Story
McKesson Brings Log Investigation onto Splunk
McKesson, a health care organization in the United States, uses Splunk SOAR from Splunk to support incident response for on-call engineers.
Value results
| Category | Value result |
|---|---|
| Productivity | Fewer stalled items because log investigation has a clear owner |
| Risk and compliance | Splunk SOAR is the governed place on-call engineers use for incident response |
| Capability | New joiners can see how incident response actually runs |
Story
Inside McKesson, incident response used to depend on whoever still had the latest file. That pattern is common in health care groups working out of the United States. On-call engineers needed a system that would still make sense after the original project team moved on.
McKesson uses Splunk SOAR from Splunk as the working layer for log investigation. Splunk (a Cisco company) is a data platform for security and observability, used to search machine data and investigate incidents. The practical change is simple: incident response has a home, and reviews happen there instead of in a forwarded thread.
Nothing in this writeup invents a savings number. What McKesson gets from Splunk is a durable place to run incident response and a way for on-call engineers to see the same log investigation at the same time.