Splunk uses Isovalent Runtime Security (the enterprise edition of Tetragon) to protect its own cloud infrastructure, which spans approximately 170,000 cloud resources including tens of thousands of VMs and dozens of Kubernetes clusters. Built on eBPF, Tetragon provides kernel-level visibility into process execution, file activity, and network connections without application sidecars. Replacing older sidecar-based telemetry with Tetragon resulted in a 66.5% reduction in CPU utilization and 74% reduction in memory utilization in Kubernetes environments. Tetragon telemetry flows directly into Splunk, where Detection Engineering teams use it for SOC alerts, threat investigation, and security enrichment. Deployment is managed via Helm and CI/CD for Kubernetes clusters, and Puppet for VM environments.