No compromise undetected
DKB’s teams improved network security by accelerating alert response; before, there were simply too many alerts to keep up with, and they were decentralized too, which meant delays and missed alerts. “In the past, we searched through log files to look for network issues, but it was time-intensive, and it was easy to miss alerts. Now that we have all components of our infrastructure connected to Splunk as our SIEM, there’s a lot of different activities inside network security that are quickly visible and in a centralized, correlated database,” says Hennich. “In the case of compromise, we can see the alerts more quickly and react faster.”
When it comes to actual threats, DKB has reduced investigation and resolution time by 90%, Hennich reports. “Before Splunk, we had to search different log files, search additional data, write search queries and more. But it’s so much faster with Splunk.”