SlideShare a Scribd company logo
Copyright	
  ©	
  2014	
  Splunk	
  Inc.	
  
Bernie	
  Macias	
  
Applied	
  Architect,	
  Nordstrom	
  
Mobile	
  POS,	
  DevOps	
  
and	
  the	
  Role	
  of	
  
Splunk	
  
Disclaimer	
  
2	
  
During	
  the	
  course	
  of	
  this	
  presentaIon,	
  we	
  may	
  make	
  forward-­‐looking	
  statements	
  regarding	
  future	
  events	
  or	
  the	
  
expected	
  performance	
  of	
  the	
  company.	
  We	
  cauIon	
  you	
  that	
  such	
  statements	
  reflect	
  our	
  current	
  expectaIons	
  and	
  
esImates	
  based	
  on	
  factors	
  currently	
  known	
  to	
  us	
  and	
  that	
  actual	
  events	
  or	
  results	
  could	
  differ	
  materially.	
  For	
  
important	
  factors	
  that	
  may	
  cause	
  actual	
  results	
  to	
  differ	
  from	
  those	
  contained	
  in	
  our	
  forward-­‐looking	
  statements,	
  
please	
  review	
  our	
  filings	
  with	
  the	
  SEC.	
  The	
  forward-­‐looking	
  statements	
  made	
  in	
  the	
  this	
  presentaIon	
  are	
  being	
  made	
  as	
  
of	
  the	
  Ime	
  and	
  date	
  of	
  its	
  live	
  presentaIon.	
  If	
  reviewed	
  aTer	
  its	
  live	
  presentaIon,	
  this	
  presentaIon	
  may	
  not	
  contain	
  
current	
  or	
  accurate	
  informaIon.	
  We	
  do	
  not	
  assume	
  any	
  obligaIon	
  to	
  update	
  any	
  forward-­‐looking	
  statements	
  we	
  may	
  
make.	
  In	
  addiIon,	
  any	
  informaIon	
  about	
  our	
  roadmap	
  outlines	
  our	
  general	
  product	
  direcIon	
  and	
  is	
  subject	
  to	
  change	
  
at	
  any	
  Ime	
  without	
  noIce.	
  It	
  is	
  for	
  informaIonal	
  purposes	
  only,	
  and	
  shall	
  not	
  be	
  incorporated	
  into	
  any	
  contract	
  or	
  
other	
  commitment.	
  Splunk	
  undertakes	
  no	
  obligaIon	
  either	
  to	
  develop	
  the	
  features	
  or	
  funcIonality	
  described	
  or	
  to	
  
include	
  any	
  such	
  feature	
  or	
  funcIonality	
  in	
  a	
  future	
  release.	
  
Who	
  Am	
  I?	
  
!   Current	
  PosiIon:	
  1+	
  years	
  
–  Applied	
  Architect	
  
!   Past	
  Experience:	
  Since	
  2005	
  
–  Tech	
  support,	
  Windows	
  system	
  admin,	
  windows	
  
system	
  engineer,	
  system	
  architect,	
  Unix	
  analyst	
  
! Splunk	
  Experience:	
  3+	
  years	
  
–  Deployed	
  approved	
  Splunk	
  architecture	
  at	
  Capital	
  One	
  	
  
–  Started	
  the	
  Splunk>	
  Sea^le	
  user	
  group	
  
!   Other	
  Tech	
  Interests:	
  Ongoing	
  
–  Python,	
  Django,	
  Data	
  visualizaIon	
  (d3.js),	
  Open	
  Stack	
  
• 3	
  
Agenda	
  
!   About	
  Nordstrom	
  
!   What s	
  Nordstrom	
  Doing	
  with	
  Splunk?	
  
!   Managing	
  and	
  Scaling	
  Splunk	
  
! DevOps	
  on	
  Splunk	
  	
  
!   What	
  About	
  the	
  Users?	
  (Gecng	
  the	
  Users	
  Involved)	
  
	
  
4	
  
About	
  Nordstrom	
  
!   Founded	
  by	
  John	
  W.	
  Nordstrom	
  in	
  1901	
  
!   Over	
  260	
  stores	
  in	
  US	
  and	
  Canada	
  
! eCommerce:	
  Nordstrom.com,	
  
NordstromRack.com,	
  HauteLook.com	
  
!   65,000	
  employees;	
  over	
  1,000	
  in	
  IT	
  
!   MulIple	
  data	
  centers	
  with	
  an	
  eye	
  on	
  the	
  
cloud	
  or	
  mulI-­‐cloud	
  
! DevOps	
  mission:	
  scale,	
  manage,	
  and	
  
quickly	
  deliver	
  on	
  Nordstrom	
  iniIaIves	
  
• 5	
  
Omni-­‐channel	
  at	
  Nordstrom	
  
Deliver	
  a	
  Seamless	
  Customer	
  Experience	
  
6	
  
Nordstrom	
  Store	
   Nordstrom	
  Online	
  
Nordstrom	
  Rack	
  
Nordstrom	
  Rack	
  Online	
  /
Haute	
  Look	
  
Nordstrom	
  	
  
Omni-­‐Channel	
  
What’s	
  Nordstrom	
  
Doing	
  with	
  Splunk?	
  
Web	
  apps	
   OperaIonal	
  logs,	
  
system	
  logs,	
  Web	
  
logs,	
  Crash	
  logs	
  
Win/Unix	
  
metrics	
  
(2000+	
  servers)	
  
Chef	
  data	
  POS	
  and	
  
Wi-­‐Fi	
  data	
  
NNMi,	
  SCOM,	
  
Gomez	
  
Splunk	
  @	
  Nordstrom	
  
ConsolidaIon	
  of	
  all	
  our	
  machine	
  data	
  for	
  unified	
  visibility	
  
8	
  
Example:	
  Point	
  of	
  Sales	
  (POS)	
  
9	
  
•  New	
  customer	
  experience	
  
•  Faster	
  checkout	
  anywhere	
  in	
  store	
  
•  Small	
  real	
  estate	
  footprint	
  v.	
  
tradiIonal	
  POS	
  
Performance	
  Monitoring	
  of	
  POS	
  Devices	
  
10	
  
11	
  
POS	
  Inventory	
  Mapping	
  
11	
  
Splunk	
  AdopIon	
  Has	
  Been	
  Organic	
  and	
  Viral	
  
•  AgnosIc	
  to	
  technology	
  
•  Index	
  any	
  type	
  of	
  data	
  from	
  any	
  data	
  source	
  
•  Scalable	
  soluIon	
  	
  
SINGLE	
  SOURCE	
  OF	
  
TRUTH	
  
•  Accelerated	
  adopIon	
  with	
  300+	
  users	
  across	
  the	
  organizaIon	
  
•  Dev,	
  App,	
  NW,	
  Ops	
  and	
  global	
  offshore	
  teams	
  create	
  their	
  own	
  data	
  
inputs,	
  reports	
  and	
  dashboards	
  
EASE	
  OF	
  USE	
  
•  Role-­‐based	
  access	
  controls	
  to	
  provide	
  dev	
  teams	
  access	
  to	
  producIon	
  
logs	
  and	
  metrics	
  
•  Flexible	
  reporIng	
  	
  across	
  a	
  variety	
  of	
  use-­‐cases	
  
SECURE	
  &	
  FLEXBILE	
  
PLATFORM	
  
12	
  
AcceleraIng	
  Value	
  by	
  Using	
  Splunk	
  Apps	
  
!   Technology	
  Add-­‐ons:	
  
–  *nix	
  
–  Windows	
  
–  Cisco	
  IOS	
  
–  MicrosoT	
  Exchange	
  
!   Homegrown	
  App	
  
–  Splunk	
  for	
  Gomez	
  
–  Few	
  Django	
  Apps	
  
! Splunk	
  for	
  simple	
  XML	
  	
  
13	
  
Secng	
  the	
  Stage	
  for	
  
Managing	
  and	
  
Scaling	
  Splunk	
  
14	
  
How	
  Many	
  of	
  You	
  Would	
  Consider	
  Yourself…?	
  
15	
  
SYS	
  ADMIN	
   SPLUNK	
  ADMIN	
   SPLUNK	
  USER	
  
Distributed	
  Splunk	
  gets	
  complex	
  
16	
  
17	
  
All-in-One
Search
Indexers
FW
HFWSYSLOG
TCP
HTTP
FW
HFW
Pool
Storage
Search
Pool #1
Search
Pool #2
GA
Indexers
Pool
Storage
Secure
Indexers
Search
Pool #3
Pool
Storage
Indexers Indexers
FW
HFW
Managed Per
Available Zone
Forwarder/Agents
only send data to
Zone Specific
indexers
TOPOLOGIES	
  
OF	
  SPLUNK	
  
InstallaIon	
  and	
  ConfiguraIon	
  	
  
18	
  
Using	
  DevOps	
  
Principles	
  to	
  
Manage	
  Splunk	
  	
  
19	
  
Why	
  Not	
  DevOps	
  for	
  Splunk?	
  
20	
  
DevOps	
  Tools	
  
!   Config	
  Management	
  Plauorm	
  
!   Source	
  Control	
  
!   Dev	
  Environments	
  
! ConInuous	
  IntegraIon	
  
Tools	
  for	
  building	
  tools	
  spanning:	
  
21	
  
How	
  Many	
  Splunk	
  Components?	
  
!   NFS	
  Server	
  –	
  shared	
  search	
  head	
  storage	
  
!   Search	
  Head	
  –	
  searches	
  indexed	
  data	
  
!   Indexer	
  –	
  parsing	
  and	
  indexing	
  data	
  
!   Deployment	
  Server	
  –	
  App	
  Deployment	
  
!   Intermediate	
  forwarder	
  –	
  receiving	
  or	
  collect	
  
data	
  where	
  forwarder	
  cannot	
  be	
  install	
  directly	
  
!   Master	
  –	
  Cluster	
  and	
  ReplicaIon	
  Master	
  
!   Universal	
  Forwarder	
  –	
  local	
  collecIon	
  agent	
  
22	
  
nord_chef-­‐splunk:	
  	
  
a	
  CHEF	
  cookbook	
  
!   Ruby	
  code	
  that	
  models	
  distributed	
  Splunk	
  
(search,	
  index,	
  etc)	
  
!   Reuse	
  able	
  code	
  defined	
  by	
  a^ributes	
  
CONSISTENT,	
  SCALABLE,	
  REPEATABLE	
  
23	
  
What's	
  Automagically	
  Configured?	
  
•  Splunk	
  SSL	
  
•  TCP	
  and	
  UDP	
  listen	
  Ports	
  
•  Set	
  system	
  local	
  configs	
  
•  Distributed	
  Search	
  
•  Mounted	
  Bundles	
  
•  Indexers	
  aware	
  of	
  all	
  search	
  
pools	
  
•  And	
  More	
  
•  Move	
  default	
  DB	
  locaIons	
  
•  Add	
  user	
  and	
  change	
  Admin	
  
•  Splunk	
  servers	
  share	
  Secret	
  
•  Search	
  pooling	
  
•  Set	
  Deployment	
  Server	
  
•  Search	
  Heads	
  aware	
  of	
  Indexers	
  
•  Drives	
  configured	
  
•  Web	
  server	
  
24	
  
What	
  About	
  	
  
the	
  Users?	
  
25	
  
What	
  Can	
  Users	
  Do	
  In	
  Splunk?	
  
•  Create	
  private	
  objects	
  
•  Cannot	
  create/edit	
  global	
  
objects	
  directly	
  in	
  Splunk	
  
•  Dashboards?	
  Extracts?	
  Saved	
  
searches?	
  
26	
  
USE	
  GIT!	
  
CreaIng	
  a	
  Custom	
  GIT	
  CLI	
  
•  Downloaded	
  Web	
  Terminal	
  
for	
  Splunk	
  App	
  	
  
•  Installed	
  on	
  limited	
  
capability	
  search	
  head	
  
•  Customized	
  for	
  GIT	
  CLI	
  	
  
27	
  
Sample	
  Deployment	
  Workflow	
  
28	
  
Insert	
  Image(s)	
  
29	
  
Splunk	
  is	
  a	
  Journey	
  
What’s	
  Next?	
  
Special	
  Offer:	
  Try	
  Splunk	
  MINT	
  Express	
  for	
  Free!	
  
Splunk	
  MINT	
  offers	
  a	
  fast	
  path	
  to	
  mobile	
  intelligence.	
  How	
  fast?	
  	
  
Find	
  out	
  with	
  a	
  6-­‐month	
  trial*	
  
•  Register	
  for	
  your	
  free	
  trial:	
  
h^p://mint.splunk.com/conf2014offer	
  
•  Download	
  the	
  Splunk	
  MINT	
  SDKs	
  
•  Add	
  the	
  Splunk	
  MINT	
  line	
  of	
  SDK	
  code	
  
and	
  publish**	
  	
  
•  Start	
  gecng	
  digital	
  intelligence	
  at	
  your	
  
fingerIps!	
  
	
  
*Offer	
  valid	
  for	
  .conf2014	
  a5endees	
  and	
  coworkers	
  of	
  a5endees	
  only.	
  
**Trial	
  allows	
  monitoring	
  of	
  up	
  to	
  750,000	
  monthly	
  acDve	
  users	
  (MAUs).	
  
	
  
30	
  
THANK	
  YOU	
  
31	
  

More Related Content

PDF
Splunk in Yoox: Security and Compliance
Timur Bagirov
 
PDF
Splunk in Target: Internet of Things (Robot Analytics)
Timur Bagirov
 
PDF
Splunk in Rakuten: Splunk as a Service for all
Timur Bagirov
 
PDF
Qwasi Splunk and NCR Integration: Business Analytics
Timur Bagirov
 
PPTX
Elevate your Splunk Deployment by Better Understanding your Value Breakfast S...
Splunk
 
PPTX
Splunk for Developers Breakout Session
Splunk
 
PPTX
Machine Learning and Analytics Breakout Session
Splunk
 
PPTX
Taking Splunk to the Next Level - Manager
Splunk
 
Splunk in Yoox: Security and Compliance
Timur Bagirov
 
Splunk in Target: Internet of Things (Robot Analytics)
Timur Bagirov
 
Splunk in Rakuten: Splunk as a Service for all
Timur Bagirov
 
Qwasi Splunk and NCR Integration: Business Analytics
Timur Bagirov
 
Elevate your Splunk Deployment by Better Understanding your Value Breakfast S...
Splunk
 
Splunk for Developers Breakout Session
Splunk
 
Machine Learning and Analytics Breakout Session
Splunk
 
Taking Splunk to the Next Level - Manager
Splunk
 

What's hot (20)

PPTX
SplunkLive! - Splunk for IT Operations
Splunk
 
PPTX
Getting Started with Splunk Enterprise
Splunk
 
PPTX
How to Design, Build and Map IT and Business Services in Splunk
Splunk
 
PPTX
Splunk for Developers
Splunk
 
PPTX
Machine Learning and Analytics Breakout Session
Splunk
 
PDF
Herbalife Customer Presentation
Splunk
 
PPTX
Devops Powered by Splunk
Splunk
 
PPTX
Getting Started with Splunk Enterprise Hands-On
Splunk
 
PPTX
Splunk IT Service Intelligence
Georg Knon
 
PDF
Splunk Webinar: IT Operations Demo für Troubleshooting & Dashboarding
Georg Knon
 
PDF
Splunk at Scotiabank
Splunk
 
PPTX
IT Service Intelligence Hands On Breakout Session
Splunk
 
PPTX
Taking Splunk to the Next Level - Architecture
Splunk
 
PDF
SplunkLive! Austin Customer Presentation - Xerox
Splunk
 
PPTX
Splunk Ninjas: New Features and Search Dojo
Splunk
 
PPTX
SplunkLive! Paris 2018: Splunk Overview
Splunk
 
PDF
Getting Started with Splunk Enterprise Hands-On
Splunk
 
PPTX
SplunkLive! Tampa: Splunk for Security - Hands-On Session
Splunk
 
PPTX
SplunkLive! - Splunk for IT Operations
Splunk
 
PDF
Machine Data 101
Splunk
 
SplunkLive! - Splunk for IT Operations
Splunk
 
Getting Started with Splunk Enterprise
Splunk
 
How to Design, Build and Map IT and Business Services in Splunk
Splunk
 
Splunk for Developers
Splunk
 
Machine Learning and Analytics Breakout Session
Splunk
 
Herbalife Customer Presentation
Splunk
 
Devops Powered by Splunk
Splunk
 
Getting Started with Splunk Enterprise Hands-On
Splunk
 
Splunk IT Service Intelligence
Georg Knon
 
Splunk Webinar: IT Operations Demo für Troubleshooting & Dashboarding
Georg Knon
 
Splunk at Scotiabank
Splunk
 
IT Service Intelligence Hands On Breakout Session
Splunk
 
Taking Splunk to the Next Level - Architecture
Splunk
 
SplunkLive! Austin Customer Presentation - Xerox
Splunk
 
Splunk Ninjas: New Features and Search Dojo
Splunk
 
SplunkLive! Paris 2018: Splunk Overview
Splunk
 
Getting Started with Splunk Enterprise Hands-On
Splunk
 
SplunkLive! Tampa: Splunk for Security - Hands-On Session
Splunk
 
SplunkLive! - Splunk for IT Operations
Splunk
 
Machine Data 101
Splunk
 
Ad

Viewers also liked (20)

PPTX
Tennis Clinics in hyderabad
VSports
 
PPTX
January 31 (child rights)
AIMEC Reporter
 
PDF
inner city farming
Iza Grek
 
PDF
UDOT Motor Carrier Division Report
State of Utah, Salt Lake City
 
PDF
Extending_HR_Self-Service_To_Unconnected_Workers_Netkey_White_Paper[1]
Linda Haelsen
 
DOCX
ENSAYO Capitalizacion De Interes.
gabrieldavidg
 
PPTX
Simple Way for MySQL to NoSQL
Okcan Yasin Saygılı
 
PPTX
What Yoda Can Teach Us about Collaboration
PGi
 
PDF
ゼロからつくるWord pressテーマ第7回
Hitsuji
 
PDF
CISSP new 2015 domain structure review (RUS)
Konstantin Beltsov
 
PDF
SOC and Enterprise Security. Аспекты внедрения. Декабрь 2012
Ken Tulegenov
 
PDF
IT-Task. Максим Степченков. "Примеры использования SIEM системы для решения р...
Expolink
 
PDF
Internal Threats in Kazakhstan. Cyber crime. How to defend. Cyber Security
Ken Tulegenov
 
PDF
Анализ реального взлома нефтяной компании с Ближнего Востока
Cisco Russia
 
PPTX
SIEM-система как основа для выявления компьютерных атак несигнатурными методами
Alexander Dorofeev
 
PDF
Мониторинг событий информационной безопасности на базе решений HP ArcSight ES...
DialogueScience
 
PPTX
9th grade english unit 9.4 its a matter of opinion week four
Efraín Suárez-Arce, M.Ed
 
PDF
Operational Analytics on Splunk
CleverDATA
 
PDF
Solar inView - Безопасность под контролем
Konstantin Beltsov
 
PDF
Splunk live мегафон 2015 - v4
Timur Bagirov
 
Tennis Clinics in hyderabad
VSports
 
January 31 (child rights)
AIMEC Reporter
 
inner city farming
Iza Grek
 
UDOT Motor Carrier Division Report
State of Utah, Salt Lake City
 
Extending_HR_Self-Service_To_Unconnected_Workers_Netkey_White_Paper[1]
Linda Haelsen
 
ENSAYO Capitalizacion De Interes.
gabrieldavidg
 
Simple Way for MySQL to NoSQL
Okcan Yasin Saygılı
 
What Yoda Can Teach Us about Collaboration
PGi
 
ゼロからつくるWord pressテーマ第7回
Hitsuji
 
CISSP new 2015 domain structure review (RUS)
Konstantin Beltsov
 
SOC and Enterprise Security. Аспекты внедрения. Декабрь 2012
Ken Tulegenov
 
IT-Task. Максим Степченков. "Примеры использования SIEM системы для решения р...
Expolink
 
Internal Threats in Kazakhstan. Cyber crime. How to defend. Cyber Security
Ken Tulegenov
 
Анализ реального взлома нефтяной компании с Ближнего Востока
Cisco Russia
 
SIEM-система как основа для выявления компьютерных атак несигнатурными методами
Alexander Dorofeev
 
Мониторинг событий информационной безопасности на базе решений HP ArcSight ES...
DialogueScience
 
9th grade english unit 9.4 its a matter of opinion week four
Efraín Suárez-Arce, M.Ed
 
Operational Analytics on Splunk
CleverDATA
 
Solar inView - Безопасность под контролем
Konstantin Beltsov
 
Splunk live мегафон 2015 - v4
Timur Bagirov
 
Ad

Similar to Splunk in Nordstrom: IT Operations (20)

PDF
Splunk Sales Presentation Imagemaker 2014
Urena Nicolas
 
PPTX
Customer Presentation - Financial Services Organization
Splunk
 
PDF
SplunkLive! Amsterdam 2015 Breakout - Getting Started with Splunk
Splunk
 
PPTX
SplunkLive! Washington DC May 2013 - Splunk Enterprise 5
Splunk
 
PPTX
Getting Started with Splunk Breakout Session
Splunk
 
PDF
Splunk in Staples: IT Operations
Timur Bagirov
 
PDF
Splunk Cloud
Splunk
 
PDF
Splunk Cloud
Splunk
 
PDF
Splunk Cloud
Splunk
 
PDF
Splunk Cloud
Splunk
 
PPTX
SplunkLive! Developer Session
Splunk
 
PPTX
Splunk Different
Splunk
 
PPTX
Taking Splunk to the Next Level – Architecture
Splunk
 
PPTX
Taking Splunk to the Next Level - Technical
Splunk
 
PDF
SFBA Splunk Usergroup meeting March 13, 2024
Becky Burwell
 
PDF
Getting Started with Splunk Enterprise
Splunk
 
PDF
Getting Started with Splunk Enterprise
Splunk
 
PPTX
Splunk live london_grs
jenny_splunk
 
PDF
Getting Started with Splunk Enterprise
Splunk
 
PPTX
Getting Started with Splunk Enterprises
Splunk
 
Splunk Sales Presentation Imagemaker 2014
Urena Nicolas
 
Customer Presentation - Financial Services Organization
Splunk
 
SplunkLive! Amsterdam 2015 Breakout - Getting Started with Splunk
Splunk
 
SplunkLive! Washington DC May 2013 - Splunk Enterprise 5
Splunk
 
Getting Started with Splunk Breakout Session
Splunk
 
Splunk in Staples: IT Operations
Timur Bagirov
 
Splunk Cloud
Splunk
 
Splunk Cloud
Splunk
 
Splunk Cloud
Splunk
 
Splunk Cloud
Splunk
 
SplunkLive! Developer Session
Splunk
 
Splunk Different
Splunk
 
Taking Splunk to the Next Level – Architecture
Splunk
 
Taking Splunk to the Next Level - Technical
Splunk
 
SFBA Splunk Usergroup meeting March 13, 2024
Becky Burwell
 
Getting Started with Splunk Enterprise
Splunk
 
Getting Started with Splunk Enterprise
Splunk
 
Splunk live london_grs
jenny_splunk
 
Getting Started with Splunk Enterprise
Splunk
 
Getting Started with Splunk Enterprises
Splunk
 

More from Timur Bagirov (11)

PDF
презентация Clever data конференция splunk октябрь 2016 v2
Timur Bagirov
 
PDF
Splunk for NAC in Yandex
Timur Bagirov
 
PDF
Tinkoff splunk 2016
Timur Bagirov
 
PDF
Splunk sberbank cib
Timur Bagirov
 
PDF
11 nov splunk_conf_мониторинг доступности услуг в мегафон
Timur Bagirov
 
PDF
Splunk in Otto: Business Analytics
Timur Bagirov
 
PDF
Splunk in John Lewis: Business Analytics
Timur Bagirov
 
PPTX
Splunk Check Point технологические партнеры
Timur Bagirov
 
PDF
Доступная безопасность: смесь инструментов с данными. Советы архитектора Oracle
Timur Bagirov
 
PDF
Немного о Splunk в Yota
Timur Bagirov
 
PPTX
Splunk company overview april. 2015
Timur Bagirov
 
презентация Clever data конференция splunk октябрь 2016 v2
Timur Bagirov
 
Splunk for NAC in Yandex
Timur Bagirov
 
Tinkoff splunk 2016
Timur Bagirov
 
Splunk sberbank cib
Timur Bagirov
 
11 nov splunk_conf_мониторинг доступности услуг в мегафон
Timur Bagirov
 
Splunk in Otto: Business Analytics
Timur Bagirov
 
Splunk in John Lewis: Business Analytics
Timur Bagirov
 
Splunk Check Point технологические партнеры
Timur Bagirov
 
Доступная безопасность: смесь инструментов с данными. Советы архитектора Oracle
Timur Bagirov
 
Немного о Splunk в Yota
Timur Bagirov
 
Splunk company overview april. 2015
Timur Bagirov
 

Recently uploaded (13)

PPTX
10ft Pop-Up Lockers_ Affordable Storage Solutions for Nova Scotia Businesses....
Pop up Lockers
 
PDF
Fashion PRODUCT CYCLE AND CONSUMER CATEGORIES
joannadcunha3
 
PDF
Silver Plaques at Trophy-World Malaysia | Custom Trophies & Plaques Supplier
Trophy-World Malaysia Your #1 Rated Trophy Supplier
 
PDF
How to Use Spelt Flour in High-Volume Artisan Baking
US Flour Corp.
 
PDF
Star Rainbow Crystal Trophies at Trophy-World Malaysia | Custom Trophies & Pl...
Trophy-World Malaysia Your #1 Rated Trophy Supplier
 
PDF
Adore Kids Catalog for Reseller Collection 2025.pdf
GoldKidsOfficial
 
PDF
The Yiddy Werzberger Effect: Where Luxury Precision Meets Tech Efficiency
Joshua Kaftari
 
PDF
Supermarket Floral Ad Roundup- Week 30 2025.pdf
KarliNelson4
 
PPTX
How can a leather kilt add a bold and modern touch to your wardrobe?
Eric Robert
 
PDF
Crystal Wooden Trophies at Trophy-World Malaysia | Custom Trophies & Plaques ...
Trophy-World Malaysia Your #1 Rated Trophy Supplier
 
PPTX
Why 7 Feet Pop Up Lockers in Nova Scotia Are Revolutionizing Mobile Storage.pptx
Pop up Lockers
 
PDF
fundamental categorizing fashion clothing
joannadcunha3
 
PDF
Red Crystal Wooden Plaques at Trophy-World Malaysia | Custom Trophies & Plaqu...
Trophy-World Malaysia Your #1 Rated Trophy Supplier
 
10ft Pop-Up Lockers_ Affordable Storage Solutions for Nova Scotia Businesses....
Pop up Lockers
 
Fashion PRODUCT CYCLE AND CONSUMER CATEGORIES
joannadcunha3
 
Silver Plaques at Trophy-World Malaysia | Custom Trophies & Plaques Supplier
Trophy-World Malaysia Your #1 Rated Trophy Supplier
 
How to Use Spelt Flour in High-Volume Artisan Baking
US Flour Corp.
 
Star Rainbow Crystal Trophies at Trophy-World Malaysia | Custom Trophies & Pl...
Trophy-World Malaysia Your #1 Rated Trophy Supplier
 
Adore Kids Catalog for Reseller Collection 2025.pdf
GoldKidsOfficial
 
The Yiddy Werzberger Effect: Where Luxury Precision Meets Tech Efficiency
Joshua Kaftari
 
Supermarket Floral Ad Roundup- Week 30 2025.pdf
KarliNelson4
 
How can a leather kilt add a bold and modern touch to your wardrobe?
Eric Robert
 
Crystal Wooden Trophies at Trophy-World Malaysia | Custom Trophies & Plaques ...
Trophy-World Malaysia Your #1 Rated Trophy Supplier
 
Why 7 Feet Pop Up Lockers in Nova Scotia Are Revolutionizing Mobile Storage.pptx
Pop up Lockers
 
fundamental categorizing fashion clothing
joannadcunha3
 
Red Crystal Wooden Plaques at Trophy-World Malaysia | Custom Trophies & Plaqu...
Trophy-World Malaysia Your #1 Rated Trophy Supplier
 

Splunk in Nordstrom: IT Operations

  • 1. Copyright  ©  2014  Splunk  Inc.   Bernie  Macias   Applied  Architect,  Nordstrom   Mobile  POS,  DevOps   and  the  Role  of   Splunk  
  • 2. Disclaimer   2   During  the  course  of  this  presentaIon,  we  may  make  forward-­‐looking  statements  regarding  future  events  or  the   expected  performance  of  the  company.  We  cauIon  you  that  such  statements  reflect  our  current  expectaIons  and   esImates  based  on  factors  currently  known  to  us  and  that  actual  events  or  results  could  differ  materially.  For   important  factors  that  may  cause  actual  results  to  differ  from  those  contained  in  our  forward-­‐looking  statements,   please  review  our  filings  with  the  SEC.  The  forward-­‐looking  statements  made  in  the  this  presentaIon  are  being  made  as   of  the  Ime  and  date  of  its  live  presentaIon.  If  reviewed  aTer  its  live  presentaIon,  this  presentaIon  may  not  contain   current  or  accurate  informaIon.  We  do  not  assume  any  obligaIon  to  update  any  forward-­‐looking  statements  we  may   make.  In  addiIon,  any  informaIon  about  our  roadmap  outlines  our  general  product  direcIon  and  is  subject  to  change   at  any  Ime  without  noIce.  It  is  for  informaIonal  purposes  only,  and  shall  not  be  incorporated  into  any  contract  or   other  commitment.  Splunk  undertakes  no  obligaIon  either  to  develop  the  features  or  funcIonality  described  or  to   include  any  such  feature  or  funcIonality  in  a  future  release.  
  • 3. Who  Am  I?   !   Current  PosiIon:  1+  years   –  Applied  Architect   !   Past  Experience:  Since  2005   –  Tech  support,  Windows  system  admin,  windows   system  engineer,  system  architect,  Unix  analyst   ! Splunk  Experience:  3+  years   –  Deployed  approved  Splunk  architecture  at  Capital  One     –  Started  the  Splunk>  Sea^le  user  group   !   Other  Tech  Interests:  Ongoing   –  Python,  Django,  Data  visualizaIon  (d3.js),  Open  Stack   • 3  
  • 4. Agenda   !   About  Nordstrom   !   What s  Nordstrom  Doing  with  Splunk?   !   Managing  and  Scaling  Splunk   ! DevOps  on  Splunk     !   What  About  the  Users?  (Gecng  the  Users  Involved)     4  
  • 5. About  Nordstrom   !   Founded  by  John  W.  Nordstrom  in  1901   !   Over  260  stores  in  US  and  Canada   ! eCommerce:  Nordstrom.com,   NordstromRack.com,  HauteLook.com   !   65,000  employees;  over  1,000  in  IT   !   MulIple  data  centers  with  an  eye  on  the   cloud  or  mulI-­‐cloud   ! DevOps  mission:  scale,  manage,  and   quickly  deliver  on  Nordstrom  iniIaIves   • 5  
  • 6. Omni-­‐channel  at  Nordstrom   Deliver  a  Seamless  Customer  Experience   6   Nordstrom  Store   Nordstrom  Online   Nordstrom  Rack   Nordstrom  Rack  Online  / Haute  Look   Nordstrom     Omni-­‐Channel  
  • 7. What’s  Nordstrom   Doing  with  Splunk?  
  • 8. Web  apps   OperaIonal  logs,   system  logs,  Web   logs,  Crash  logs   Win/Unix   metrics   (2000+  servers)   Chef  data  POS  and   Wi-­‐Fi  data   NNMi,  SCOM,   Gomez   Splunk  @  Nordstrom   ConsolidaIon  of  all  our  machine  data  for  unified  visibility   8  
  • 9. Example:  Point  of  Sales  (POS)   9   •  New  customer  experience   •  Faster  checkout  anywhere  in  store   •  Small  real  estate  footprint  v.   tradiIonal  POS  
  • 10. Performance  Monitoring  of  POS  Devices   10  
  • 11. 11   POS  Inventory  Mapping   11  
  • 12. Splunk  AdopIon  Has  Been  Organic  and  Viral   •  AgnosIc  to  technology   •  Index  any  type  of  data  from  any  data  source   •  Scalable  soluIon     SINGLE  SOURCE  OF   TRUTH   •  Accelerated  adopIon  with  300+  users  across  the  organizaIon   •  Dev,  App,  NW,  Ops  and  global  offshore  teams  create  their  own  data   inputs,  reports  and  dashboards   EASE  OF  USE   •  Role-­‐based  access  controls  to  provide  dev  teams  access  to  producIon   logs  and  metrics   •  Flexible  reporIng    across  a  variety  of  use-­‐cases   SECURE  &  FLEXBILE   PLATFORM   12  
  • 13. AcceleraIng  Value  by  Using  Splunk  Apps   !   Technology  Add-­‐ons:   –  *nix   –  Windows   –  Cisco  IOS   –  MicrosoT  Exchange   !   Homegrown  App   –  Splunk  for  Gomez   –  Few  Django  Apps   ! Splunk  for  simple  XML     13  
  • 14. Secng  the  Stage  for   Managing  and   Scaling  Splunk   14  
  • 15. How  Many  of  You  Would  Consider  Yourself…?   15   SYS  ADMIN   SPLUNK  ADMIN   SPLUNK  USER  
  • 16. Distributed  Splunk  gets  complex   16  
  • 17. 17   All-in-One Search Indexers FW HFWSYSLOG TCP HTTP FW HFW Pool Storage Search Pool #1 Search Pool #2 GA Indexers Pool Storage Secure Indexers Search Pool #3 Pool Storage Indexers Indexers FW HFW Managed Per Available Zone Forwarder/Agents only send data to Zone Specific indexers TOPOLOGIES   OF  SPLUNK  
  • 19. Using  DevOps   Principles  to   Manage  Splunk     19  
  • 20. Why  Not  DevOps  for  Splunk?   20  
  • 21. DevOps  Tools   !   Config  Management  Plauorm   !   Source  Control   !   Dev  Environments   ! ConInuous  IntegraIon   Tools  for  building  tools  spanning:   21  
  • 22. How  Many  Splunk  Components?   !   NFS  Server  –  shared  search  head  storage   !   Search  Head  –  searches  indexed  data   !   Indexer  –  parsing  and  indexing  data   !   Deployment  Server  –  App  Deployment   !   Intermediate  forwarder  –  receiving  or  collect   data  where  forwarder  cannot  be  install  directly   !   Master  –  Cluster  and  ReplicaIon  Master   !   Universal  Forwarder  –  local  collecIon  agent   22  
  • 23. nord_chef-­‐splunk:     a  CHEF  cookbook   !   Ruby  code  that  models  distributed  Splunk   (search,  index,  etc)   !   Reuse  able  code  defined  by  a^ributes   CONSISTENT,  SCALABLE,  REPEATABLE   23  
  • 24. What's  Automagically  Configured?   •  Splunk  SSL   •  TCP  and  UDP  listen  Ports   •  Set  system  local  configs   •  Distributed  Search   •  Mounted  Bundles   •  Indexers  aware  of  all  search   pools   •  And  More   •  Move  default  DB  locaIons   •  Add  user  and  change  Admin   •  Splunk  servers  share  Secret   •  Search  pooling   •  Set  Deployment  Server   •  Search  Heads  aware  of  Indexers   •  Drives  configured   •  Web  server   24  
  • 25. What  About     the  Users?   25  
  • 26. What  Can  Users  Do  In  Splunk?   •  Create  private  objects   •  Cannot  create/edit  global   objects  directly  in  Splunk   •  Dashboards?  Extracts?  Saved   searches?   26   USE  GIT!  
  • 27. CreaIng  a  Custom  GIT  CLI   •  Downloaded  Web  Terminal   for  Splunk  App     •  Installed  on  limited   capability  search  head   •  Customized  for  GIT  CLI     27  
  • 28. Sample  Deployment  Workflow   28   Insert  Image(s)  
  • 29. 29   Splunk  is  a  Journey   What’s  Next?  
  • 30. Special  Offer:  Try  Splunk  MINT  Express  for  Free!   Splunk  MINT  offers  a  fast  path  to  mobile  intelligence.  How  fast?     Find  out  with  a  6-­‐month  trial*   •  Register  for  your  free  trial:   h^p://mint.splunk.com/conf2014offer   •  Download  the  Splunk  MINT  SDKs   •  Add  the  Splunk  MINT  line  of  SDK  code   and  publish**     •  Start  gecng  digital  intelligence  at  your   fingerIps!     *Offer  valid  for  .conf2014  a5endees  and  coworkers  of  a5endees  only.   **Trial  allows  monitoring  of  up  to  750,000  monthly  acDve  users  (MAUs).     30