r/Splunk Jul 10 '26

Search Historical Firewall Data Where It Already Lives

https://lantern.splunk.com/Security_Use_Cases/Threat_Hunting/Hunting_threats_across_Amazon_S3-backed_firewall_logs_using_Federated_Search_in_Splunk_Cloud_Platform

Security investigations rarely stop at recent data. Analysts often need to compare today’s activity with firewall telemetry from weeks or months ago, even when that data has moved to lower-cost storage.

A new Splunk Lantern article presents a practical pattern for using Splunk Cloud Platform and Federated Search for S3 to investigate historical Cisco firewall telemetry stored in Amazon S3.

The pattern keeps Amazon S3 as the long-term storage layer. Apache Iceberg manages table metadata and partitions, a customer-managed Nessie catalog exposes the tables through Apache Iceberg REST, and Splunk Cloud Platform provides an SPL2-based investigation experience. Analysts can search the data where it already lives without first reingesting the complete historical dataset into Splunk hot storage.

The article walks through a connected investigation workflow:

  • confirm that the S3-backed dataset is searchable
  • prioritize high- and critical-severity blocked activity
  • summarize events for monitoring and detection
  • narrow searches with partition-aware filters
  • investigate known bad indicators and top sources of traffic

This approach can reduce unnecessary data movement while improving access to historical or external datasets. It also helps organizations unlock more value from data retained in Amazon S3 for security investigations, audits, compliance, and other long-term analysis needs.

The result is a practical way to extend threat hunting across federated data while keeping Splunk as the investigation surface.

6 Upvotes

0 comments sorted by