Platform Privacy & Security Academy: Introducing ServiceNow Log Export Service
all right let's get it started thank you all for joining our uh platform privacy and Security Academy session uh the topic that we're going to cover today is uh service now log expert service my name is FKA Sim I am one of the outbound product manager uh in platform privacy and security team here at service now now I've been with service now for almost four years and part of my job is to talk with a customer like you to understand your use case and concerns so that I can provide some strategies to meet your business needs while staying aligned with your security needs with me today Stefano hello everyone thank you for joining yeah this I'm a c pro product manager here service now I'm part of the platform security Buu um I have responsibility over a number of product including the log exper service that I'll be happy to um describe to you today thank you so much I appreciate it so before we go any further as always we have to start by reminding you that we might talk about things that are on the road product road maps since we are a publicly traded company There are rules about making forward-looking statements so we just want to remind you to please make your purchasing decision based on the product as it exists today the agenda that we're going to cover today we're going to talk about service now Vault quickly I'm sure most of you are aware what service now Vault bundle really is what are the offering and premium products that it contains but I'm just going to re um affirm a Fe uh the new features and the product that we added as part of this bundle and then I will uh hand it over to uh the the Stefano to go over the log expert service and then we're going to talk about the packaging and the licensing and the some of the customer engagement Channel and I will jump onto Q&A as well all right let's get it started service now Vol so what is service now V it is our Marquee security enhancement Suite uh intended to provide additional layer of security and privacy capabilities for the na platform and it it consists of five six key uh security elements right now one platform encryption uh Pro to an auditor that you're following industry best practices around encryption of sensitive data the data privacy show the right data to only to the right people by finding classifying and reducting private information in production and subpro environment the zero trust access is the new product that we add as part of our Vancouver release which is granular contextual policy to enforce least privileges access the secrets management use item discovery in very sensitive environment with provable assurance that service now employees have zero access to the distor credentials the code signing to ensure that the code running on your mid server has not been tempered with uh the last but not least the log expert service that's one of the main topic that we're going to cover today with Stephano the automated collection of realtime forensic quality law so that uh you can detect and respond to abuse and misuse Fester so this comprehensive security solution has been package to make it easy for organization to order and to consume the solution as well so if you're curious about the other PL the offering starting from any the platform encryption data privacy and a zero trust access is one of the new the product that we released as part of incur release please ref refer back to our platform privacy and Security Academy uh the channel That We presented earlier so you will see all the demo and use cases as well with that I'm going to hand it over to Stefano to just kick off uh the log expert service Stefano great thank you for um so as as always let's start with the you know with the goals you know what are we trying to achieve what can the log exper do for us there are three main use cases I'm sure you're aware of number one is security so by pulling your log into your security system system you can aggregate analyze corate investigate any kind of potentially misconfigurations um um Potential Threat potential um insecure Behavior Uh and fully and and automatically identify analyze and and remediate those issues before they occurred same from a troubl shoting and optimizing of performance but injesting this information into the tools you already have is log analytics which comes under different names that can ingest the data with granular data and then fully and automatically analyze it predicted uh and provide you the insight to anticipate any kind of performance issues you might have or to troubleshoot when you do have a potential issues in the service now environment and then finally U it also allows you to Monitor and optimize the user experience making sure that the applications and services you provide to your customers are up to the standards and slas that you want to achieve and help you improve and optimiz them as well but logs are hard and large um they come in different forms we have some are table base some are file base we have large files call service now no logs that are in each one of your instincts you might have multiple uh nodes within an instance um they have different formats for different purposes and the collection of all that data um needs to be orchestrated and it needs to be automated otherwise it takes a f amount of effort to make that happen you have to write your own scripts uh to pull the data that you care for you have to manage those you have to put them somewhere you have to make sure they are highly available um dealing with any kind of of potential connectivity issues with your system it can be somewhat laborious and this is why we have created uh this service Lo exper service it's a turnkey product that allows you to with a few clicks after an initial setup to systematically import all the data that you want into the system that you want is highly scalable it's near real time it literally will copy that data at the time when it's logged into the system it's e to set out there's no coding required um it will reduce um and improve efficiencies by exporting it has filters so you can choose the data you want to export you don't have to export everything you export the things that you care for it will improve your PR detection your compliance simp simplify aage TR shooting uh and we have a number of connectivity modes uh to allow you to do this within your existing um tools and framewor and I'll go over those in a second let's talk about the log sources so we covered all three major kind what we call system and application log sources with in service now first of all system so system loog table we have sis logs s log transaction and CIS outbound HTTP log table what we uh log any external connectivity to your external system the other table is what we keep track of everything that's change as you know s is now a heavily table based information we keep in the environment is in one table somewhere um and by allting Stables you keep track of every single changes from to in every record of every table you have a choice of which tables you added but that will maintain inut uity we never actually trim those tables you can um so you'll have that information for any kind of audit purposes and then finally the UPN live files these are application uh files that are siid in each one of the nodes and keep track of the very granular level of any interactions of that application so let's talk about connectivity options how do you connect uh the your system your login ntic system which could be of different kinds and you might have of course more than one two are Cloud environment so what's depicted in the picture it's kind of small is on the left side is what we do so basically we have built a servers that CCT the data from all the different sources into a single string of data we then uh copy that data into what we call the hermis messaging service it's a Kafka as a service it's an infrastructure we're build in a infrastructure and Kafka is highly scalable highly reliable uh highly performant uh so we pull all the data in hermas uh in real time and then you use a couple different connectivity option to pull the data from our Cloud into your log antic system and we have two major way to do this number one you could use me server most of you are familiars already have implemented the me server in your environment it's a non entity and basically we have created a small consumer that you will install on a mute server and that consumer takes out of all the connectivity uh and all the uh High availability the the transposing of the data from our Cloud into then a rest push to any uh local analytical product that you might have but it's plank or elk or an aide Kafka whatever system you might have and that is that is purely using all service now component you also have an option to use any kind of C consumer so Kat is a standard in Industry uh for subub push pool type of data communication every tool has its own consumer for example splank has as you know a a sanction and supported small consumer uh you would Implement uh that consumer on in your environment it could be in the cloud it can be on Prem uh it will then connect that to the the hermis messaging service and again it's it's it's a normal step of getting a certificate and and then exchanging a certificate so you know the two you know our cloud and your system can trust each other and then all you have to do is just configure what sources and what filters you want to apply if you have your own cfus system and some of you do you can also natively since now you're talking C to Kaa you can also have a system your own c talk to the our service the Hermos measurement service that is um here we have another more details picture that I want to go into today uh but let me talk about uh jump into the packaging I'm sure many of you will have questions about the product the product can be acquired in two different ways um if you are a customer or a future customer Vault then you get unlimited usage of log export uh you can consume as much data as as you need to your second option is Al you have two different options there is a store uh SK that allows you for 500 gab per month half a tte per month uh from our um investigation analysis we believe that that will uh suffice the vast majority of our customer so you can actually use log exess service for free in most cases if you need additional capacity keep in mind it's a cost po as to manage all the storage and infrastructure and all the different um cloud data center then you can acquire one or more additional 1,000 gab one taby of data at an additional cost uh and of course you know your your uh trusted uh customer support folks can can Mark you through the details of the of the structure and price let me talk about some of the kind of the practicalities or licenses uh you most likely well but I want to make sure you understand number one is you can test the product in sub production without any excuse as always that's standard service now um behavior number two is and again the free log exper to starus skew should be able to accommodate your needs especially um by you choosing the appropriate sources and filters uh and thear of customers might need um to acquire uh one or more of the incremental skills so let me talk a little bit about what you could do with service now logge we we cover the high level use cases earlier in this presentation I want to talk a little bit and give you just two examples of what you could do uh with this tool and let's start with security and just because I come from a platform security environment but again um I I would expect that actually most of you will use it for performance purposes and and some of you will use it for security as well let's talk about automating the security instant detection and I'm going to use Splunk as an example because many of you do have this spank environment it's a common cloud or arm pram logical tools it's a maret leader um but um there are many others and they all just as good and they all provide the same capabilities um you're probably going to be familiar with some of the other um security tool like aride or or um of course Microsoft and U has Sentinel and and every single platform has a a very uh sophisticated capable systems and all the systems come with um typically with out box capabilities to do secur threat detection uh without you are having to create any kind of dashboards or additional analytics for example we're going to use again in the splank example they have a a three applications it's called the splank infos um it's fre to download it's easy to install and once you do that it will pull all the appropriate logs into it provide you rich visualization in this case I'm showing the security posture that dashb and then uh it will um actually apply automatically analytics to it to detect certain behaviors inesss and in addition to it you can of course set threshold and notification so you'll be automatically notified when any of this potential threats occur in your environment and in this case in the service now environment and just to give you some of the examples of of the type of threats that this particular application can detect they can identify spares and access all of a sudden um your um access to your service now environment Sparks in in a normal way clearly that is um something to look into bruteforce attacks which is your typical keyword spray or password spray or other large attacks that routinely occur onto everyone's nowadays environment uh including yours counts that have high percentage of loging failures versus success uh clearly if there is a large Spike and people having to log in multiple times to get in is probably a good indication again that you are on under a some kind of attack user performing new and privilege action you know privilege users um it's definitely something you want to look up for uh and make sure that uh you don't see any unnormal Behavior or uh that they're not um um taking an excess amount of privilege um actions as well which is again indicative of potential misbehavior or potential compromise uh from the outside one that is you know very popular but actually very helpful is the geographically improbable aess commonly known as the Superman use case uh the same person logging in uh within a short period of time from impossible distance you know me now logging in from California and then within you know a couple of minutes um logging into from South Korea and there's many others of this that all are preconfigured they all are built into these applications and then you can easily take advantage of that of course PL provide additional and more sophisticated as do all the other log analytic Solutions you can move from infac to Essentials which provide hundreds of analytics across many different areas uh you can move to Enterprise security which then provides you know ml capabilities AI capabilities abilities to create very sophisticated behaviors and notifications um automatically within the the tool itself and this just the example in security uh most of you uh probably works with Security operation scenes that have requested that type of information so they can actually operate this systems and take full advantage to secure your service now environments let's talk a little bit about automate regular performance Administration and here are going to bring a different example uh and I've used uh the someone some of you will be familiar uh if not I encourage you to look at a service Now guide called fine tune your service now platform with regular performance Administration it's a really good guide that can of provide some guidelines and best practices or what are the daily weekly monthly quality activities that we recommend you do to one monitor the overall health from the performance of your environment but also to anticipate again any kind of potential issues that might occur uh in your environment and catch them ahead of time and some of the things that that guide recommends um I'm sure you recognize them are you know kind of um pretty obvious normal things that you probably would want to check for for example uh looking for excessive loging it's always an indication when applications might be misbehaving uh large log files uh you do want to uh monitor your slow run jobs you do want to monitor through your long run jobs uh here's one of my favorite track your table growth rate um if a table is all of a sudden growing at an exceeding rate not that it's not growing but it's growing proportionally larger than it has in the past again it's an indication that something might be uh misbehaving and if you catch it early enough you can actually troubleshoot and identify and remediate it before it actually exceeds to it to point they might cause performance issues there's many other recommendations in in the guide of things of this sort typically you might have to do this manually you might have to monitor on a daily basis you might have to go and monitor for some of these um Trends which we expose in service now itself uh some you might have to actually Aggregate and um and do your own calculations to monitor the growth and in changes over time what you can do of course with log analytic system you can actually automate all of it you create simple queries that pull that information and then you can set your own threshold your your own growth rate and again set automatic alerts that will allow to proactively what you having to physically monitor this different metrics and you know Diagnostics on um on your own time and then once you do that because these tools this log and this products give you the ability to fully understand exactly what happened drill into what might be the cause and then even expand out and see what are the potential repercussions and all of that functionality comes embedded into those tools so key key takeaways from from this presentation number one is the lock exper service allows you to improve the performance and security your service now instances by leveraging tools that you already have in your environment everyone has a log and integ good product number two is um after the few and simple setup steps that you do one time the like of e will send all the system application logs in your real time and a scale uh you don't have there's no further effort you might want to optimize you might want to change a filter you might want to push and pull more data as time goes by but after that initial uh resly small setup the system is truny it does it for you and and lastly um again we provide a free starus SK you can provide you can test this functionality in your sub environment U see if that fits you need making sure that you can ask and provide the right information to your tools or tools um and it should be sufficient that was 500 gab per month should be sufficient for most of you we buil it and we provide them in St ke because we want you our customers to use to export the data to your tools we see an enhan benefit that by doing so you will actually take better care of your service now environment from a security performance and experience standpoint which then will make you of course happier continue to grow your deployment of service St and with that I'm gonna pass it back to forit all right thank you so much Stefano it's really uh insightful information there so before I go any further there's one question that I want to uh just uh I just came from Jonathan regarding to uh I'm sure you're reading that one as well so how does this differ from the mid server with with CIS loock prop and we need to be clear on this since Lees has additional cost okay so let me talk first the CIS log probe is a way that you can um actually create workflows which are specific identifying specific events so you'll say oh let me look at this specific event and when that occurs send it to my external system Sim so it say event by event workflow that you can choose to create um you have to have a mits it has to be in an on plan environment uh so it's a very granular event by event kind of extion when you see this send it when you see this send it this is actually take a different approach as opposed to send single event we're actually allowing you to pull all the data out of the systems pull it into your log analytics where you can actually like Leverage The Power of those systems and in many cases the prepackage the out of the box capabilities to do many many many different of analytics to uh Power many different kinds of dashboards many different kinds of Lords and also cross culate information across multiple systems attacks often are nowadays are not just single applications but across from multiple Cloud longtime application as well so that's a CIS probe so the CIS probe is a great tool for single event U exilation or or export this is really a turn key for all the system and application logs at scale um and in near real time all right second question sure I think it was a a also an ask about qualifications of the of the pricing I was I sure understood the second part of the question uh no the second part is just we need to be clear on this uh since L has additional cost so uh I think you answered that one as well yes yes and again most of you will not um will not have should not have um Ur any additional cost thanks to the sure thank you anything uh else you want to add before we jump on the next slide Stefano uh no uh unless the questions on the chat that I don't see sure if if you guys have any question feel free to type in and we're happy to answer as well so uh previously we had launched somewhere around like uh seven to eight different Academy session this year as part of platform privacy and security so around Vol bundles that includes all six to seven different premium products including zero trust access that we launched as part of this vro release so if you're interested in uh please refer back to the recording that we uploaded on YouTube as well and uh at the same time you can simply scan the QR code on the screen so that it will be directed to that channel as well so here's our different documentation sites social media platform that we have our YouTube channel and follow us on LinkedIn Facebook and Instagram and podcast we have developer podcast as well that you feel free to uh tune in and understand more about other other product offering and service now and also we have a mentation site that has G that will give you overview of what the uh the product success implementation guide look like and what are things and what are use case that we need to be aware of as well and but last but not least we have a platform privacy and security Community side where we are putting and uploading all different articles and blog posts and some of our essential infos for example our upcoming Academy session as well as the pack session uh as well so if you're interested in please scan the QR code and you'd be directed to that page as well so I'm gonna pause one or two minutes yeah so I'm gonna pause one or two minutes to see if there's any question regarding to Lees uh any any concerns regarding to the pricing and packaging or the product offering that we're uh uh giving right now uh Stephanie just mentioned earlier as well so he can either purchase the S as a individual product individual skew or you can purchase that as part of Vault bundle with uh Limitless uh the capabilities there as well just gonna give one more minute for other folks sure go ahead yeah what we wait um I just want to mention is um the log exper service it's been um it's produced as a store app uh so if you want to try it just go to the service now store um type loog Expo Service uh with a couple you know just requested in a couple of clicks again on sub prod doesn't require any approvals um and you'll immediately have it on your system and you'll be ready to start uh working on develop it um as anything else you're going to see um lot export improve you know we have a number of Ro up improvements and additions over time so you'll see expand in terms of capabilities as well always appreciate feedback um but overall we're hoping that you'll find this very very helpful and and simple to use uh in your environments all right it seems like there's no more question this is the end of our session of introducing service now log expert service thank you all for joining in I really appreciate it for you all spending your time to just tune in and understand our product offering here till next time stay tuned thanks stefanno for joining us well bye bye thank you thank you very much
https://www.youtube.com/watch?v=kRPTNuUfFAE