Deep in a narrow stack, on purpose.
Everyone at KEOS holds the highest level of Splunk technical certification — not just the few. Everyone! KEOS is who you call when you need Splunk expertise above beyond a generalist
Detections that survive contact with a SOC.
Where KEOS engineers spend most of their time — SIEM migrations, fresh installs, and security stacks that are not living up to their potential.
Enterprise Security
Splunk's SIEM, and a product that has added real capability year over year. Every customer should be making full use of risk-based alerting, data modeling, and machine learning. Most are not.
Fewer alerts, better ones
Rather than one detection firing something your SOC must look at now, RBA scores behavior across a wide set of users and entities. False positives fall away and genuinely concerning patterns rise to the top. An absolute must in ES 8.x — KEOS enables the framework and write your custom alerts.
No more magic numbers
Detections should not contain arbitrary thresholds. if (num_failed_logins > 3) — what is special about three? Nothing, and that alert will generate thousands of false positives. The tools to do it properly ship in the box with SPL and MLTK. Using them well is a different matter.
Automation worth trusting
The out-of-the-box playbooks are inspiration, not production. The playbooks worth building are the ones you find by watching your own analysts repeat the same task. KEOS implements them in Python.
The Datamodel Dictionary
Datamodels are Splunk's crown jewel and the reason you can search enormous volumes in seconds. Out of the box they do not populate, and defaults need changing per customer. KEOS maintains a field repository that maps your datamodels to your log sources — so they keep working, and so your team can write their own tstats searches.
User & entity behavior
Splunk's unsung hero. Underneath sits a sophisticated set of ML models that must be trained on a lot of data before they detect anything. Powerful, and genuinely difficult to stand up.
AI in the detection, not the pitch deck
In most security marketing "AI" is a label. In practice it is specific models doing specific jobs: baselining what an entity normally does, scoring risk across a window of behavior instead of a single event, and surfacing the few sequences worth an analyst's attention.
KEOS combines Splunk's machine learning toolkit with risk-based alerting to raise alert fidelity rather than alert volume — and KEOS developed that approach on their own rather than buying it. The same scoring drives remediation: once a detection is trustworthy enough to act on, it can hand off to a SOAR playbook instead of a human.
Agentic SOC, AIOps and Data Fabric
Thanks to KEOS' elite status with Cisco and Splunk, KEOS has had access to advanced technologies before most companies have heard of them. These technologies and products are game changers. Evert Splunk (and non-Splunk) customer needs to see the latest and greatest. Not just in slideware. Actual demonstrations of the products.
The rest of the Cisco line
In regards to Cisco products, KEOS supports XDR, ThousandEyes and Cisco log ingestion into Splunk.
Getting data in is less a skill than an art form.
Every customer monitors the health of their own infrastructure. The challenge is getting the data into the platform and reporting problems before they become outages.
Adaptive thresholds and predicted failures
A static threshold is wrong in both directions. It pages someone at 3am for a spike that did not matter, and it stays silent through the slow drift that did. Adaptive thresholding learns what normal looks like for each service — by hour, by day of week — and alerts on departure from that rather than on a number somebody typed in years ago.
The same models run forward. Watching saturation, error-rate drift, and dependencies degrading lets us flag a service trending toward failure while there is still time to do something about it. That is the honest version of prediction: catching the failure modes that announce themselves, not the novel ones nobody sees coming.
Where most of our training goes
More Keos training hours go into Observability Cloud than any other Splunk product. Full-stack tracing, metrics, and real-user monitoring built on OpenTelemetry, and it does things ITSI was never designed to do.
It is also complicated enough that professional services are not really optional.
AppDynamics or Observability Cloud?
Our consultants hold AppDynamics certifications, which matters less for the deployment work than for the question that comes before it: which of the two platforms should be watching which part of your estate.
That decision is genuinely complicated. The products overlap, they overlap differently depending on what you are running, and both vendors have an answer ready. We do not sell either one, so we can work through it with you on the technical merits and tell you plainly where each belongs and what to anticipate going forward.
IT Service Intelligence
Splunk's first premium IT Operations product, effectively rewritten in recent years. Today it is capable and full-featured — and very complicated to set up and run. ITSI is a platform. Wonderfully versatile and customizable with KEOS services.
Migration since day one
We have been migrating customers to Splunk Cloud since Splunk Cloud existed. Two jobs sit inside every migration: getting logs in, and getting knowledge objects over. Not everyone chooses Splunk Cloud. KEOS supports ALL of Splunk's products, either on-prem or in the cloud.
Machine learning toolkit
MLTK has been sitting in the shadows for over a decade, and only in the AI era are customers noticing what it can do. It is complicated, and typically needs services..
Pipeline control
Splunk has made several attempts at a Cribl competitor; Edge Processor is the current one. And it appears to be successful, KEOS has instrumented it successfully Edge and Cribl for several large customers.
Container and cloud plumbing
Getting container logs into Splunk, and continerizing Splunk itself. KEOS mostly use AWS services to move data and manage forwarder deployment. Note: KEOS consultants hold AWS , Azure and Google CLoud certifications.
Sentinel, O365, Azure
Usually this means writing Python or Event Hub functions to get Microsoft data into Splunk. KEOS has worked with Sentinel, O365, Azure, Event Hub, Blob storage, and Defender for ingestion.
See the big picture before the capital expenditure.
Every customer environment is different. KEOS works with you to understand the whole shape and size before you commit to infrastructure changes or a large capital spend.
Migrating between SIEMs, standing one up fresh, or fixing a stack that is not living up to its potential.
Marketed everywhere as "AI." Machine learning is the part that actually produces results — modeling behavior and alerting on genuine anomalies.
Cisco and Splunk products are not self-sustaining. The good news is that issues are almost never unique — we have very likely seen yours before.
A report on what is actually wrong and why, for customers who do not know what they do not know. One to two weeks, ending in causes rather than symptoms. It is also the cheapest way to find out whether a platform you are frustrated with is really the problem — more than one customer has come to us intending to migrate and stayed instead.
Most security customers already have a feed. If you do not, KEOS will walk you through the trade-offs between suppliers. Then KEOS will get it into ES and SOAR, where it materially changes risk scoring and remediation.
Before a major outlay it is worth watching the product perform against your objectives. This is not a sales motion. It is your chance to find out whether the thing does what you were told it does.
Shared Splunk environments drift out of control once enough teams use them. Detection as Code started as an internal Splunk skunkworks project and was made commercially available by KEOS. It lets you govern the environment with the DevOps tooling you already run.
Splunk bills on ingestion, SVC usage, activity, seats and more. Confused? We recommend tuning the stack at least annually — the tuning frequently pays for itself out of the reduced license fee.
Predictive reporting on infrastructure and services, built on a broad set of proven techniques for getting data in.
Splunk Cloud gives you this out of the box. Customer-managed stacks do not — nor does the equipment feeding data into Cloud.
Splunk ships no suite of detections that will pass a security audit, and never could — every environment differs. KEOS is called in before audits to find gaps and write coverage, and sometimes after a failed one.
Give us the objective, not the shopping list.
Send your environment and what you are trying to achieve. You will get a technical answer about what the work actually is.