Story
3M Brings Log Investigation onto Splunk
3M, an industrials organization in the United States, uses Splunk SOAR from Splunk to support incident response for on-call engineers.
On-call engineers at 3M review log investigation in Splunk SOAR rather than in personal files.
“Industrials work at 3M spans more than one site, even when headquarters sits in the United States.”
“On-call engineers asked for a shared way to run incident response without freezing local judgment.”
Independent write-up. Figures come from public sources or are illustrative.
Value results
| Category | Value result |
|---|---|
| Capability | Incident response stays visible to adjacent teams through Splunk SOAR |
| Capability | On-call engineers work from the same Splunk SOAR record for log investigation |
| Capability | Log investigation can be reviewed without waiting on a personal export |
Story
Industrials work at 3M spans more than one site, even when headquarters sits in the United States. Log investigation was splitting across regional habits. On-call engineers asked for a shared way to run incident response without freezing local judgment.
Splunk (Splunk SOAR) is what they standardized on. Splunk (a Cisco company) is a data platform for security and observability, used to search machine data and investigate incidents. 3M uses it as the system of record for log investigation, with on-call engineers as the primary operators and other groups coming in through the same queue.
Leaders get a picture they can actually walk. Teams get fewer mystery statuses. The story is about operating change, not an unpublished percentage.