Case Study: Splunk achieves stronger runtime security visibility and lower overhead with Isovalent Runtime Security

A Isovalent Case Study

Preview of the Splunk Case Study

Splunk cuts CPU use 66.5% and memory use 74% with Isovalent Runtime Security

Splunk, a major data analytics and security company, needed to improve runtime security visibility across its large-scale cloud infrastructure, which included both Kubernetes clusters and virtual machines. Their challenge was to consolidate this visibility, reduce the operational overhead of maintaining multiple separate security services, and feed high-quality telemetry directly into their own Splunk platform for detection and response. They turned to vendor Isovalent and implemented their product, Isovalent Runtime Security, which is built on the open-source Tetragon project.

The solution from Isovalent provided kernel-level visibility into runtime activity using eBPF, replacing older sidecar-based approaches. This allowed Splunk to deploy a common source of security telemetry across its entire environment. The results were significant, with Isovalent's solution reducing CPU utilization by 66.5% and memory utilization by 74% in Kubernetes environments. This gave Splunk's security teams richer context for investigations while substantially lowering operational overhead.


View this case study…

Isovalent

10 Case Studies