Splunk Mission Control

Asset context and/or integration with asset management/CMDB- Is this something Mission Control can or is looking to do?

mikerennie
Explorer

Hi MC team, 

One of our current requirements for a Security Incident Management solution is to be able to provide quick context around an asset.  One of the most time consuming tasks that an incident responder faces is to track down what the device being alerted on does, what its criticality is and who is the owner.  The most effective way to do this is to integrate with an Asset Management /CMDB solution.  Is this something that Mission Control can or is looking to do?

Thank you kindly,

Mike

Tags (1)
0 Karma
1 Solution

msayar
Splunk Employee
Splunk Employee

Yes it is! One of the main goals for MC is to be a one-stop-shop providing an analyst all the information they need to make a decision on how to respond to incidents. Part of that goal is enriching the incident with information from various sources. You'll see that coming as Mission Control continues to evolve. If you'd like more information, feel free to reach out to your account team for a roadmap review

View solution in original post

0 Karma

msayar
Splunk Employee
Splunk Employee

Yes it is! One of the main goals for MC is to be a one-stop-shop providing an analyst all the information they need to make a decision on how to respond to incidents. Part of that goal is enriching the incident with information from various sources. You'll see that coming as Mission Control continues to evolve. If you'd like more information, feel free to reach out to your account team for a roadmap review

0 Karma
Get Updates on the Splunk Community!

Enhance Your Splunk App Development: New Tools & Support

UCC FrameworkAdd-on Builder has been around for quite some time. It helps build Splunk apps faster, but it ...

Prove Your Splunk Prowess at .conf25—No Prereqs Required!

Your Next Big Security Credential: No Prerequisites Needed We know you’ve got the skills, and now, earning the ...

Splunk Observability Cloud's AI Assistant in Action Series: Observability as Code

This is the sixth post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how to ...