Skip to content
storyUnited StatesHealth CareProductivityRisk and complianceCapability

Story

Splunk@McKesson

McKesson Brings Log Investigation onto Splunk

McKesson, a health care organization in the United States, uses Splunk SOAR from Splunk to support incident response for on-call engineers.

Value results

CategoryValue result
ProductivityFewer stalled items because log investigation has a clear owner
Risk and complianceSplunk SOAR is the governed place on-call engineers use for incident response
CapabilityNew joiners can see how incident response actually runs

Story

Inside McKesson, incident response used to depend on whoever still had the latest file. That pattern is common in health care groups working out of the United States. On-call engineers needed a system that would still make sense after the original project team moved on.

McKesson uses Splunk SOAR from Splunk as the working layer for log investigation. Splunk (a Cisco company) is a data platform for security and observability, used to search machine data and investigate incidents. The practical change is simple: incident response has a home, and reviews happen there instead of in a forwarded thread.

Nothing in this writeup invents a savings number. What McKesson gets from Splunk is a durable place to run incident response and a way for on-call engineers to see the same log investigation at the same time.

Relationship map

McKesson uses Splunk, Cartesia, Anthropic, Veeva, Confluent, Epic Systems. Shared with 1Password, 3M, 6sense, Airbnb, American Express GBT. Industry: Health Care. Value: Productivity, Risk and compliance, Capability. Drag nodes, filter types, or expand a node to follow more commonalities.

100%

Similar stories

Search Valuerepo

Search stories, solutions, customers, and more.

Type to search stories, solutions, and companies

↑↓Navigate↵OpenEscClose

View all