下载PDF
From legacy onprem to a modern cloud SIEM
技术
- 网络安全和隐私 - 安全合规
- 分析与建模 - 预测分析
适用行业
- 建筑与基础设施
适用功能
- 商业运营
用例
- 欺诈识别
服务
- 云规划/设计/实施服务
- 网络安全服务
- 系统集成
挑战
Running an inefficient SIEM solution left Knauf’s SOC team unable to scale at the same pace as company growth. As a business in operation since 1932, Knauf’s IT infrastructure had expanded through the years, becoming a large, legacy on-premises environment with decentralized SCADA systems, production tools, and many regional locations. Knauf was running McAfee Enterprise Security Manager (ESM) on-premises for their SIEM solution to gain real-time security monitoring of the extended environment. But the McAfee solution was unreliable. Dawid Krochmal, SOC Manager at Knauf, explained that “McAfee ESM was highly inefficient. An analyst wouldn’t just go for a coffee; he could go to lunch during the time it took for a query to run. Just to learn that after an hour, the query had an error, and he had to start again and wait another hour.”
关于客户
Knauf is a well-established company that has been in operation since 1932. Over the years, its IT infrastructure has grown significantly, resulting in a large, legacy on-premises environment. This environment includes decentralized SCADA systems, production tools, and numerous regional locations. The company had been using McAfee Enterprise Security Manager (ESM) on-premises for their SIEM solution to gain real-time security monitoring of their extended environment. However, the McAfee solution proved to be unreliable and inefficient, causing significant delays and operational challenges for the SOC team. As Knauf continued to grow rapidly, it became clear that a more efficient and scalable solution was needed to keep pace with the company's expansion and evolving security needs.
解决方案
McAfee ESM wasn’t serving the company’s needs, and in parallel, Knauf was growing rapidly and wanted to pursue a significant transformation of its IT environment. The goal was to move away from legacy, on-premises systems to a cloud-native architecture that enabled Knauf’s IT security and operations to run more efficiently, effectively and smoothly. Pursuing a cloud-native strategy for the company’s new SIEM solution, Knauf conducted an in-depth evaluation of ten vendor solutions and selected Sumo Logic Cloud SIEM as its winning security platform. The SOC team’s first big win with Cloud SIEM was the ability to centrally see everything across the organization’s environment and user-friendly features, including more than 600 out-of-the-box rules. That made it easy for the security team to ramp up and get started within two hours. Cloud SIEM delivers significant improvement for the SOC team in handling threat investigations. With the solution’s cloud-native architecture, the team no longer has to worry about disc space for log ingestion or latency in obtaining search results. With Cloud SIEM’s advanced analytics, Knauf gets millions of threat signals distilled down to insights for the SOC team to focus on.
运营影响
数量效益
相关案例.
Case Study
IoT System for Tunnel Construction
The Zenitaka Corporation ('Zenitaka') has two major business areas: its architectural business focuses on structures such as government buildings, office buildings, and commercial facilities, while its civil engineering business is targeted at structures such as tunnels, bridges and dams. Within these areas, there presented two issues that have always persisted in regard to the construction of mountain tunnels. These issues are 'improving safety" and "reducing energy consumption". Mountain tunnels construction requires a massive amount of electricity. This is because there are many kinds of electrical equipment being used day and night, including construction machinery, construction lighting, and ventilating fan. Despite this, the amount of power consumption is generally not tightly managed. In many cases, the exact amount of power consumption is only ascertained when the bill from the power company becomes available. Sometimes, corporations install demand-monitoring equipment to help curb the maximum power demanded. However, even in these cases, the devices only allow the total volume of power consumption to be ascertained, or they may issue warnings to prevent the contracted volume of power from being exceeded. In order to tackle the issue of reducing power consumption, it was first necessary to obtain an accurate breakdown of how much power was being used in each particular area. In other words, we needed to be able to visualize the amount of power being consumed. Safety, was also not being managed very rigorously. Even now, tunnel construction sites often use a 'name label' system for managing entry into the work site. Specifically, red labels with white reverse sides that bear the workers' names on both sides are displayed at the tunnel work site entrance. The workers themselves then flip the name label to the appropriate side when entering or exiting from the work site to indicate whether or not they are working inside the tunnel at any given time. If a worker forgets to flip his or her name label when entering or exiting from the tunnel, management cannot be performed effectively. In order to tackle the challenges mentioned above, Zenitaka decided to build a system that could improve the safety of tunnel construction as well as reduce the amount of power consumed. In other words, this new system would facilitate a clear picture of which workers were working in each location at the mountain tunnel construction site, as well as which processes were being carried out at those respective locations at any given time. The system would maintain the safety of all workers while also carefully controlling the electrical equipment to reduce unnecessary power consumption. Having decided on the concept, our next concern was whether there existed any kind of robust hardware that would not break down at the construction work site, that could move freely in response to changes in the working environment, and that could accurately detect workers and vehicles using radio frequency identification (RFID). Given that this system would involve many components that were new to Zenitaka, we decided to enlist the cooperation of E.I.Sol Co., Ltd. ('E.I.Sol') as our joint development partner, as they had provided us with a highly practical proposal.
Case Study
Splunk Partnership Ties Together Big Data & IoT Services
Splunk was faced with the need to meet emerging customer demands for interfacing IoT projects to its suite of services. The company required an IoT partner that would be able to easily and quickly integrate with its Splunk Enterprise platform, rather than allocating development resources and time to building out an IoT interface and application platform.
Case Study
Bridge monitoring in Hamburg Port
Kattwyk Bridge is used for both rail and road transport, and it has played an important role in the Port of Hamburg since 1973. However, the increasing pressure from traffic requires a monitoring solution. The goal of the project is to assess in real-time the bridge's status and dynamic responses to traffic and lift processes.
Case Study
Bellas Landscaping
Leading landscaping firm serving central Illinois streamlines operations with Samsara’s real-time fleet tracking solution: • 30+ vehicle fleet includes International Terrastar dump trucks and flatbeds, medium- and light-duty pickups from Ford and Chevrolet. Winter fleet includes of snow plows and salters.
Case Study
Condition Based Monitoring for Industrial Systems
A large construction aggregate plant operates 10 high horsepower Secondary Crusher Drive Motors and associated conveyor belts, producing 600 tons of product per hour. All heavy equipment requires maintenance, but the aggregate producer’s costs were greatly magnified any time that the necessary maintenance was unplanned and unscheduled. The product must be supplied to the customers on a tight time schedule to fulfill contracts, avoid penalties, and prevent the loss of future business. Furthermore, a sudden failure in one of the drive motors would cause rock to pile up in unwanted locations, extending the downtime and increasing the costs.Clearly, preventative maintenance was preferable to unexpected failures. So, twice each year, the company brought in an outside vendor to attach sensors to the motors, do vibration studies, measure bearing temperatures and attempt to assess the health of the motors. But that wasn’t enough. Unexpected breakdowns continued to occur. The aggregate producer decided to upgrade to a Condition Based Monitoring (CBM) sensor system that could continually monitor the motors in real time, apply data analytics to detect changes in motor behavior before they developed into major problems, and alert maintenance staff via email or text, anywhere they happened to be.A wired sensor network would have been cost prohibitive. An aggregate plant has numerous heavy vehicles moving around, so any cabling would have to be protected. But the plant covers 400 acres, and the cable would have to be trenched to numerous locations. Cable wasn’t going to work. The aggregate producer needed a wireless solution.