

Sentinel, O365, Azure

Usually this means writing Python or Event Hub functions to get Microsoft data into Splunk. KEOS has worked with Sentinel, O365, Azure, Event Hub, Blob storage, and Defender for ingestion.

03 / Architecture & platform

See the big picture before the capital expenditure.

Every customer environment is different. KEOS works with you to understand the whole shape and size before you commit to infrastructure changes or a large capital spend.

01
Security detections and remediations

Migrating between SIEMs, standing one up fresh, or fixing a stack that is not living up to its potential.

02
Machine learning for detection and analytics

Marketed everywhere as "AI." Machine learning is the part that actually produces results — modeling behavior and alerting on genuine anomalies.

03
Troubleshooting

Cisco and Splunk products are not self-sustaining. The good news is that issues are almost never unique — we have very likely seen yours before.

04
Health checks

A report on what is actually wrong and why, for customers who do not know what they do not know. One to two weeks, ending in causes rather than symptoms. It is also the cheapest way to find out whether a platform you are frustrated with is really the problem — more than one customer has come to us intending to migrate and stayed instead.

05
Threat intelligence

Most security customers already have a feed. If you do not, KEOS will walk you through the trade-offs between suppliers. Then KEOS will get it into ES and SOAR, where it materially changes risk scoring and remediation.

06
Proof of concept

Before a major outlay it is worth watching the product perform against your objectives. This is not a sales motion. It is your chance to find out whether the thing does what you were told it does.

07
Detection as Code

Shared Splunk environments drift out of control once enough teams use them. Detection as Code started as an internal Splunk skunkworks project and was made commercially available by KEOS. It lets you govern the environment with the DevOps tooling you already run.

08
Reduce license cost

Splunk bills on ingestion, SVC usage, activity, seats and more. Confused? We recommend tuning the stack at least annually — the tuning frequently pays for itself out of the reduced license fee.

09
IT operations detections and remediations

Predictive reporting on infrastructure and services, built on a broad set of proven techniques for getting data in.

10
High availability and disaster recovery

Splunk Cloud gives you this out of the box. Customer-managed stacks do not — nor does the equipment feeding data into Cloud.

11
Audit preparation

Splunk ships no suite of detections that will pass a security audit, and never could — every environment differs. KEOS is called in before audits to find gaps and write coverage, and sometimes after a failed one.

Give us the objective, not the shopping list.

Send your environment and what you are trying to achieve. You will get a technical answer about what the work actually is.