MDR partner · Splunk Enterprise Security

Managed SOC on Splunk Enterprise Security: we run the detections.

For teams that invested in Splunk but have findings nobody works at night, or rules written years ago that nobody maintains. The Fortgale MDR service runs the detections in your Splunk, leaves the data where it is and acts through the connected tools, at a median TTC of <30 minutes.

<15 minMedian TTD
<30 minMedian TTC
24·7·365SOC in Milan since 2017
Fortgale × Splunk
MDR · live
Splunk sensor activeEndpoint · cloud · identity telemetry
Splunk
European SOC 24·7·365L2/L3 analysts · direct interaction
Fortgale
Multi-domain AI tier-zeroNoise reduced >90% by day 30
Fortgale
Native Splunk responseHost isolation in seconds
Live
Proprietary intelligence287 tracked adversary groups and attack tools
Fortgale
MDR live, Splunk + Fortgale SOC active
Compliance
ISO/IEC 27001
NIS2 ready
DORA aligned
GDPR · ENISA
Technology partnership
Splunk Enterprise Security
MITRE ATT&CK aligned
OpenCTI
Coverage

What we cover on Splunk.

The Splunk components the SOC operates, on Splunk Cloud Platform or Splunk Enterprise on-prem. If Splunk is not in place yet, licensing and deployment are part of the service.

01

Enterprise Security 8

Analysts working findings and finding groups in the Enterprise Security queue, which since version 8 replace notable events and include Mission Control.

02

SPL detections

Event-based detections written in SPL by Fortgale, mapped to MITRE ATT&CK and updated as tracked actors evolve.

03

Risk-based alerting

Intermediate findings aggregated by entity through finding-based detections: ten weak signals on the same user become one finding to work.

04

Threat intelligence

Fortgale indicators in the Enterprise Security Threat Intelligence Framework, via TAXII, STIX or lookups, used by threat-matching searches.

05

Splunk SOAR

Playbooks and response plans in Splunk SOAR, written and maintained by Fortgale to contain through EDR, identity provider and firewall.

06

Data sources

Endpoint, firewall, Active Directory, Microsoft 365, AWS and Azure brought into Splunk with Universal Forwarder, HEC and APIs.

07

UEBA

User and entity behaviour analytics in ES Premier; standalone Splunk UBA reaches end of life on 31 January 2027.

What we add

What Fortgale adds on top of Splunk.

A SIEM collects and correlates; it does not decide. Fortgale brings the detection engineering that turns it into a defence: rules built on 287 tracked adversary groups and attack tools, mapped to MITRE ATT&CK and maintained by the Milan SOC, with every alert enriched by proprietary CTI before it reaches the analyst. The data stays in your environment, under your retention. Noise drops by more than 90% by day 30, and once an alert is confirmed the analyst acts through the tools connected to the platform: median TTD <15 minutes, median TTC <30 minutes.

Splunk does not isolate a host or block an account: it correlates and decides what deserves attention. Response runs through Splunk SOAR playbooks launched from the investigation in Enterprise Security, with connectors to the EDR for isolation, to Active Directory or Entra ID for account blocking and to the firewall for address blocking.

Enterprise Security response plans attach actions and playbooks to the phases of an investigation: the analyst contains from the same finding they triaged, and every step stays recorded next to the evidence.

Fortgale detections live in your Splunk as SPL searches your team can read, and the 34,000 IOCs a week of Fortgale CTI enter the Threat Intelligence Framework: when the infrastructure is known, the finding reaches the analyst already attributed.

Takeover

How we take over your Splunk environment.

Takeover happens on your Splunk instance, Cloud or on-prem: indexes, retention and apps stay as they are.

Monitoring starts as soon as access is live, and technical onboarding closes in one week: Enterprise Security roles, Fortgale detections, the SOAR connection and response authorisations.

That week also covers data sources: which arrive, which are missing and which detections stay blind without them. On your side: a Splunk administrator, permissions on the response connectors and the escalation list.

From the field

Mater Nebula: enumeration you only see by correlating.

In January 2025 Fortgale documented a massive Microsoft 365 user enumeration campaign against Italian and European companies, attributed to Mater Nebula. Started on 27 December 2024, it used the open source tool o365enum to find out which accounts really exist, probing ActiveSync, Autodiscover and the office.com login page from IPv6 addresses of the provider Netassist, to prepare phishing and password spraying. The MDR service detected it across several tenants by correlating the same indicators.

The article is not about Splunk, but it is a SIEM case. On a single tenant these are scattered attempts that cross no threshold; in an index that collects Entra ID and Exchange Online sign-in logs they become a pattern. An SPL detection that aggregates attempts by source, with risk-based alerting on the identities involved, turns that noise into a finding before the spraying starts.

FAQ

What buyers running Splunk actually ask.

Does the data stay in our Splunk?

Yes. Logs stay in your indexes, with the retention you decide, on Splunk Cloud or on your own infrastructure. Our analysts work inside your instance with the agreed roles, and every search and action is tracked in Splunk audit logs.

Do we need an EDR to contain?

You need a tool that carries out the action. Splunk correlates and SOAR orchestrates, but host isolation is done by the EDR and account blocking by the identity provider. At onboarding we connect the SOAR connectors to the tools you have and agree where the analyst can act without asking for confirmation.

Do we need Enterprise Security Premier, or is Essentials enough?

It depends on how you respond. Premier includes Splunk SOAR, UEBA and automated analysis built on Attack Analyzer; Essentials covers detections, findings and threat intelligence, but response has to go through a separate SOAR or the tools' own consoles. At onboarding we start from the edition you have.

How do we move from another provider without a gap in coverage?

Indexes and data sources do not move: only roles, active detections and playbooks change. Fortgale monitoring starts as soon as access is live, and the previous contract can end once technical onboarding is complete, after one week.

Do we buy the Splunk licences, or do you?

Either way. Fortgale operates the Splunk Cloud or Splunk Enterprise licence you already own, or provides licensing and deployment as part of the service.

See a real runbook

A real runbook on your Splunk.

We walk through an Enterprise Security finding step by step: the SPL detection that raised it, the risk accumulated on the entity, the SOAR playbook that contained it and the evidence left in the indexes. Alongside it, the Report on the actors most likely to target your sector.

Response time: < 1 business day.