Splunk Mission Control

Asset context and/or integration with asset management/CMDB- Is this something Mission Control can or is looking to do?

mikerennie
Explorer

Hi MC team, 

One of our current requirements for a Security Incident Management solution is to be able to provide quick context around an asset.  One of the most time consuming tasks that an incident responder faces is to track down what the device being alerted on does, what its criticality is and who is the owner.  The most effective way to do this is to integrate with an Asset Management /CMDB solution.  Is this something that Mission Control can or is looking to do?

Thank you kindly,

Mike

Labels (1)
Tags (1)
0 Karma
1 Solution

msayar
Splunk Employee
Splunk Employee

Yes it is! One of the main goals for MC is to be a one-stop-shop providing an analyst all the information they need to make a decision on how to respond to incidents. Part of that goal is enriching the incident with information from various sources. You'll see that coming as Mission Control continues to evolve. If you'd like more information, feel free to reach out to your account team for a roadmap review

View solution in original post

0 Karma

msayar
Splunk Employee
Splunk Employee

Yes it is! One of the main goals for MC is to be a one-stop-shop providing an analyst all the information they need to make a decision on how to respond to incidents. Part of that goal is enriching the incident with information from various sources. You'll see that coming as Mission Control continues to evolve. If you'd like more information, feel free to reach out to your account team for a roadmap review

0 Karma
Get Updates on the Splunk Community!

Enter the Dashboard Challenge and Watch the .conf24 Global Broadcast!

The Splunk Community Dashboard Challenge is still happening, and it's not too late to enter for the week of ...

Join Us at the Builder Bar at .conf24 – Empowering Innovation and Collaboration

What is the Builder Bar? The Builder Bar is more than just a place; it's a hub of creativity, collaboration, ...

Combine Multiline Logs into a Single Event with SOCK - a Guide for Advanced Users

This article is the continuation of the “Combine multiline logs into a single event with SOCK - a step-by-step ...