Story
How Endress+Hauser Runs Detection Engineering on Splunk Enterprise Security
Endress+Hauser, an industrials organization in Switzerland, uses Splunk Enterprise Security from Splunk to support detection engineering for detection engineers.
Value results
| Category | Value result |
|---|---|
| Risk and compliance | Detection engineers work from the same Splunk Enterprise Security record for security telemetry |
| Risk and compliance | Security telemetry can be reviewed without waiting on a personal export |
| Risk and compliance | Named workflow replaces ad hoc routing for security telemetry |
Story
Industrials work at Endress+Hauser spans more than one site, even when headquarters sits in Switzerland. Security telemetry was splitting across regional habits. Detection engineers asked for a shared way to run detection engineering without freezing local judgment.
Splunk (Splunk Enterprise Security) is what they standardized on. Splunk (a Cisco company) is a data platform for security and observability, used to search machine data and investigate incidents. Endress+Hauser uses it as the system of record for security telemetry, with detection engineers as the primary operators and other groups coming in through the same queue.
Leaders get a picture they can actually walk. Teams get fewer mystery statuses. The story is about operating change, not an unpublished percentage.