Story
How Kayak Runs Incident Response on Splunk Enterprise Security
Kayak, a consumer discretionary organization in the United States, uses Splunk Enterprise Security from Splunk to support incident response for on-call engineers.
Value results
| Category | Value result |
|---|---|
| Productivity | Handoffs in incident response sit in a shared queue instead of a mailbox trail |
| Risk and compliance | Splunk Enterprise Security is the governed place on-call engineers use for incident response |
| Capability | New joiners can see how incident response actually runs |
Story
Consumer Discretionary work at Kayak spans more than one site, even when headquarters sits in the United States. Log investigation was splitting across regional habits. On-call engineers asked for a shared way to run incident response without freezing local judgment.
Splunk (Splunk Enterprise Security) is what they standardized on. Splunk (a Cisco company) is a data platform for security and observability, used to search machine data and investigate incidents. Kayak uses it as the system of record for log investigation, with on-call engineers as the primary operators and other groups coming in through the same queue.
Leaders get a picture they can actually walk. Teams get fewer mystery statuses. The story is about operating change, not an unpublished percentage.