Low latency, insight-driven security investigations — in real time
After deploying Sumo Logic Cloud SIEM to integrate and ingest telemetry from all aspects of the company’s infrastructure, HashiCorp experienced the first game changer for managing security investigations: the ability to do low-latency search.
Sumo Logic’s cloud scale empowers HashiCorp security experts to search and conduct investigations in real time. In addition, Cloud SIEM streamlined workflows enabled the security operations center (SOC) team to implement a system where alerts automatically initiate searches.
“Sumo Logic proactively helps us understand an alert, whether it's important or not and, in some cases, automatically disposes of the alert,” said Breed, adding that “having a low latency search system with Sumo Logic makes that kind of real-time workflow automation possible.”
Applies Alerting and Detection Strategy (ADS) to optimize security investigations
Cloud SIEM parses, maps and creates normalized records upon ingestion from HashiCorp’s structured and unstructured data and then automatically triages alerts to provide the security experts with actionable insights. To further optimize Cloud SIEM’s performance in distilling down tens of thousands of daily alerts, the SOC team applies Palantir’s ADS framework.
The framework helps the security team develop theories and think deeply about how best to leverage Cloud SIEM during investigations. For example, the team has mapped out threat-hunting searches to uncover traces a threat actor might leave on the infrastructure and workflows to support the next steps the analyst should take if they find one of those traces.
“Leveraging ADS lets us really focus on the performance side of using Cloud SIEM. Having an idea of what we’re looking for before we go looking helps us optimize things like field extractions and making the most common search patterns return very quickly. This helps the analyst stay in the zone when an investigation has multiple layers of abstraction and Cloud SIEM has made all of that supporting information available upfront,” said Breed.
Reduced time-to-decision with interactive dashboards
Sumo Logic’s security analytics and dashboards provide the security team with single-pane-of-glass visibility across HashiCorp’s extensive cloud environments. The SOC has also implemented a range of custom dashboards to advance the team’s playbooks and processes for conducting daily investigations.
When an analyst is investigating suspicious login activity, for example, they can fill in important parameters into the dashboard, such as the user ID and a time range, which then returns an interactive heads-up display where the analyst can ‘click’ to drill further into specific data.
“Interactive dashboards give us the context and color that help our security analysts minimize the time-to-decision. They can plug in the parameters and get the information very quickly, so they don't have to stop whatever they're doing to reach a decision and take action,” said Breed.