Splunk and F5 team up to deliver advanced search, analysis and reporting capabilities

Published 26th November 2008

Splunk IT Search Helps F5 Users Expand their Security Management Capabilities

London - November 26, 2008 – Splunk Inc., the IT Search company, today announced their partnership with F5 Networks, Inc. (NASDAQ: FFIV), the global leader in Application Delivery Networking, bringing innovative IT Search and reporting capabilities to the leading application infrastructure technology. Splunk and F5 have created Splunk for use with F5 solutions, running on the Splunk IT Search engine. Splunk for use with F5 solutions enables users to meet the complex needs of incident response, threat analysis and compliance and is designed specifically to work with the F5®BIG-IP® Application Security Manager™ (ASM™) and FirePass® SSL VPN solutions, with other F5 product-specific interoperability to follow.

Splunk for use with F5 solutions provides security event search correlation, visualization and reporting for large-scale enterprises and carrier grade networks. With the ability to search and index data from any server, application or network device, Splunk for use with F5 solutions works across all the IT components in complex infrastructures including WebApplication Firewalls and SSLVPNs, providing security teams pre-built searches, alerts and for a more complete understanding of any security threats.

“Enterprise customers demand technologies that validate and visualize the effectiveness of their security solutions,” said Mark Vondemkamp, Director of Product Management, Security at F5. “Having the right tools in place to be able to report on threats before they create chaos is essential. With the Splunk application, our customers are able to more easily meet the complex needs of compliance, security alerting and reporting – increasing their ability to detect and respond to threats, and minimizing the risk of disruption, harmful events and punitive fines.”

Splunk for use with F5 solutions delivers real-time information regarding security breaches and compliance that empower F5 customers to detect and halt these threats before they become costly or damaging to business. Splunk IT Search arms these organizations with an up-to-the-moment understanding of the IT infrastructure, without compromising access to mission critical systems or confidential data.

“The changing threat landscape in large-scale enterprise and carrier grade networks requires the ability to obtain real-time situational awareness,” said Michael Baum, Co-founder and Chief Corporate & Business Development Officer, Splunk. “Positioned in the Leaders Quadrant in the Gartner Magic Quadrant for the Application Delivery Controller market, F5 is at the center of tremendous critical security data. The combination of F5 and Splunk lets system and security administrators quickly understand new and changing attacks in the moment.”

Product Features

Examples of the advanced searches and reports accessible for F5 ASM include:

o Top violations
o Top violations by protocol (HTTP, FTP, SMTP)
o Top HTTP violations by web application
o Top attackers
o Top attackers by protocol (HTTP, FTP, SMTP)
o Top web applications attacked, alerted or blocked
o Top web applications alerted by IP address
o Attacks by location
o Top response codes by web application
o Top alerted or blocked web application requests by time period
o Web application requests by method
o Custom ASM forensics filtering & search

Examples of the advanced searches and reports accessible for F5 FirePassSSL VPN include:

o Detailed User, Browser, OS and Session Statistics
o Configuration Change Statistics
o Failed Logon Statistics
Splunk for use for F5 solutions can be installed as an add-on “application” to the core Splunk application, and can be easily configured to filter and report on any information available in the F5 product log files.

Product Pricing & Availability
Splunk for use with F5 solutionsis free (indexing up to 500 MB a day) for Splunk users and F5 customers, and is available for download at: www.splunk.com/partners/f5