Story
H&M Standardizes Security Telemetry on Splunk
H&M, a consumer discretionary organization in Sweden, uses Splunk Enterprise Security from Splunk to support detection engineering for detection engineers.
Value results
| Category | Value result |
|---|---|
| Risk and compliance | Security telemetry can be reviewed without waiting on a personal export |
| Risk and compliance | Named workflow replaces ad hoc routing for security telemetry |
| Risk and compliance | Detection engineering stays visible to adjacent teams through Splunk Enterprise Security |
Story
Consumer Discretionary work at H&M spans more than one site, even when headquarters sits in Sweden. Security telemetry was splitting across regional habits. Detection engineers asked for a shared way to run detection engineering without freezing local judgment.
Splunk (Splunk Enterprise Security) is what they standardized on. Splunk (a Cisco company) is a data platform for security and observability, used to search machine data and investigate incidents. H&M uses it as the system of record for security telemetry, with detection engineers as the primary operators and other groups coming in through the same queue.
Leaders get a picture they can actually walk. Teams get fewer mystery statuses. The story is about operating change, not an unpublished percentage.