{"id":1550,"date":"2022-07-13T13:58:56","date_gmt":"2022-07-13T06:58:56","guid":{"rendered":"https:\/\/dt-corp.com.vn\/?p=1550"},"modified":"2022-07-13T13:58:56","modified_gmt":"2022-07-13T06:58:56","slug":"rapid-threat-identification-with-gigamon-threatinsight-guided-saas-ndr-and-sumo-logic-cse","status":"publish","type":"post","link":"https:\/\/dt-corp.com.vn\/?p=1550","title":{"rendered":"Rapid Threat Identification with Gigamon ThreatINSIGHT Guided-SaaS NDR and Sumo Logic CSE"},"content":{"rendered":"<p>Integrations are supposed to make life easier by ensuring enterprise teams get the information they need to detect, investigate, and respond to network threats quickly. But they lose effectiveness when they exchange too little or too much data. Security teams that see too many irrelevant events can find themselves lost in the weeds, and teams that get security alerts without context aren\u2019t able to take fast and focused action, which slows triage and investigations.<\/p>\n<p>When planning the integration between\u00a0<a href=\"https:\/\/www.gigamon.com\/products\/detect-respond\/gigamon-threatinsight.html\">Gigamon ThreatINSIGHT<\/a>\u2122 network detection and response (NDR) and\u00a0<a href=\"https:\/\/www.gigamon.com\/partners\/technology-partners.html#sumo-logic\">Sumo Logic<\/a>\u00a0Cloud SIEM Enterprise (CSE), our focus was to deliver the data security pros need to fight threats without distractions.<\/p>\n<p>ThreatINSIGHT is a comprehensive toolkit that includes a playbook of pre-built queries based on latest industry data, AI software to automatically detect potential threats faster, 365 days of historical network traffic to better enable investigation, and access to a team of threat expert consultants for further guidance when needed.<\/p>\n<h2>Introducing MetaStream with Signals<\/h2>\n<p>Leveraging our newest feature, MetaStream with Signals, ThreatINSIGHT provides Sumo Logic access to network visibility context and rich threat detections. Thanks to this integration, security and network operations teams can triage, validate, and investigate anomalies quickly and efficiently directly in the Sumo Logic platform.<\/p>\n<p>The integration delivers:<\/p>\n<ul>\n<li><strong>Detections and machine learning (ML)-based observations<\/strong>\u00a0of adversary network activity identified by ThreatINSIGHT. That allows SOCs to\u00a0<strong>rapidly discover threats<\/strong>\u00a0within the Sumo Logic interface.<\/li>\n<li>Network metadata aggregations designed for security teams to provide robust network context \u2014 at just\u00a0<strong>2 to 5 percent<\/strong>\u00a0the size of full metadata events,\u00a0<strong>lowering storage costs.<\/strong><\/li>\n<li><strong>North-South and East-West network visibility<\/strong>\u00a0for core cloud networks (AWS, Azure, and Google Cloud Platform).<\/li>\n<li><strong>Secure, easy data exchange<\/strong>\u00a0via a simple, cloud-based, self-provisioned Gigamon-hosted AWS S3 bucket.<\/li>\n<\/ul>\n<p>The big picture? The integration between ThreatINSIGHT NDR Sumo Logic CSE allows for fast triage and investigation efforts with ThreatINSIGHT network metadata, reducing dwell time.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><a href=\"https:\/\/blog.gigamon.com\/wp-content\/uploads\/2022\/06\/Gigamon-GTI-Screenshot-scaled.jpg\" data-featherlight=\"image\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-176429040\" src=\"https:\/\/blog.gigamon.com\/wp-content\/uploads\/2022\/06\/Gigamon-GTI-Screenshot-1024x489.jpg\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" srcset=\"https:\/\/blog.gigamon.com\/wp-content\/uploads\/2022\/06\/Gigamon-GTI-Screenshot-1024x489.jpg 1024w, https:\/\/blog.gigamon.com\/wp-content\/uploads\/2022\/06\/Gigamon-GTI-Screenshot-300x143.jpg 300w, https:\/\/blog.gigamon.com\/wp-content\/uploads\/2022\/06\/Gigamon-GTI-Screenshot-768x366.jpg 768w, https:\/\/blog.gigamon.com\/wp-content\/uploads\/2022\/06\/Gigamon-GTI-Screenshot-1536x733.jpg 1536w, https:\/\/blog.gigamon.com\/wp-content\/uploads\/2022\/06\/Gigamon-GTI-Screenshot-2048x977.jpg 2048w\" alt=\"\" width=\"1024\" height=\"489\" \/><\/a><figcaption><em>Figure 1. Sumo Logic Metastream with Signals dashboard with Gigamon Hawk integration.<\/em><\/figcaption><\/figure>\n<\/div>\n<p>Thanks to the visibility that ThreatINSIGHT provides, Sumo Logic customers will be able to more easily collect, monitor, and visualize data across the network and gain insights from detections and ML-based observations. Customers can also customize which signals to integrate to achieve the in-depth context they need.<\/p>\n<h2>Finding the Needles<\/h2>\n<p>Security event metadata often arrives at customer security tools as a huge haystack where it\u2019s impossible to find the needles. ThreatINSIGHT streamlines aggregated network metadata before delivering it to Sumo Logic, so customers can efficiently retrieve all MetaStream with Signals and validate, hunt, or investigate an incident without the high security-event data storage costs so common with other solutions.<\/p>\n<p>\u201cMetaStream with Signals was designed by our security experts to meet the needs of SOC analysts and incident responders,\u201d says Michael Dickman, Gigamon Chief Product Officer. \u201cWorking together with Sumo Logic CSE, ThreatINSIGHT network visibility and advanced adversary identification techniques will help security teams perform threat detection, investigation, and response activities faster and more thoroughly.\u201d<\/p>\n<p>As organizations continue to implement and manage complex multi-cloud environments, network and security teams need deep observability to make real-time, strategic decisions when monitoring their networks. By combining ThreatINSIGHT, a leader in NDR, with Sumo Logic, both network and security operations teams can take advantage of rich network detection data to rapidly identify and recover from security threats.<\/p>\n<p>To learn more about how Gigamon ThreatINSIGHT and Sumo Logic can mitigate your organization\u2019s risk,\u00a0<a href=\"https:\/\/www.gigamon.com\/lp\/demos.html\">request a demo today<\/a>.<\/p>\n<p>By: <a href=\"https:\/\/blog.gigamon.com\/author\/chrisborales\/\">Chris Borales<\/a><\/p>\n<p>Source: <a href=\"https:\/\/blog.gigamon.com\/2022\/07\/12\/rapid-threat-identification-with-gigamon-threatinsight-guided-saas-ndr-and-sumo-logic-cse\/\">blog.gigamon.com<\/a><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p class=\"tx-excerpt\">Integrations are supposed to make life easier by ensuring enterprise teams get the information they need to detect, investigate, and respond to network threats quickly. But they lose effectiveness when they exchange too","protected":false},"author":3,"featured_media":1551,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[13],"tags":[],"class_list":["post-1550","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blog"],"jetpack_sharing_enabled":true,"jetpack_featured_media_url":"https:\/\/dt-corp.com.vn\/wp-content\/uploads\/2022\/07\/Screenshot-45.png","_links":{"self":[{"href":"https:\/\/dt-corp.com.vn\/index.php?rest_route=\/wp\/v2\/posts\/1550","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/dt-corp.com.vn\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/dt-corp.com.vn\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/dt-corp.com.vn\/index.php?rest_route=\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/dt-corp.com.vn\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1550"}],"version-history":[{"count":1,"href":"https:\/\/dt-corp.com.vn\/index.php?rest_route=\/wp\/v2\/posts\/1550\/revisions"}],"predecessor-version":[{"id":1552,"href":"https:\/\/dt-corp.com.vn\/index.php?rest_route=\/wp\/v2\/posts\/1550\/revisions\/1552"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/dt-corp.com.vn\/index.php?rest_route=\/wp\/v2\/media\/1551"}],"wp:attachment":[{"href":"https:\/\/dt-corp.com.vn\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1550"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/dt-corp.com.vn\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1550"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/dt-corp.com.vn\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1550"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}