Better together

1Security + Splunk.

Splunk turned machine data into a discipline: thousands of sources at terabyte scale, one search language over all of it, alerts ranked by risk instead of arrival time. 1Security adds the layer that never emits anything for Splunk to index: the standing permissions of your Microsoft 365 tenant - who can reach what, through which grant, and whether they ever needed to.

Credit where due

What Splunk does well.

The index that built the modern SOC, and a detection practice run on top of it like engineering.

  • Any data, at terabyte scale

    Splunk Enterprise collects machine data from thousands of sources at terabyte scale, with more than 2,300 out-of-the-box integrations and one search language to interrogate all of it. If it happened and it was logged, a search will find it.

  • Alerts ranked by risk

    Splunk Enterprise Security unifies SIEM, SOAR and UEBA into one threat detection, investigation and response platform. Risk-based alerting cuts alert volumes by up to 90%, so analysts work genuine threats instead of a queue of noise.

  • Detection as a discipline

    Detection Studio manages the detection lifecycle end to end, with coverage mapped to the MITRE ATT&CK framework and Cisco Talos threat intelligence enriching it at no additional cost. Detection engineering, run like engineering.

The design boundary

The index answers what arrived.

Splunk’s contract is beautifully simple: if a system emitted it, Splunk indexes it, and a search will answer questions about it for as long as you keep it. That contract built the modern SOC, and nothing about it needs fixing.

But the permissions inside Microsoft 365 never emit anything. A sharing link created in 2023 is silent tonight. A nested group extends reach to a site no event ever mentions. An identity’s real blast radius is assembled from direct grants, sharing links, group memberships and inheritance - state, not events. It never arrives at the indexer, so no search can return it. 70% of breaches exploit excessive permissions; 98% of granted permissions are never needed at all.

That’s the boundary: an archive, not a witness. Splunk stores and searches the record of what happened; who can reach what, right now, lives outside the record - by design, not by omission.

The map

What 1Security adds.

1Security is a permission-centric decision engine for Microsoft 365: it maps every identity - human, app, AI agent, device - what it can reach, and what it actually did.

  1. 01

    The permission graph

    Every file, site and mailbox an account can reach - direct grants, sharing links, groups, inheritance - resolved in minutes. A blast-radius investigation that used to take 12 hours now takes 10 minutes.

  2. 02

    Memory with an identity attached

    Per-identity behavior baselines over three years of activity history, with anomaly episodes and an alert line you position yourself. When a detection names an account, its normal is already established.

  3. 03

    Devices and origins, reconstructed

    Shadow devices rebuilt from real activity by a stable fingerprint - no Intune enrollment required. Every action enriched with location and ASN, Microsoft’s own datacenter noise labelled out.

  4. 04

    Findings that end in a fix

    Revoke the access, expire the links, sever the sessions - automations with grace periods and review queues, so nothing irreversible happens without a human decision.

Joint architecture

The index and the map.

Splunk keeps the organization-wide record and the SOC workflow - the index, the detections, the automated response. 1Security connects to your Microsoft 365 tenant with read-only consent - no agents, standard Microsoft licenses, first findings the same day - and maintains the map the index was never sent: the resolved permission graph and per-identity baselines. When a Splunk detection names an account, the analyst pivots to 1Security for its blast radius and its history, then closes the loop with remediation that queues for human review. The index states what happened; the map states what it can touch.

  • Same day
    from read-only consent to first findings
  • 12h → 10 min
    a blast-radius investigation, before and after
  • Standard
    Microsoft licenses - no E5 prerequisite

Joint use case

NIS2 gives you 24 hours.

NIS2 Article 23 puts significant incidents on a clock: an early warning within 24 hours of awareness, a full incident notification within 72, a final report after. What the regulator wants inside those windows isn’t prose - it’s scope: what was hit, how severe, what impact.

Together the two products fill the windows with facts. Splunk establishes the event chain: when the incident started, which systems were involved, what the detections and the automated response did about it. 1Security establishes the reach: every file, site and mailbox the affected identity could touch - resolved in minutes, not reconstructed against the deadline - and what it actually touched, measured against three years of its own baseline.

The early warning ships with real scope in it. The 72-hour notification cites a permission graph, not an estimate - and the remediation that follows is queued, reviewed and recorded.

Keep the index. Add the map.

Splunk already answers what happened. See what changes when the permissions underneath are resolved - every identity, every grant, every blast radius on demand.

Or keep estimating impact while the 24-hour clock runs.