SlideShare a Scribd company logo
Copyright	
  ©	
  2014	
  Splunk	
  Inc.	
  
Ma:hias	
  Maier	
  
Sales	
  Engineer,	
  Splunk	
  
Dashboard	
  Fun	
  	
  
	
  
CreaCng	
  an	
  interacCve	
  
TransacCon	
  Profiler	
  
Disclaimer	
  
2	
  
During	
  the	
  course	
  of	
  this	
  presentaCon,	
  we	
  may	
  make	
  forward-­‐looking	
  statements	
  regarding	
  future	
  events	
  or	
  the	
  
expected	
  performance	
  of	
  the	
  company.	
  We	
  cauCon	
  you	
  that	
  such	
  statements	
  reflect	
  our	
  current	
  expectaCons	
  and	
  
esCmates	
  based	
  on	
  factors	
  currently	
  known	
  to	
  us	
  and	
  that	
  actual	
  events	
  or	
  results	
  could	
  differ	
  materially.	
  For	
  
important	
  factors	
  that	
  may	
  cause	
  actual	
  results	
  to	
  differ	
  from	
  those	
  contained	
  in	
  our	
  forward-­‐looking	
  statements,	
  
please	
  review	
  our	
  filings	
  with	
  the	
  SEC.	
  The	
  forward-­‐looking	
  statements	
  made	
  in	
  the	
  this	
  presentaCon	
  are	
  being	
  made	
  as	
  
of	
  the	
  Cme	
  and	
  date	
  of	
  its	
  live	
  presentaCon.	
  If	
  reviewed	
  aPer	
  its	
  live	
  presentaCon,	
  this	
  presentaCon	
  may	
  not	
  contain	
  
current	
  or	
  accurate	
  informaCon.	
  We	
  do	
  not	
  assume	
  any	
  obligaCon	
  to	
  update	
  any	
  forward-­‐looking	
  statements	
  we	
  may	
  
make.	
  In	
  addiCon,	
  any	
  informaCon	
  about	
  our	
  roadmap	
  outlines	
  our	
  general	
  product	
  direcCon	
  and	
  is	
  subject	
  to	
  change	
  
at	
  any	
  Cme	
  without	
  noCce.	
  It	
  is	
  for	
  informaConal	
  purposes	
  only,	
  and	
  shall	
  not	
  be	
  incorporated	
  into	
  any	
  contract	
  or	
  
other	
  commitment.	
  Splunk	
  undertakes	
  no	
  obligaCon	
  either	
  to	
  develop	
  the	
  features	
  or	
  funcConality	
  described	
  or	
  to	
  
include	
  any	
  such	
  feature	
  or	
  funcConality	
  in	
  a	
  future	
  release.	
  
Who	
  I	
  am	
  
3	
  
!   Sales	
  Engineer	
  in	
  Germany	
  
! Splunker	
  nearly	
  2	
  years	
  
!   Like	
  to	
  get	
  hands	
  on	
  real	
  world	
  scenarios	
  
!   CISSP	
  
!   Worked	
  in	
  the	
  past	
  for	
  McAfee	
  (Security)	
  	
  
and	
  Tibco	
  (AnalyCcs)	
  
Self	
  AnalyCcs	
  /	
  TransacCon	
  Profiler	
  Dashboard	
  
•  Goals:	
  
–  Self	
  exploraCon	
  of	
  data	
  	
  
–  Gaining	
  Ideas	
  from	
  other	
  departmental	
  users	
  for	
  new	
  use	
  cases	
  and	
  
business	
  insight	
  
ê  “Do	
  we	
  have	
  this	
  informaCon	
  available?”	
  
ê  “Can	
  we	
  add	
  this?”	
  
ê  “Can	
  we	
  correlate	
  with	
  this?”	
  
–  How	
  to	
  get	
  to	
  this	
  stage?	
  
4	
  
Adding	
  Value	
  
5	
  
I	
  loaded	
  1.000.000	
  Records.	
  	
  
Start	
  to	
  add	
  value	
  for	
  other	
  departments	
  
You	
  might	
  want	
  to	
  provide	
  an	
  impressive	
  starCng	
  point	
  for	
  	
  
other	
  people	
  to	
  explore	
  the	
  Data	
  	
  
(Next	
  to	
  the	
  RAW	
  Searches	
  and	
  DATA	
  Models)	
  
Challenge	
  for	
  Machine	
  Data	
  in	
  Business	
  Context	
  
!   Not	
  every	
  user	
  who	
  can	
  benefit	
  might	
  have	
  SPLK	
  Language	
  skills	
  
!   Not	
  every	
  user	
  is	
  creaCve	
  with	
  data	
  in	
  the	
  first	
  step	
  
!   YOU	
  as	
  a	
  Splunk	
  Data	
  Analyst	
  might	
  not	
  be	
  able	
  to	
  interpret	
  business	
  
data	
  for	
  Business	
  Insights	
  
6	
  
DemonstraCon	
  
7	
  
Demo	
  (That	
  is	
  what	
  you	
  learn	
  	
  
how	
  to	
  create/get	
  this	
  aPer	
  my	
  session):	
  
Profiling	
  Dashboard	
  
TransacCon	
  Profiler	
  With	
  IP	
  Traffic	
  
8	
  
Start	
  With	
  One	
  Single	
  “TransacCon”	
  
1.  Search	
  and	
  InvesCgate	
  a	
  TransacCon	
  Field	
  	
  
‒  Filter	
  down	
  to	
  one	
  session	
  
	
  
9	
  
Sample	
  “transac7on”	
  fields	
  
Username	
  +	
  Session	
  InformaCon	
  
TransacCon	
  ID	
  
Order-­‐ID	
  
E-­‐Mail	
  Address	
  
Service	
  Name	
  
IP-­‐Address/Hostname/System	
  name	
  
Interview	
  
2.  Go	
  to	
  a	
  object	
  ma:er	
  expert	
  and	
  let	
  them	
  explain	
  what	
  happened	
  
in	
  this	
  session	
  
10	
  
DemonstraCon	
  
11	
  
Demo	
  
(raw	
  search,	
  explain	
  data-­‐set)	
  
	
  
TransacCon	
  Profiler	
  With	
  IP	
  Traffic	
  
12	
  
Create	
  Dashboards	
  
3.  Create	
  consistent	
  dashboards	
  by	
  using	
  some	
  of	
  the	
  following	
  
methods	
  
13	
  
Search	
   Descrip7on	
  
…	
  |	
  Cmechart	
  count	
   Easiest	
  one	
  ever	
  
…	
  |	
  stats	
  dc(<fieldname>)	
  by	
  <fieldname>	
   DisCnct	
  count	
  gives	
  a	
  lot	
  of	
  interesCng	
  insights:	
  
•  Why	
  is	
  this	
  user	
  logging	
  on	
  from	
  so	
  many	
  different	
  systems	
  
•  Why	
  has	
  this	
  transacCon	
  id	
  so	
  many	
  different	
  status	
  codes	
  
•  Why	
  is	
  this	
  IP	
  communicaCng	
  to	
  so	
  many	
  desCnaCon	
  ports	
  
…	
  |	
  transacCon	
  <fieldname>	
  |	
  table	
  
duraCon	
  
As	
  single	
  value	
  
How	
  long	
  did	
  it	
  take?	
  	
  
…	
  |	
  head	
  1	
  |	
  table	
  _Cme	
  
…	
  |	
  tail	
  1	
  |	
  table	
  _Cme	
  
•  When	
  was	
  the	
  first	
  “session”,	
  
•  When	
  was	
  the	
  last	
  “interacCon	
  with	
  the	
  system”	
  
DemonstraCon	
  
14	
  
Demo	
  
(dashboard	
  with	
  some	
  single	
  values	
  +	
  stats	
  +	
  	
  
Cme	
  charts	
  based	
  on	
  ONE	
  TransacCon)	
  
	
  
My	
  IP	
  Profiler	
  
15	
  
Create	
  Drop	
  Down	
  Lists	
  
4.  Create	
  drop	
  down	
  lists	
  and	
  input	
  fields	
  to	
  make	
  the	
  dashboard	
  
interacCve	
  
‒  Thanks	
  to	
  Version	
  6.1	
  it	
  can	
  be	
  done	
  via	
  the	
  Gui	
  without	
  coding	
  
‒  Review	
  the	
  dashboard	
  example	
  app	
  for	
  addiConal	
  visualizaCon	
  tricks	
  
5.  Tokenize	
  the	
  searches	
  to	
  make	
  them	
  flexible	
  
16	
  
DemonstraCon	
  
17	
  
Demo	
  
(add	
  free	
  text	
  field,	
  pickers	
  (dynamic),	
  token	
  
fields	
  +	
  replace	
  single	
  transacCon	
  id	
  with	
  token)	
  
	
  
My	
  IP	
  Profiler	
  
18	
  
Example	
  
19	
  
We	
  are	
  not	
  done	
  
6.  Make	
  sure	
  you	
  add	
  default	
  values	
  for	
  each	
  of	
  the	
  drop	
  down	
  
fields.	
  So	
  in	
  case	
  someone	
  wants	
  to	
  see	
  something,	
  you	
  guide	
  him	
  
to	
  the	
  right	
  choice	
  to	
  get	
  a	
  dashboard	
  populated.	
  
20	
  
DemonstraCon	
  
21	
  
Demo	
  
(add	
  default	
  values	
  and	
  show	
  first	
  user	
  
experience	
  accessing	
  the	
  dashboard)	
  
	
  
22	
  
23	
  
24	
  
TransacCon	
  Profiler	
  Use	
  Cases	
  for…	
  
!   Helpdesk	
  
!   Support	
  Desk	
  
!   Second	
  +	
  Third	
  Level	
  Support	
  
!   Developers	
  of	
  In	
  House	
  
ApplicaCons	
  
!   Service	
  Level	
  Manager	
  
!   MarkeCng	
  Departments	
  
!   IT-­‐Security	
  /	
  SIEM	
  Use	
  Cases	
  
!   Business	
  Fraud	
  DetecCon	
  	
  
Search	
  and	
  InvesCgate	
  a	
  Single	
  
TransacCon	
  
Review	
  transacCon	
  with	
  a	
  
subject	
  ma:er	
  expert	
  from	
  the	
  
business	
  
Create	
  a	
  Dashboard	
  for	
  a	
  
single	
  transacCon	
  
Create	
  drop	
  downs	
  for	
  
exploraCon	
  Tokenize	
  the	
  searches	
  
Set	
  default	
  values	
  
Gain	
  new	
  ideas	
  and	
  business	
  
insight	
  from	
  Machine	
  Data	
  
• Give	
  this	
  in	
  the	
  hand’s	
  of	
  Business	
  
People	
  for	
  	
  
• gather	
  Feedback	
  and	
  tune	
  
Special	
  Offer:	
  Try	
  Splunk	
  MINT	
  Express	
  for	
  Free!	
  
Splunk	
  MINT	
  offers	
  a	
  fast	
  path	
  to	
  mobile	
  intelligence.	
  How	
  fast?	
  	
  
Find	
  out	
  with	
  a	
  6-­‐month	
  trial*	
  
•  Register	
  for	
  your	
  free	
  trial:	
  
h:p://mint.splunk.com/conf2014offer	
  
•  Download	
  the	
  Splunk	
  MINT	
  SDKs	
  
•  Add	
  the	
  Splunk	
  MINT	
  line	
  of	
  SDK	
  code	
  
and	
  publish**	
  	
  
•  Start	
  gexng	
  digital	
  intelligence	
  at	
  your	
  
fingerCps!	
  
	
  
*Offer	
  valid	
  for	
  .conf2014	
  a5endees	
  and	
  coworkers	
  of	
  a5endees	
  only.	
  
**Trial	
  allows	
  monitoring	
  of	
  up	
  to	
  750,000	
  monthly	
  acDve	
  users	
  (MAUs).	
  
	
  
25	
  
THANK	
  YOU	
  
Contact:	
  
ma:hias@splunk.com	
  

More Related Content

What's hot (20)

PPTX
SplunkLive! Splunk App for VMware
Splunk
 
PPTX
Getting started with Splunk - Break out Session
Georg Knon
 
PPTX
Machine Data 101 Hands-on
Splunk
 
PPTX
SplunkLive! Splunk for IT Operations
Splunk
 
PPTX
Splunk for IT Operations
Splunk
 
PPTX
Splunk Enterprise for IT Troubleshooting
Splunk
 
PPTX
SplunkLive! Utrecht 2016 - NXP
Splunk
 
PPTX
Splunk for ITOps
Splunk
 
PPTX
Splunk Tutorial for Beginners - What is Splunk | Edureka
Edureka!
 
PPTX
SplunkLive! - Splunk for Security
Splunk
 
PPTX
Level Up Your Security Skills in Splunk Enterprise
Splunk
 
PPTX
Splunk Overview
Splunk
 
PDF
Splunk Webinar Best Practices für Incident Investigation
Georg Knon
 
PDF
SplunkLive! München 2016 - Splunk für Security
Splunk
 
PDF
SplunkLive! London - Splunk App for Stream & MINT Breakout
Splunk
 
PPTX
SplunkLive! München 2016 - Splunk für IT Operations
Splunk
 
PPTX
Splunk for IT Operations Breakout Session
Georg Knon
 
PPTX
Splunk for IT Operations
Splunk
 
PPTX
What's New in 6.3 + Data On-Boarding
Splunk
 
PDF
Enterprise Security Guided Tour
Splunk
 
SplunkLive! Splunk App for VMware
Splunk
 
Getting started with Splunk - Break out Session
Georg Knon
 
Machine Data 101 Hands-on
Splunk
 
SplunkLive! Splunk for IT Operations
Splunk
 
Splunk for IT Operations
Splunk
 
Splunk Enterprise for IT Troubleshooting
Splunk
 
SplunkLive! Utrecht 2016 - NXP
Splunk
 
Splunk for ITOps
Splunk
 
Splunk Tutorial for Beginners - What is Splunk | Edureka
Edureka!
 
SplunkLive! - Splunk for Security
Splunk
 
Level Up Your Security Skills in Splunk Enterprise
Splunk
 
Splunk Overview
Splunk
 
Splunk Webinar Best Practices für Incident Investigation
Georg Knon
 
SplunkLive! München 2016 - Splunk für Security
Splunk
 
SplunkLive! London - Splunk App for Stream & MINT Breakout
Splunk
 
SplunkLive! München 2016 - Splunk für IT Operations
Splunk
 
Splunk for IT Operations Breakout Session
Georg Knon
 
Splunk for IT Operations
Splunk
 
What's New in 6.3 + Data On-Boarding
Splunk
 
Enterprise Security Guided Tour
Splunk
 

Viewers also liked (20)

PPTX
Splunking the JVM
Damien Dallimore
 
PDF
Splunk conf2014 - Lesser Known Commands in Splunk Search Processing Language ...
Splunk
 
PPTX
Splunk Java Agent
Damien Dallimore
 
PPTX
Splunk for JMX
Damien Dallimore
 
PDF
Splunk Insights
Sunil Kumar
 
PPTX
Splunk overview
Daniel Hernandez
 
PPTX
Getting Started with Splunk Break out Session
Georg Knon
 
PPTX
Splunk Conf 2014 - Splunking the Java Virtual Machine
Damien Dallimore
 
PPTX
SplunkLive! Getting Started with Splunk Enterprise
Splunk
 
PPTX
Getting Started with Splunk Enterprise
Splunk
 
PPTX
SplunkLive 2011 Advanced Session
Splunk
 
PDF
Splunk Enterprise for IT Troubleshooting Hands-On
Splunk
 
PPTX
Webinar: Vulnerability Management leicht gemacht – mit Splunk und Qualys
Georg Knon
 
PPTX
SplunkLive 2011 Beginners Session
Splunk
 
PDF
QualysGuard InfoDay 2014 - QualysGuard Web Application Security a Web Applica...
Risk Analysis Consultants, s.r.o.
 
DOCX
Getting Started with Splunk Enterprise - Demo
Splunk
 
PPT
Learn Dashing Widget in 90 minutes
Larry Cai
 
PDF
Splunk Enterprise for IT Troubleshooting
Splunk
 
PDF
Best Practices for Network Security Management
Skybox Security
 
PPTX
Insider Threat Kill Chain: Detecting Human Indicators of Compromise
Tripwire
 
Splunking the JVM
Damien Dallimore
 
Splunk conf2014 - Lesser Known Commands in Splunk Search Processing Language ...
Splunk
 
Splunk Java Agent
Damien Dallimore
 
Splunk for JMX
Damien Dallimore
 
Splunk Insights
Sunil Kumar
 
Splunk overview
Daniel Hernandez
 
Getting Started with Splunk Break out Session
Georg Knon
 
Splunk Conf 2014 - Splunking the Java Virtual Machine
Damien Dallimore
 
SplunkLive! Getting Started with Splunk Enterprise
Splunk
 
Getting Started with Splunk Enterprise
Splunk
 
SplunkLive 2011 Advanced Session
Splunk
 
Splunk Enterprise for IT Troubleshooting Hands-On
Splunk
 
Webinar: Vulnerability Management leicht gemacht – mit Splunk und Qualys
Georg Knon
 
SplunkLive 2011 Beginners Session
Splunk
 
QualysGuard InfoDay 2014 - QualysGuard Web Application Security a Web Applica...
Risk Analysis Consultants, s.r.o.
 
Getting Started with Splunk Enterprise - Demo
Splunk
 
Learn Dashing Widget in 90 minutes
Larry Cai
 
Splunk Enterprise for IT Troubleshooting
Splunk
 
Best Practices for Network Security Management
Skybox Security
 
Insider Threat Kill Chain: Detecting Human Indicators of Compromise
Tripwire
 
Ad

Similar to Splunk conf2014 - Dashboard Fun - Creating an Interactive Transaction Profiler (20)

PDF
Splunk Data Onboarding Overview - Splunk Data Collection Architecture
Splunk
 
PPTX
SplunkLive! Frankfurt 2018 - Data Onboarding Overview
Splunk
 
PDF
Apache Flink Adoption at Shopify
Yaroslav Tkachenko
 
PPTX
SplunkLive! Munich 2018: Data Onboarding Overview
Splunk
 
PDF
SplunkSummit 2015 - Security Ninjitsu
Splunk
 
PPTX
.conf21 - The Best of
Splunk
 
PPTX
Asynchronous Apex Salesforce World Tour Paris 2015
Samuel De Rycke
 
PPTX
Getting Started with Splunk Enterprise
Splunk
 
PDF
Qwasi Splunk and NCR Integration: Business Analytics
Timur Bagirov
 
PDF
ChatGPT and Beyond - Elevating DevOps Productivity
VictorSzoltysek
 
PPTX
TrailblazerDX Motihari.pptx
Om Prakash
 
PDF
Why Distributed Tracing is Essential for Performance and Reliability
Aggregage
 
PDF
Confluent Partner Tech Talk with Synthesis
confluent
 
DOC
Resume Manoj Kumar M
Manoj Kumar
 
PDF
Design Patterns Every ISV Needs to Know (October 15, 2014)
Salesforce Partners
 
PDF
When Data Visualizations and Data Imports Just Don’t Work
Jim Kaplan CIA CFE
 
PDF
Salesforce Admin Group-Barcelona-2022-07-05 In-person Meetup-BCN Admins Group
animuscrm
 
PPTX
SplunkLive! Frankfurt 2018 - Monitoring the End User Experience with Splunk
Splunk
 
PPTX
01 #awesome admin tdx19 global gatherings highlights for admins final
szurley
 
PPTX
TrailheaDX and Summer '19: Developer Highlights
Salesforce Developers
 
Splunk Data Onboarding Overview - Splunk Data Collection Architecture
Splunk
 
SplunkLive! Frankfurt 2018 - Data Onboarding Overview
Splunk
 
Apache Flink Adoption at Shopify
Yaroslav Tkachenko
 
SplunkLive! Munich 2018: Data Onboarding Overview
Splunk
 
SplunkSummit 2015 - Security Ninjitsu
Splunk
 
.conf21 - The Best of
Splunk
 
Asynchronous Apex Salesforce World Tour Paris 2015
Samuel De Rycke
 
Getting Started with Splunk Enterprise
Splunk
 
Qwasi Splunk and NCR Integration: Business Analytics
Timur Bagirov
 
ChatGPT and Beyond - Elevating DevOps Productivity
VictorSzoltysek
 
TrailblazerDX Motihari.pptx
Om Prakash
 
Why Distributed Tracing is Essential for Performance and Reliability
Aggregage
 
Confluent Partner Tech Talk with Synthesis
confluent
 
Resume Manoj Kumar M
Manoj Kumar
 
Design Patterns Every ISV Needs to Know (October 15, 2014)
Salesforce Partners
 
When Data Visualizations and Data Imports Just Don’t Work
Jim Kaplan CIA CFE
 
Salesforce Admin Group-Barcelona-2022-07-05 In-person Meetup-BCN Admins Group
animuscrm
 
SplunkLive! Frankfurt 2018 - Monitoring the End User Experience with Splunk
Splunk
 
01 #awesome admin tdx19 global gatherings highlights for admins final
szurley
 
TrailheaDX and Summer '19: Developer Highlights
Salesforce Developers
 
Ad

More from Splunk (20)

PDF
Splunk Leadership Forum Wien - 20.05.2025
Splunk
 
PDF
Splunk Security Update | Public Sector Summit Germany 2025
Splunk
 
PDF
Building Resilience with Energy Management for the Public Sector
Splunk
 
PDF
IT-Lagebild: Observability for Resilience (SVA)
Splunk
 
PDF
Nach dem SOC-Aufbau ist vor der Automatisierung (OFD Baden-Württemberg)
Splunk
 
PDF
Monitoring einer Sicheren Inter-Netzwerk Architektur (SINA)
Splunk
 
PDF
Praktische Erfahrungen mit dem Attack Analyser (gematik)
Splunk
 
PDF
Cisco XDR & Splunk SIEM - stronger together (DATAGROUP Cyber Security)
Splunk
 
PDF
Security - Mit Sicherheit zum Erfolg (Telekom)
Splunk
 
PDF
One Cisco - Splunk Public Sector Summit Germany April 2025
Splunk
 
PDF
.conf Go 2023 - Data analysis as a routine
Splunk
 
PDF
.conf Go 2023 - How KPN drives Customer Satisfaction on IPTV
Splunk
 
PDF
.conf Go 2023 - Navegando la normativa SOX (Telefónica)
Splunk
 
PDF
.conf Go 2023 - Raiffeisen Bank International
Splunk
 
PDF
.conf Go 2023 - På liv og død Om sikkerhetsarbeid i Norsk helsenett
Splunk
 
PDF
.conf Go 2023 - Many roads lead to Rome - this was our journey (Julius Bär)
Splunk
 
PDF
.conf Go 2023 - Das passende Rezept für die digitale (Security) Revolution zu...
Splunk
 
PDF
.conf go 2023 - Cyber Resilienz – Herausforderungen und Ansatz für Energiever...
Splunk
 
PDF
.conf go 2023 - De NOC a CSIRT (Cellnex)
Splunk
 
PDF
conf go 2023 - El camino hacia la ciberseguridad (ABANCA)
Splunk
 
Splunk Leadership Forum Wien - 20.05.2025
Splunk
 
Splunk Security Update | Public Sector Summit Germany 2025
Splunk
 
Building Resilience with Energy Management for the Public Sector
Splunk
 
IT-Lagebild: Observability for Resilience (SVA)
Splunk
 
Nach dem SOC-Aufbau ist vor der Automatisierung (OFD Baden-Württemberg)
Splunk
 
Monitoring einer Sicheren Inter-Netzwerk Architektur (SINA)
Splunk
 
Praktische Erfahrungen mit dem Attack Analyser (gematik)
Splunk
 
Cisco XDR & Splunk SIEM - stronger together (DATAGROUP Cyber Security)
Splunk
 
Security - Mit Sicherheit zum Erfolg (Telekom)
Splunk
 
One Cisco - Splunk Public Sector Summit Germany April 2025
Splunk
 
.conf Go 2023 - Data analysis as a routine
Splunk
 
.conf Go 2023 - How KPN drives Customer Satisfaction on IPTV
Splunk
 
.conf Go 2023 - Navegando la normativa SOX (Telefónica)
Splunk
 
.conf Go 2023 - Raiffeisen Bank International
Splunk
 
.conf Go 2023 - På liv og død Om sikkerhetsarbeid i Norsk helsenett
Splunk
 
.conf Go 2023 - Many roads lead to Rome - this was our journey (Julius Bär)
Splunk
 
.conf Go 2023 - Das passende Rezept für die digitale (Security) Revolution zu...
Splunk
 
.conf go 2023 - Cyber Resilienz – Herausforderungen und Ansatz für Energiever...
Splunk
 
.conf go 2023 - De NOC a CSIRT (Cellnex)
Splunk
 
conf go 2023 - El camino hacia la ciberseguridad (ABANCA)
Splunk
 

Recently uploaded (20)

PPTX
Introduction to Flutter by Ayush Desai.pptx
ayushdesai204
 
PDF
Research-Fundamentals-and-Topic-Development.pdf
ayesha butalia
 
PDF
Responsible AI and AI Ethics - By Sylvester Ebhonu
Sylvester Ebhonu
 
PDF
Brief History of Internet - Early Days of Internet
sutharharshit158
 
PPTX
Applied-Statistics-Mastering-Data-Driven-Decisions.pptx
parmaryashparmaryash
 
PDF
NewMind AI Weekly Chronicles – July’25, Week III
NewMind AI
 
PPTX
The Future of AI & Machine Learning.pptx
pritsen4700
 
PPTX
AI in Daily Life: How Artificial Intelligence Helps Us Every Day
vanshrpatil7
 
PDF
Structs to JSON: How Go Powers REST APIs
Emily Achieng
 
PDF
How ETL Control Logic Keeps Your Pipelines Safe and Reliable.pdf
Stryv Solutions Pvt. Ltd.
 
PDF
TrustArc Webinar - Navigating Data Privacy in LATAM: Laws, Trends, and Compli...
TrustArc
 
PPTX
Agile Chennai 18-19 July 2025 | Emerging patterns in Agentic AI by Bharani Su...
AgileNetwork
 
PPTX
Agile Chennai 18-19 July 2025 | Workshop - Enhancing Agile Collaboration with...
AgileNetwork
 
PPTX
What-is-the-World-Wide-Web -- Introduction
tonifi9488
 
PPTX
AI and Robotics for Human Well-being.pptx
JAYMIN SUTHAR
 
PDF
Generative AI vs Predictive AI-The Ultimate Comparison Guide
Lily Clark
 
PPTX
Dev Dives: Automate, test, and deploy in one place—with Unified Developer Exp...
AndreeaTom
 
PPTX
OA presentation.pptx OA presentation.pptx
pateldhruv002338
 
PPTX
Farrell_Programming Logic and Design slides_10e_ch02_PowerPoint.pptx
bashnahara11
 
PDF
Economic Impact of Data Centres to the Malaysian Economy
flintglobalapac
 
Introduction to Flutter by Ayush Desai.pptx
ayushdesai204
 
Research-Fundamentals-and-Topic-Development.pdf
ayesha butalia
 
Responsible AI and AI Ethics - By Sylvester Ebhonu
Sylvester Ebhonu
 
Brief History of Internet - Early Days of Internet
sutharharshit158
 
Applied-Statistics-Mastering-Data-Driven-Decisions.pptx
parmaryashparmaryash
 
NewMind AI Weekly Chronicles – July’25, Week III
NewMind AI
 
The Future of AI & Machine Learning.pptx
pritsen4700
 
AI in Daily Life: How Artificial Intelligence Helps Us Every Day
vanshrpatil7
 
Structs to JSON: How Go Powers REST APIs
Emily Achieng
 
How ETL Control Logic Keeps Your Pipelines Safe and Reliable.pdf
Stryv Solutions Pvt. Ltd.
 
TrustArc Webinar - Navigating Data Privacy in LATAM: Laws, Trends, and Compli...
TrustArc
 
Agile Chennai 18-19 July 2025 | Emerging patterns in Agentic AI by Bharani Su...
AgileNetwork
 
Agile Chennai 18-19 July 2025 | Workshop - Enhancing Agile Collaboration with...
AgileNetwork
 
What-is-the-World-Wide-Web -- Introduction
tonifi9488
 
AI and Robotics for Human Well-being.pptx
JAYMIN SUTHAR
 
Generative AI vs Predictive AI-The Ultimate Comparison Guide
Lily Clark
 
Dev Dives: Automate, test, and deploy in one place—with Unified Developer Exp...
AndreeaTom
 
OA presentation.pptx OA presentation.pptx
pateldhruv002338
 
Farrell_Programming Logic and Design slides_10e_ch02_PowerPoint.pptx
bashnahara11
 
Economic Impact of Data Centres to the Malaysian Economy
flintglobalapac
 

Splunk conf2014 - Dashboard Fun - Creating an Interactive Transaction Profiler

  • 1. Copyright  ©  2014  Splunk  Inc.   Ma:hias  Maier   Sales  Engineer,  Splunk   Dashboard  Fun       CreaCng  an  interacCve   TransacCon  Profiler  
  • 2. Disclaimer   2   During  the  course  of  this  presentaCon,  we  may  make  forward-­‐looking  statements  regarding  future  events  or  the   expected  performance  of  the  company.  We  cauCon  you  that  such  statements  reflect  our  current  expectaCons  and   esCmates  based  on  factors  currently  known  to  us  and  that  actual  events  or  results  could  differ  materially.  For   important  factors  that  may  cause  actual  results  to  differ  from  those  contained  in  our  forward-­‐looking  statements,   please  review  our  filings  with  the  SEC.  The  forward-­‐looking  statements  made  in  the  this  presentaCon  are  being  made  as   of  the  Cme  and  date  of  its  live  presentaCon.  If  reviewed  aPer  its  live  presentaCon,  this  presentaCon  may  not  contain   current  or  accurate  informaCon.  We  do  not  assume  any  obligaCon  to  update  any  forward-­‐looking  statements  we  may   make.  In  addiCon,  any  informaCon  about  our  roadmap  outlines  our  general  product  direcCon  and  is  subject  to  change   at  any  Cme  without  noCce.  It  is  for  informaConal  purposes  only,  and  shall  not  be  incorporated  into  any  contract  or   other  commitment.  Splunk  undertakes  no  obligaCon  either  to  develop  the  features  or  funcConality  described  or  to   include  any  such  feature  or  funcConality  in  a  future  release.  
  • 3. Who  I  am   3   !   Sales  Engineer  in  Germany   ! Splunker  nearly  2  years   !   Like  to  get  hands  on  real  world  scenarios   !   CISSP   !   Worked  in  the  past  for  McAfee  (Security)     and  Tibco  (AnalyCcs)  
  • 4. Self  AnalyCcs  /  TransacCon  Profiler  Dashboard   •  Goals:   –  Self  exploraCon  of  data     –  Gaining  Ideas  from  other  departmental  users  for  new  use  cases  and   business  insight   ê  “Do  we  have  this  informaCon  available?”   ê  “Can  we  add  this?”   ê  “Can  we  correlate  with  this?”   –  How  to  get  to  this  stage?   4  
  • 5. Adding  Value   5   I  loaded  1.000.000  Records.     Start  to  add  value  for  other  departments  
  • 6. You  might  want  to  provide  an  impressive  starCng  point  for     other  people  to  explore  the  Data     (Next  to  the  RAW  Searches  and  DATA  Models)   Challenge  for  Machine  Data  in  Business  Context   !   Not  every  user  who  can  benefit  might  have  SPLK  Language  skills   !   Not  every  user  is  creaCve  with  data  in  the  first  step   !   YOU  as  a  Splunk  Data  Analyst  might  not  be  able  to  interpret  business   data  for  Business  Insights   6  
  • 7. DemonstraCon   7   Demo  (That  is  what  you  learn     how  to  create/get  this  aPer  my  session):   Profiling  Dashboard  
  • 8. TransacCon  Profiler  With  IP  Traffic   8  
  • 9. Start  With  One  Single  “TransacCon”   1.  Search  and  InvesCgate  a  TransacCon  Field     ‒  Filter  down  to  one  session     9   Sample  “transac7on”  fields   Username  +  Session  InformaCon   TransacCon  ID   Order-­‐ID   E-­‐Mail  Address   Service  Name   IP-­‐Address/Hostname/System  name  
  • 10. Interview   2.  Go  to  a  object  ma:er  expert  and  let  them  explain  what  happened   in  this  session   10  
  • 11. DemonstraCon   11   Demo   (raw  search,  explain  data-­‐set)    
  • 12. TransacCon  Profiler  With  IP  Traffic   12  
  • 13. Create  Dashboards   3.  Create  consistent  dashboards  by  using  some  of  the  following   methods   13   Search   Descrip7on   …  |  Cmechart  count   Easiest  one  ever   …  |  stats  dc(<fieldname>)  by  <fieldname>   DisCnct  count  gives  a  lot  of  interesCng  insights:   •  Why  is  this  user  logging  on  from  so  many  different  systems   •  Why  has  this  transacCon  id  so  many  different  status  codes   •  Why  is  this  IP  communicaCng  to  so  many  desCnaCon  ports   …  |  transacCon  <fieldname>  |  table   duraCon   As  single  value   How  long  did  it  take?     …  |  head  1  |  table  _Cme   …  |  tail  1  |  table  _Cme   •  When  was  the  first  “session”,   •  When  was  the  last  “interacCon  with  the  system”  
  • 14. DemonstraCon   14   Demo   (dashboard  with  some  single  values  +  stats  +     Cme  charts  based  on  ONE  TransacCon)    
  • 16. Create  Drop  Down  Lists   4.  Create  drop  down  lists  and  input  fields  to  make  the  dashboard   interacCve   ‒  Thanks  to  Version  6.1  it  can  be  done  via  the  Gui  without  coding   ‒  Review  the  dashboard  example  app  for  addiConal  visualizaCon  tricks   5.  Tokenize  the  searches  to  make  them  flexible   16  
  • 17. DemonstraCon   17   Demo   (add  free  text  field,  pickers  (dynamic),  token   fields  +  replace  single  transacCon  id  with  token)    
  • 20. We  are  not  done   6.  Make  sure  you  add  default  values  for  each  of  the  drop  down   fields.  So  in  case  someone  wants  to  see  something,  you  guide  him   to  the  right  choice  to  get  a  dashboard  populated.   20  
  • 21. DemonstraCon   21   Demo   (add  default  values  and  show  first  user   experience  accessing  the  dashboard)    
  • 22. 22  
  • 23. 23  
  • 24. 24   TransacCon  Profiler  Use  Cases  for…   !   Helpdesk   !   Support  Desk   !   Second  +  Third  Level  Support   !   Developers  of  In  House   ApplicaCons   !   Service  Level  Manager   !   MarkeCng  Departments   !   IT-­‐Security  /  SIEM  Use  Cases   !   Business  Fraud  DetecCon     Search  and  InvesCgate  a  Single   TransacCon   Review  transacCon  with  a   subject  ma:er  expert  from  the   business   Create  a  Dashboard  for  a   single  transacCon   Create  drop  downs  for   exploraCon  Tokenize  the  searches   Set  default  values   Gain  new  ideas  and  business   insight  from  Machine  Data   • Give  this  in  the  hand’s  of  Business   People  for     • gather  Feedback  and  tune  
  • 25. Special  Offer:  Try  Splunk  MINT  Express  for  Free!   Splunk  MINT  offers  a  fast  path  to  mobile  intelligence.  How  fast?     Find  out  with  a  6-­‐month  trial*   •  Register  for  your  free  trial:   h:p://mint.splunk.com/conf2014offer   •  Download  the  Splunk  MINT  SDKs   •  Add  the  Splunk  MINT  line  of  SDK  code   and  publish**     •  Start  gexng  digital  intelligence  at  your   fingerCps!     *Offer  valid  for  .conf2014  a5endees  and  coworkers  of  a5endees  only.   **Trial  allows  monitoring  of  up  to  750,000  monthly  acDve  users  (MAUs).     25