We just sent you a verification email. Please verify your account to gain access to
Cloud AWS re:Invent Coverage. If you don’t think you received an email check your
spam folder.
In order to sign in, enter the email address you used to registered for the event. Once completed, you will receive an email with a verification link. Open this link to automatically sign into the site.
Register For Cloud AWS re:Invent Coverage
Please fill out the information below. You will recieve an email with a verification link confirming your registration. Click the link to automatically sign into the site.
You’re almost there!
We just sent you a verification email. Please click the verification button in the email. Once your email address is verified, you will have full access to all event content for Cloud AWS re:Invent Coverage.
I want my badge and interests to be visible to all attendees.
Checking this box will display your presense on the attendees list, view your profile and allow other attendees to contact you via 1-1 chat. Read the Privacy Policy. At any time, you can choose to disable this preference.
Select your Interests!
add
Upload your photo
Uploading..
OR
Connect via Twitter
Connect via Linkedin
EDIT PASSWORD
Share
Forgot Password
Almost there!
We just sent you a verification email. Please verify your account to gain access to
Cloud AWS re:Invent Coverage. If you don’t think you received an email check your
spam folder.
In order to sign in, enter the email address you used to registered for the event. Once completed, you will receive an email with a verification link. Open this link to automatically sign into the site.
Sign in to gain access to Cloud AWS re:Invent Coverage
Please sign in with LinkedIn to continue to Cloud AWS re:Invent Coverage. Signing in with LinkedIn ensures a professional environment.
TheCUBE covers AWS re:Invent 2024 in Las Vegas, featuring keynotes and announcements. Scott and Pedro, software engineering and security engineers at Siemens, use Cribl for data reduction and visibility in their Splunk environment, resulting in a 90-95% reduction and enhanced data access with Security Lake. They value Cribl's flexibility and usability in modernizing their operations. Transforming data for relevance and usability is crucial in security ops data modernization. The engagement at re:Invent provides valuable networking opportunities. Their team pr...Read more
exploreKeep Exploring
What was the key benefit of using Cribl in managing data for our Splunk environment?add
What advantages has Cribl Stream provided in terms of working with Amazon Security Lake and other components?add
What are some benefits of using a tool like Cribl for data modification before it reaches the SIEM system?add
>> Welcome back everyone to theCUBE coverage here in Las Vegas for AWS re:Invent 2024. I'm John Furrier, your host of theCUBE. We're here getting all the action. We got the keynotes going off. A lot of experts coming through theCUBE. We got the news makers, the top executives. Check out SiliconANGLE.com. Of course, CUBE.net. We got a great story here from people in the trenches, building, engineering the solutions. Also a customer of a company we've been covering, which is one of the fastest growing startups in the decade, Cribl, Scott in software engineering and then Pedro, who is security engineer at Siemens. You guys are customers. You guys are practitioners. You're basically doing it. You're making it happen. Thanks for coming on theCUBE.>> Thanks for having us.>> Thank you.>> Re:Invent, this is a conference where everyone goes crazy where the keynote is so long, but it's chock-full of every word is like another announcements. D-SQL, tabular database, data lakes going on steroids with new capabilities, security as a service, all the slew of announcements, of course, the Gen AI, but just real infrastructure advantage to start to see a lot more energy into the infrastructure. And then now the data piece is flowing because the data is not stopping, and Cribl has been a key part of that. So first of all, what do you guys do? Explain what your jobs are, then I want to dig into some of the use cases. Scott, I'll start with you.>> Okay. I'm a software engineering senior manager. A team that we're leading up is a security team. It's internally known as a sim engineering and tooling team. We're responsible for building out our Splunk environment and setting up automation, third-party tooling and things like that. And Pedro is an engineer on my team.>> Yeah, so I'm a senior secure engineer on Scott's team. Mainly dealing with the Splunk engineering and architecture side of things along with all the end to end visibility in our infrastructure environment, which we use Cribl for.>> Yeah, when Cribl was a startup, I knew the founders before they started. We followed the journey and it's really one of those incredible stories where they just solve a great problem, pain point and that pain point a lot of people had, but also it lined up with the market that everyone's like, "Okay, wow. Growth of data." So they just accelerated. So what do you guys like about Cribl if you had to boil down why you guys use Cribl?>> From my perspective, it's about the data reduction that we now have visibility into our environment like we never had before. We didn't have the licensing capacity for our Splunk environment to ingest all the different logs that we were interested in, but Security Lake really allowed us to start collecting those. And then it was a matter of, okay, now what do we do with that data? We couldn't take five terabytes of data and throw it into our Splunk environment as is, but Cribl allowed us to reduce a lot of the data, eliminate fields that weren't of important to us, do some summarization upon it, and as a result of that, we were able to do a 90 to 95% reduction of the data.>> So your core problem was multi-fold, what's the visibility of the data look like, and two, I got to pay out the nose for Splunk. Exactly. It's like, "Okay. Okay. I don't yet know what I am I going to get so why am I," it's one of those things, right? You just do the product, right? Yeah, we've heard that story many times. Okay, let's get into the Security Lake piece because now, okay, we're hearing a lot of stories around, okay, I use AI, I use tools to help me understand what I got, solve some pain points, and then there's an eureka moment. Whoa, whoa, wow, look at this. We're seeing things and then acting on them. Can you guys share any examples of what came next? Honestly, clearly old way versus the new way explained, but was there illumination of like, okay, let's start doing things differently with the data? Can you share any examples of how this played out in the day in the life of as you guys operate this?>> Yeah, I mean, so we learned about Security Lake and its features and how it could very easily aggregate all this highly valuable to security and observability and other components, but certainly for security data. But then when it came to how do we actually get at this data, that's where Cribl came in. We were able with Cribl Stream, which now I know that Cribl just got their Amazon Security Lake competency as both a subscriber and a producer. So they used to be able to write to Security Lake. Now they can actually read from it, which is the part that we're mostly using. It gives us the flexibility of getting the data out of Security Lake, and as Scott was saying, reducing it, but transforming it such that we, because there were a lot of fields that we didn't necessarily care about, a lot of events that were, let's say, 10 events describing similar behavior. Now we can summarize that before sending it to Cribl. There are just Splunks rather, and not just Security Lake. Other components too. Cribl just gives us that flexibility of making the data look the way we want to as far as the format that we are expecting that our analysts are used to, so it's more usable to them.>> Yeah, it reminds me of the story Scott when you mentioned you got to clean house, clean up, get up all the rooms, get everything set up, Security Lake does that, the new version. You mentioned the competency certification. That's cool. That gets to the next level. And then how's this impacting the modernization on the SIM side, as you look at migrations, there's a lot of SIM activity going on. Does that play into this?>> Well, for us it was the just that enhanced visibility. Amazon Security Lake makes it so that at the organization level, we can collect all these logs in a central location. But now with Cribl, our analysts have easy access to all this data. Now we can really populate all these great dashboards that Splunk provides, be able to run detections like a normal day-to-day. They don't have to pivot to another tool. They can just stay where they're at and continue to do their .>> Talk about pivoting to another tool. That's come up a lot as a pain in the, you know what. I don't want to just go to another tool because I got a lot of vendor's wares, right? This is where you feel like it's jammed down your throat. It's like gun to your head, I don't want to do that. What's the real impact of that because that's disruption.>> Absolutely, and I think one of the things for us is we've really utilized Splunk as the platform that we built everything around, and that's really where we send our users. So we're a centralized security team and we have dozens of development teams that are internal clients, and we utilize that Splunk platform for our clients to access. So we're constantly creating dashboards, reports, various searches for them, and it's just really a one-stop shop for our customers.>> On the security operations side, what is the current state of the art from modernization if you guys had to look at where the Cribl dynamic comes in or just in general data management, how do you guys seeing this? What does state-of-the-art mean to you? Is it the platform? Is it the tooling? Is it just the consistency in the data? If someone said, define a security ops data modernization, what would you say? How would you describe that?>> I mean, traditionally there was very little means of modifying the data before it got to your SIEM. You had to build your own tooling around it, or you just had to, if whatever vendor, whatever their data looked like, that's what ended up in the SIEM and that worked. But as the volume of data grows, as the licensing, it's not like it gets cheaper. Now with a tool like Cribl, the way modernization looks like for us is now we don't have to settle for whatever the vendors give us. Not that there's good reasons for why they build it the way they build it, but now we can really transform it and only get the things that we care about and that are relevant not just to our SOC, but like Scott said, to our internal operations teams, dev teams, and they can get full access to the data as opposed to having to pivot to a different tool to get access to the data where it lives.>> So usability is key for the ops team, but you just said reduction of data was a real value.>> Absolutely.>> That's value. Then you've got quality. You're not overstuffing data into the SIEM or other mechanisms.>> Absolutely.>> All right. What's the big takeaway from re:Invent this year for you guys? You guys in the hallway, conversations, this is one of those events. So I was with someone from another company, I won't say their name because they're doing a deal with AWS. It was her first time at re:Invent. She goes, "Where's everyone going? Is there like a concert?" I go, "No, it's the keynote." Keynote at 8:30? Yeah, it Peter DeSantis is the infrastructure keynote. They're still going? There's companies had never seen the conference where people are going to keynotes at 8:30, so they just never been, and so she was blown away. So there's always hallways. It's the late night. I mean everyone, there's meeting, see friends here. What have you guys learned so far here at re:Invent? Any observations, takeaways, hallway conversations that you've seen and heard?>> I mean, for me, it's all about the engagement and the networking. I've been here as an attendee many times. I sat in line for hours on end to get into a session, but I think I find real value in meeting with our clients, our internal customers, our suppliers, our vendors. That's really where I find a lot of value and we've had the opportunity already to speak with several different product development teams on AWS side and some of our other businesses that we work with like Cribl. We've had a lot of exchanges with them, and it's just been really valuable as far as all the things that are coming down the line and things that we can take advantage of.>> It's a wired community here. People are wired up together, all online. They come here for the confab, see each other. Anything on your end Pedro that you'd like to share?>> For me, in a way, I like getting carried away with the hype so that I get excited, riled up, get some new ideas of what other teams are, how other teams are solving these problems so that when we get back to our home offices, we can hopefully implement some of that in our environment.>> Yeah. I'm 12 years in and 10 years ago I could stay out till 2:00 in the morning, get some scoops and some good content. I'm in bed by 11:30. Okay, I try for 11:30, but it's just a great conference. I mean, I don't get to go to these sessions. I don't have the time, but I get a lot of the CUBE interviews. But again, the change of pace of play right now in this business is probably at an all-time high I've seen, and it's putting a lot of pressure on people and teams. As you guys look at your teams and your teammates, what's some of the things that you guys do to chill, to relax, to kind of absorb and still run as fast as you do? What are some of the things that you guys do, whether it's coping mechanisms or just strategies? I mean, people are running hard right now and it's fun. It is not a boring time, but you got security, you got inbounds coming in, but you got technology coming in. What would you guys share to other folks out there watching? I feel like we're in this, lie down the couch.>> Yeah. One thing that I really like how our team does is that we don't tend to rush to implement the latest and greatest right away. We take the time to really understand what the applicable use cases are for us, what problems we're trying to solve, and then we try to put processes around it and make sure we're actually using the tool or whatever the technology is before we start looking at the next thing. Because otherwise, at leads to burnout, leads to doing too much at once or poorly implemented things. I mean, not for everybody, but certainly for us. One of the things I like that we do and we do well, I think is implement, take our time, do things right before we move on.>> Yeah. And you guys got a great reputation, good quality. Any thoughts just to close this out?>> One of the things that I'll say is that we're a relatively small team, but we're distributed. We're all across the states, and one of the things that I really enjoy is being able to get our team together every so often for team workshops, doing hackathons, whatever it may be. But it's really the camaraderie and the culture that we've established is just, it's awesome.>> get the face-to-face going on, and then remote work is fine as long as you get together and keep nurturing the relationships.>> Exactly.>> Takes a team to win. Guys, thanks so much for sharing. Appreciate you coming on theCUBE. Thanks to Cribl for bringing you in. Really appreciate your time. Thank you.>> Thank you.>> All right. More CUBE coverage here at re:Invent. We'll be right back. I'm John Furrier, your host of theCUBE. We'll be right back.