Splunk uses Isovalent Runtime Security (the enterprise edition of Tetragon) to protect its own cloud infrastructure, which spans approximately 170,000 cloud resources including tens of thousands of VMs and dozens of Kubernetes clusters. Built on eBPF, Tetragon provides kernel-level visibility into process execution, file activity, and network connections without application sidecars. Replacing older sidecar-based telemetry with Tetragon resulted in a 66.5% reduction in CPU utilization and 74% reduction in memory utilization in Kubernetes environments. Tetragon telemetry flows directly into Splunk, where Detection Engineering teams use it for SOC alerts, threat investigation, and security enrichment. Deployment is managed via Helm and CI/CD for Kubernetes clusters, and Puppet for VM environments.

8m read timeFrom isovalent.com
Post cover image
Table of contents
What Splunk Needed From Runtime SecurityWhy Isovalent Runtime SecurityThe Solution: Tetragon Data Into SplunkThe Outcome: More Visibility, Less OverheadThe Value of Enterprise SupportFAQ: What Other Security Teams Can LearnBuild Runtime Security into the Platform
563 Impressions