Splunk Enterprise Security logo
LiveSIEMPulse

Touchpoint Pulse + Splunk Enterprise Security

Pulse ingests alerts from Splunk Enterprise Security so our analysts can triage, investigate and, within actions you pre-approve, contain threats 24/7, using the tool you already own.

Talk to us about Splunk Enterprise Security How Pulse works
What we collect
  • Splunk Enterprise Security notable events and alerts
  • Correlated incidents from your connected sources
  • Severity and status, kept in sync
What we detect
  • Correlated attacks across your environment
  • Custom detections you already run
  • Anomalies in firewall, server and application logs
What we can do
  • 24/7 triage and investigation of every alert
  • Incident notes and status written back, where supported

How it works

  1. 01ConnectOur team sets up the connection with you during onboarding.
  2. 02Agree authorityYou choose which response actions we can take without calling first.
  3. 03TuneWe tune detections to your environment to cut noise.
  4. 04MonitorAnalysts watch 24/7 and act within your agreed authority.

Every response action is optional and agreed in writing before go-live. Anything outside your pre-approved list, we call you first.

Other SIEM integrations

Microsoft Sentinel logoMicrosoft SentinelLive

Splunk Enterprise Security is a trademark of Splunk (Cisco). Touchpoint Security is not affiliated with or endorsed by Splunk (Cisco). Available data and actions depend on your licence and configuration.

Already run Splunk Enterprise Security?

We’ll show you what Pulse would see in your environment.

Book a call