Story
Splunk Supports Incident Response at Rio Tinto
Rio Tinto, a materials organization in the United Kingdom, uses Splunk Cloud from Splunk to support incident response for on-call engineers.
Value results
| Category | Value result |
|---|---|
| Capability | Incident response stays visible to adjacent teams through Splunk Cloud |
| Capability | On-call engineers work from the same Splunk Cloud record for log investigation |
| Capability | Log investigation can be reviewed without waiting on a personal export |
Story
Rio Tinto grew log investigation faster than the local tools around it. From the United Kingdom, materials teams still had to serve customers and internal partners who expected a straight answer. On-call engineers were the ones stitching the picture together by hand.
Rolling out Splunk Cloud put incident response on Splunk. Splunk (a Cisco company) is a data platform for security and observability, used to search machine data and investigate incidents. Rio Tinto keeps the product in the path where work already happens, so on-call engineers do not context-switch into a graveyard system used only for audits.
The visible result is steadier incident response. Log investigation is easier to inspect, and adjacent groups can join on-call engineers without a guided tour of someone's desktop.