Siemens’ centralized operational data empowers its security teams to shorten its mean time to resolve. In one investigation, Siemens identified what data in Amazon S3 was impacted in an event within 10 minutes as opposed to several days. “Our team has more confidence now that we’re collecting these logs and monitoring for security use cases,” says Borges.
Siemens ingests 5–7 TB of security data daily into Amazon Security Lake, then uses Cribl to forward only the most relevant 600 GB of data to Splunk for detailed analysis, a 90 percent reduction. Siemens saved 1.3 million dollars annually while aggregating more logs.
“Using Amazon Security Lake, we have dramatically improved visibility across our entire AWS infrastructure. We can ingest multiple data sources into Splunk and run threat detections against our data in AWS, which helps us satisfy our compliance requirements,” says Schwartz. “This service will help us stay ahead of potential threats while managing the complexity of our large-scale AWS environment.”