Slide 1

Slide 1 text

© 2014 Autodesk Strengthening Operations with Splunk and AWS CloudTrail Alan Williams alanwill on Twitter & GitHub Principal Engineer AWS/Splunk Big Data Webinar 10/16/2014

Slide 2

Slide 2 text

© 2014 Autodesk §  Engineer @ Autodesk §  Technology Generalist §  Background in Infrastructure §  AWS for ~4 years §  Splunk for ~1 year §  Motorcyclist §  Soft spot for pit bulls Who Am I?

Slide 3

Slide 3 text

© 2014 Autodesk §  Leader in 3D design, engineering and entertainment software §  Introduced AutoCAD in 1982 §  Empowering the Maker movement §  Help our customers imagine, design and create a better world Who is Autodesk? http://www.autodesk.com/products/personal-design-and-creativity

Slide 4

Slide 4 text

© 2014 Autodesk §  How do we know what’s happening in our accounts? §  Malicious activity? §  How can we validate that we’re compliant? Problem

Slide 5

Slide 5 text

© 2014 Autodesk

Slide 6

Slide 6 text

© 2014 Autodesk +

Slide 7

Slide 7 text

© 2014 Autodesk §  Logs AWS API calls §  Visibility and analytics §  AWS native §  Simple to configure §  Point and click (most parts automatable) §  Covers almost all AWS services §  New coverage added regularly (http://goo.gl/jf9uLq) §  Available in all 8 regions (http://goo.gl/ojU7ut) Why CloudTrail?

Slide 8

Slide 8 text

© 2014 Autodesk §  Leverage existing investment §  Standard log aggregation platform §  Splunk App for AWS (http://goo.gl/Xc7XsZ) §  Familiar technology §  Logging = Splunk §  Supports logging REST endpoints §  SQS & S3 §  Single view across all accounts Why Splunk?

Slide 9

Slide 9 text

© 2014 Autodesk CloudTrail + Splunk Architecture SNS Topic SQS Queue CloudTrail S3 Bucket SNS Topic CloudTrail 1 1 2 2 3 3 4 4 5 Account A Account B Core Services Account §  Simple to configure §  Scalable to many accounts §  Central logging view across all accounts

Slide 10

Slide 10 text

© 2014 Autodesk §  Incident Response §  Operations Troubleshooting §  Compliance Auditing CloudTrail Use Cases

Slide 11

Slide 11 text

© 2014 Autodesk §  Something happened in Account X between a certain time window §  Has this compromised host made any API calls? §  Where have these IAM keys been used? Incident Response

Slide 12

Slide 12 text

© 2014 Autodesk Something happened in Account X between a certain time window

Slide 13

Slide 13 text

© 2014 Autodesk Has this compromised host made any API calls?

Slide 14

Slide 14 text

© 2014 Autodesk Where have these IAM keys been used?

Slide 15

Slide 15 text

© 2014 Autodesk §  Who created this instance? §  Where in the world are sign-ins originating? Operations Troubleshooting

Slide 16

Slide 16 text

© 2014 Autodesk Who created this instance?

Slide 17

Slide 17 text

© 2014 Autodesk Where in the world are sign-ins originating?

Slide 18

Slide 18 text

© 2014 Autodesk §  Alert if an SG rule is created with 0.0.0.0/0 rule §  Frequency of certain events §  Alert whenever an IAM user is created Compliance Auditing

Slide 19

Slide 19 text

© 2014 Autodesk Alert if an SG rule is created with 0.0.0.0/0 rule

Slide 20

Slide 20 text

© 2014 Autodesk Alert whenever an IAM user is created

Slide 21

Slide 21 text

© 2014 Autodesk §  AWS CloudTrail + Splunk = Happy Marriage §  Scalable to 100s of accounts §  Toolset for Operations and Security Teams §  Our common use cases with examples Summary

Slide 22

Slide 22 text

Autodesk is a registered trademark of Autodesk, Inc., and/or its subsidiaries and/or affiliates in the USA and/or other countries. All other brand names, product names, or trademarks belong to their respective holders. Autodesk reserves the right to alter product and services offerings, and specifications and pricing at any time without notice, and is not responsible for typographical or graphical errors that may appear in this document. © 2014 Autodesk. All rights reserved. @alanwill alanwill