SlideShare a Scribd company logo
Copyright © 2015 Splunk Inc.
Wayne Carter
Senior Sales Engineer
Getting Started with
Splunk Enterprise
http://www.splunk.com/download
http://docs.splunk.com/images/Tutorial/tutorialdata.zip
Legal Notices
During the course of this presentation, we may make forward-looking statements regarding future
events or the expected performance of the company. We caution you that such statements reflect our
current expectations and estimates based on factors currently known to us and that actual events or
results could differ materially. For important factors that may cause actual results to differ from those
contained in our forward-looking statements, please review our filings with the SEC. The forward-
looking statements made in this presentation are being made as of the time and date of its live
presentation. If reviewed after its live presentation, this presentation may not contain current or
accurate information. We do not assume any obligation to update any forward-looking statements
we may make. In addition, any information about our roadmap outlines our general product direction
and is subject to change at any time without notice. It is for informational purposes only and shall
not be incorporated into any contract or other commitment. Splunk undertakes no obligation either
to develop the features or functionality described or to include any such feature or functionality in a
future release.
2
3
Making machine data accessible,
usable and valuable to everyone.
3
Our Plan of Action
4
1.Setting the stage.
2.How does Splunk fit in the landscape?
3.What differentiates Splunk?
4.Components that make up Splunk?
5.Demo - How it works?
The Accelerating Pace of Data
Volume | Velocity | Variety | Variability
GPS,
RFID,
Hypervisor,
Web Servers,
Email, Messaging,
Clickstreams, Mobile,
Telephony, IVR, Databases,
Sensors, Telematics, Storage,
Servers, Security Devices, Desktops
Machine data is the fastest growing, most
complex, most valuable area of big data
5
Industry Leading Platform For Machine Data
Machine Data: Any Location, Type, Volume
Online
Services Web
Services
Servers
Security GPS
Location
Storage
Desktops
Networks
Packaged
Applications
Custom
ApplicationsMessaging
Telecoms
Online
Shopping
Cart
Web
Clickstreams
Databases
Energy
Meters
Call Detail
Records
Smartphones
and Devices
RFID
On-
Premises
Private
Cloud
Public
Cloud
Platform Support (Apps / API / SDKs)
Enterprise Scalability
Universal Indexing
Answer Any Question
Developer
Platform
Report
and
analyze
Custom
dashboards
Monitor
and alert
Ad hoc
search
Universal
Machine Data
Platform
No backend database
No custom connectors
No need to filter data
Schema-on-the-fly
Quick time to value
Agile statistics and reporting
Real-time architecture
perf
shell
API
Mounted File Systems
hostnamemount
syslog
TCP/UDP
Event Logs
Performance
Active
Directory
syslog hosts
and network devices
Unix, Linux and Windows hosts
Local File Monitoring
Splunk Forwarder
virtual
host
Windows
Scripted or Modular Inputs
shell scripts
API subscriptions
Mainframes*nix
Wire Data
Splunk App for Stream
Efficient Time Based Indexing
Splunk Differentiators
Splunk Differentiators
8
• Role Based Access Control
• Define roles and assign users to them.
• Integrate with LDAP or SSO.
• Centralized Access
• Allows multiple users across the organization to securely leverage same
instance with multiple data types.
• Align data access to policies in the organization
• Secure Data Transmission
• Universal Forwarders provides easy, reliable, secure data collection
from remote sources.
• SSL security, data compression, configurable throttling and buffering.
Splunk Components
9
Data Collection Layer - Universal Forwarders, syslog, API, TCP, Scripts, Wire, etc.
Data Indexing Layer – Indexer(s).
Data Presentation Layer– Search Head(s)
Universal Forwarder
1.
2.
3.
4.
How to Get Started
Download
Install
Forward Data
Search
Databases
Networks
Servers
Virtual
Machines
Smart
phones
and
Devices
Custom
Applications
Security
WebServer
Sensors
Four steps:
Demo – How it Works
11
1. Installing and Starting Splunk
2. Ingesting Data
3. Search Basics
• Search Bar
• Time Picker
• Extracted Fields
4. Dynamic Field Extraction
5. Alerting
6. Statistics and Reporting
7. Command Language
8. Splunk Applications
Demo
12
Supplemental Information
13
Get the following at splunk.does-it.net
Download
• www.splunk.com/download
Search Tutorial:
• docs.splunk.com/Documentation/Splunk/latest/SearchTutorial
Tutorial Data:
• docs.splunk.com/images/Tutorial/tutorialdata.zip
Education Resources
14
Splunk Education
• www.splunk.com/education
Using Splunk, Searching and Reporting, Developing Apps,
Administering Splunk, and more!
Books
• Implementing Splunk: Big Data Essentials for Operational Intelligence
• Splunk Essentials
• Exploring Splunk
• Splunk Operational Intelligence Cookbook
Things to Remember
15
1. Splunk is Free – Download and get started today
2. Quick Time to Value
3. Data Gold Mines – what informational fortune awaits?!
4. Leverage the Splunk Community
• splunkbase.splunk.com
• answers.splunk.com
• blogs.splunk.com
5. Happy Splunking!!
Questions?
Thank You

More Related Content

PPTX
Splunk for Enterprise Security featuring UBA Breakout Session
Splunk
 
PPTX
Splunk for Enterprise Security featuring User Behavior Analytics
Splunk
 
PPTX
Drive more value through data source and use case optimization
Splunk
 
PPTX
Operational Security Intelligence Breakout Session
Splunk
 
PPTX
Splunk for Enterprise Security Featuring User Behavior Analytics
Splunk
 
PPTX
Splunk Enterpise for Information Security Hands-On
Splunk
 
PDF
SplunkSummit 2015 - Splunk User Behavioral Analytics
Splunk
 
PPTX
SplunkLive! Milano 2016 - Splunk Plenary Session
Splunk
 
Splunk for Enterprise Security featuring UBA Breakout Session
Splunk
 
Splunk for Enterprise Security featuring User Behavior Analytics
Splunk
 
Drive more value through data source and use case optimization
Splunk
 
Operational Security Intelligence Breakout Session
Splunk
 
Splunk for Enterprise Security Featuring User Behavior Analytics
Splunk
 
Splunk Enterpise for Information Security Hands-On
Splunk
 
SplunkSummit 2015 - Splunk User Behavioral Analytics
Splunk
 
SplunkLive! Milano 2016 - Splunk Plenary Session
Splunk
 

What's hot (20)

PPTX
Splunk Enterprise for InfoSec Hands-On Breakout Session
Splunk
 
PPTX
Splunk for Developers
Splunk
 
PPTX
Splunk for Enterprise Security featuring User Behavior Analytics
Splunk
 
PDF
Splunk for Enterprise Security and User Behavior Analytics
Splunk
 
PPTX
Splunk EMEA Webinar: Scoping infections and disrupting breaches
Splunk
 
PPTX
Splunk for Enterprise Security featuring UBA Breakout Session
Splunk
 
PPTX
Getting Started with Splunk Enterprise
Shannon Cuthbertson
 
PPTX
Gov & Education Day 2015 - User Behavior Analytics
Splunk
 
PPTX
Enterprise Sec + User Bahavior Analytics
Splunk
 
PPTX
Splunk for Security - Hands-On
Splunk
 
PPTX
Splunk for Enterprise Security featuring User Behavior Analytics
Splunk
 
PPTX
Data Onboarding Breakout Session
Splunk
 
PPTX
Best Practices For Sharing Data Across The Enteprrise
Splunk
 
PPTX
SplunkLive! - Splunk for IT Operations
Splunk
 
PDF
Enterprise Security Guided Tour
Splunk
 
PPTX
Getting Started with Splunk Enterprise
Splunk
 
PPTX
Level Up Your Security Skills in Splunk Enterprise
Splunk
 
PDF
Splunk @ Adobe
Splunk
 
PPTX
SplunkLive! Milano 2016 - customer presentation - Saipem
Splunk
 
PPTX
Splunk für Security
Splunk
 
Splunk Enterprise for InfoSec Hands-On Breakout Session
Splunk
 
Splunk for Developers
Splunk
 
Splunk for Enterprise Security featuring User Behavior Analytics
Splunk
 
Splunk for Enterprise Security and User Behavior Analytics
Splunk
 
Splunk EMEA Webinar: Scoping infections and disrupting breaches
Splunk
 
Splunk for Enterprise Security featuring UBA Breakout Session
Splunk
 
Getting Started with Splunk Enterprise
Shannon Cuthbertson
 
Gov & Education Day 2015 - User Behavior Analytics
Splunk
 
Enterprise Sec + User Bahavior Analytics
Splunk
 
Splunk for Security - Hands-On
Splunk
 
Splunk for Enterprise Security featuring User Behavior Analytics
Splunk
 
Data Onboarding Breakout Session
Splunk
 
Best Practices For Sharing Data Across The Enteprrise
Splunk
 
SplunkLive! - Splunk for IT Operations
Splunk
 
Enterprise Security Guided Tour
Splunk
 
Getting Started with Splunk Enterprise
Splunk
 
Level Up Your Security Skills in Splunk Enterprise
Splunk
 
Splunk @ Adobe
Splunk
 
SplunkLive! Milano 2016 - customer presentation - Saipem
Splunk
 
Splunk für Security
Splunk
 
Ad

Viewers also liked (17)

PDF
Energy efficiency where to invest
Darren Garbett
 
PPTX
Travis Plan.2
Tketchel
 
PPTX
Chromosomal coiling in cell cycle
Huma Zaheer
 
PPTX
Jhonny
kmilpolucho
 
DOCX
HiteshPrajapatiCv
hitesh prajapati
 
DOCX
Rachelle resume 2015 (Sept 2015)
Rachelle Lau
 
PDF
Repasse maio 2014_detalhado
Cacs Fundeb Barcarena
 
PDF
Emma BTEC Cert 2013
Emma Mclarin
 
PPTX
Os problemas dos MIPs
Cassyano Correr
 
PDF
ВОЗМОЖНОСТИ ФАСИЛИТАЦИИ
Independent Consultant
 
PPTX
Cone de Dale
DanielaG123
 
PDF
Kickstart Your Retrospectives with a Cheat Sheet
Alexey Krivitsky
 
PPTX
Broadcast media radyo
maricar francia
 
PDF
Rhetorical Reinventions: Rethinking Research Processes and Information Practi...
Donna Witek
 
PPTX
Danh sach so do
Nguyễn Ngọc Phan Văn
 
PPTX
Фасилитация управленческих сессий
Training Institute - ARB Pro Group
 
PDF
HandUpHandoutswahili
Ronald Okubasu
 
Energy efficiency where to invest
Darren Garbett
 
Travis Plan.2
Tketchel
 
Chromosomal coiling in cell cycle
Huma Zaheer
 
Jhonny
kmilpolucho
 
HiteshPrajapatiCv
hitesh prajapati
 
Rachelle resume 2015 (Sept 2015)
Rachelle Lau
 
Repasse maio 2014_detalhado
Cacs Fundeb Barcarena
 
Emma BTEC Cert 2013
Emma Mclarin
 
Os problemas dos MIPs
Cassyano Correr
 
ВОЗМОЖНОСТИ ФАСИЛИТАЦИИ
Independent Consultant
 
Cone de Dale
DanielaG123
 
Kickstart Your Retrospectives with a Cheat Sheet
Alexey Krivitsky
 
Broadcast media radyo
maricar francia
 
Rhetorical Reinventions: Rethinking Research Processes and Information Practi...
Donna Witek
 
Danh sach so do
Nguyễn Ngọc Phan Văn
 
Фасилитация управленческих сессий
Training Institute - ARB Pro Group
 
HandUpHandoutswahili
Ronald Okubasu
 
Ad

Similar to Getting Started with Splunk Enterprise Hands-On (20)

PPTX
Getting Started with Splunk Enterprise Hands-On
Splunk
 
PPTX
Getting Started with Splunk Enterprise
Splunk
 
PPTX
SplunkLive! Tampa: Getting Started Session
Splunk
 
PPTX
Webinar: Neuigkeiten zu Splunk Enterprise 6.3
Splunk
 
PPTX
Getting Started with Splunk Enterprises
Splunk
 
PPTX
Getting Started with Splunk (Hands-On)
Splunk
 
PPTX
Getting Started with Splunk Enterprise
Splunk
 
PPTX
SplunkLive! Splunk Enterprise 6.3 - Data On-boarding
Splunk
 
PDF
SplunkLive! Amsterdam 2015 Breakout - Getting Started with Splunk
Splunk
 
PDF
Getting Started with Splunk Enterprise
Splunk
 
PPTX
Splunk for IT Operations Breakout Session
Splunk
 
PPTX
Getting Started with Splunk Breakout Session
Splunk
 
PDF
Virtual SplunkLive! for Higher Education Overview/Customers
Splunk
 
PPTX
Splunk Internet of Things Roundtable 2015
Georg Knon
 
PDF
Splunk for Industrial Data and the Internet of Things
aliciasyc
 
PDF
Splunk - Splunk for Industrial Data and the Internet of Things
Aruj Thirawat
 
PPTX
Splunk MINT for Mobile Intelligence and Splunk App for Stream for Enhanced Op...
Splunk
 
PPTX
Splunk IT Service Intelligence
Georg Knon
 
PPTX
What’s New: Splunk App for Stream and Splunk MINT
Splunk
 
PPTX
Splunk MINT and Stream Breakout
Splunk
 
Getting Started with Splunk Enterprise Hands-On
Splunk
 
Getting Started with Splunk Enterprise
Splunk
 
SplunkLive! Tampa: Getting Started Session
Splunk
 
Webinar: Neuigkeiten zu Splunk Enterprise 6.3
Splunk
 
Getting Started with Splunk Enterprises
Splunk
 
Getting Started with Splunk (Hands-On)
Splunk
 
Getting Started with Splunk Enterprise
Splunk
 
SplunkLive! Splunk Enterprise 6.3 - Data On-boarding
Splunk
 
SplunkLive! Amsterdam 2015 Breakout - Getting Started with Splunk
Splunk
 
Getting Started with Splunk Enterprise
Splunk
 
Splunk for IT Operations Breakout Session
Splunk
 
Getting Started with Splunk Breakout Session
Splunk
 
Virtual SplunkLive! for Higher Education Overview/Customers
Splunk
 
Splunk Internet of Things Roundtable 2015
Georg Knon
 
Splunk for Industrial Data and the Internet of Things
aliciasyc
 
Splunk - Splunk for Industrial Data and the Internet of Things
Aruj Thirawat
 
Splunk MINT for Mobile Intelligence and Splunk App for Stream for Enhanced Op...
Splunk
 
Splunk IT Service Intelligence
Georg Knon
 
What’s New: Splunk App for Stream and Splunk MINT
Splunk
 
Splunk MINT and Stream Breakout
Splunk
 

More from Splunk (20)

PDF
Splunk Leadership Forum Wien - 20.05.2025
Splunk
 
PDF
Splunk Security Update | Public Sector Summit Germany 2025
Splunk
 
PDF
Building Resilience with Energy Management for the Public Sector
Splunk
 
PDF
IT-Lagebild: Observability for Resilience (SVA)
Splunk
 
PDF
Nach dem SOC-Aufbau ist vor der Automatisierung (OFD Baden-Württemberg)
Splunk
 
PDF
Monitoring einer Sicheren Inter-Netzwerk Architektur (SINA)
Splunk
 
PDF
Praktische Erfahrungen mit dem Attack Analyser (gematik)
Splunk
 
PDF
Cisco XDR & Splunk SIEM - stronger together (DATAGROUP Cyber Security)
Splunk
 
PDF
Security - Mit Sicherheit zum Erfolg (Telekom)
Splunk
 
PDF
One Cisco - Splunk Public Sector Summit Germany April 2025
Splunk
 
PDF
.conf Go 2023 - Data analysis as a routine
Splunk
 
PDF
.conf Go 2023 - How KPN drives Customer Satisfaction on IPTV
Splunk
 
PDF
.conf Go 2023 - Navegando la normativa SOX (Telefónica)
Splunk
 
PDF
.conf Go 2023 - Raiffeisen Bank International
Splunk
 
PDF
.conf Go 2023 - På liv og død Om sikkerhetsarbeid i Norsk helsenett
Splunk
 
PDF
.conf Go 2023 - Many roads lead to Rome - this was our journey (Julius Bär)
Splunk
 
PDF
.conf Go 2023 - Das passende Rezept für die digitale (Security) Revolution zu...
Splunk
 
PDF
.conf go 2023 - Cyber Resilienz – Herausforderungen und Ansatz für Energiever...
Splunk
 
PDF
.conf go 2023 - De NOC a CSIRT (Cellnex)
Splunk
 
PDF
conf go 2023 - El camino hacia la ciberseguridad (ABANCA)
Splunk
 
Splunk Leadership Forum Wien - 20.05.2025
Splunk
 
Splunk Security Update | Public Sector Summit Germany 2025
Splunk
 
Building Resilience with Energy Management for the Public Sector
Splunk
 
IT-Lagebild: Observability for Resilience (SVA)
Splunk
 
Nach dem SOC-Aufbau ist vor der Automatisierung (OFD Baden-Württemberg)
Splunk
 
Monitoring einer Sicheren Inter-Netzwerk Architektur (SINA)
Splunk
 
Praktische Erfahrungen mit dem Attack Analyser (gematik)
Splunk
 
Cisco XDR & Splunk SIEM - stronger together (DATAGROUP Cyber Security)
Splunk
 
Security - Mit Sicherheit zum Erfolg (Telekom)
Splunk
 
One Cisco - Splunk Public Sector Summit Germany April 2025
Splunk
 
.conf Go 2023 - Data analysis as a routine
Splunk
 
.conf Go 2023 - How KPN drives Customer Satisfaction on IPTV
Splunk
 
.conf Go 2023 - Navegando la normativa SOX (Telefónica)
Splunk
 
.conf Go 2023 - Raiffeisen Bank International
Splunk
 
.conf Go 2023 - På liv og død Om sikkerhetsarbeid i Norsk helsenett
Splunk
 
.conf Go 2023 - Many roads lead to Rome - this was our journey (Julius Bär)
Splunk
 
.conf Go 2023 - Das passende Rezept für die digitale (Security) Revolution zu...
Splunk
 
.conf go 2023 - Cyber Resilienz – Herausforderungen und Ansatz für Energiever...
Splunk
 
.conf go 2023 - De NOC a CSIRT (Cellnex)
Splunk
 
conf go 2023 - El camino hacia la ciberseguridad (ABANCA)
Splunk
 

Recently uploaded (20)

PPTX
Agile Chennai 18-19 July 2025 Ideathon | AI Powered Microfinance Literacy Gui...
AgileNetwork
 
PDF
Make GenAI investments go further with the Dell AI Factory
Principled Technologies
 
PDF
GDG Cloud Munich - Intro - Luiz Carneiro - #BuildWithAI - July - Abdel.pdf
Luiz Carneiro
 
PDF
The Future of Artificial Intelligence (AI)
Mukul
 
PPTX
AI and Robotics for Human Well-being.pptx
JAYMIN SUTHAR
 
PDF
Responsible AI and AI Ethics - By Sylvester Ebhonu
Sylvester Ebhonu
 
PPTX
What-is-the-World-Wide-Web -- Introduction
tonifi9488
 
PPTX
The Future of AI & Machine Learning.pptx
pritsen4700
 
PDF
A Strategic Analysis of the MVNO Wave in Emerging Markets.pdf
IPLOOK Networks
 
PPTX
cloud computing vai.pptx for the project
vaibhavdobariyal79
 
PDF
Brief History of Internet - Early Days of Internet
sutharharshit158
 
PPTX
Dev Dives: Automate, test, and deploy in one place—with Unified Developer Exp...
AndreeaTom
 
PDF
Google I/O Extended 2025 Baku - all ppts
HusseinMalikMammadli
 
PDF
Structs to JSON: How Go Powers REST APIs
Emily Achieng
 
PDF
Presentation about Hardware and Software in Computer
snehamodhawadiya
 
PDF
MASTERDECK GRAPHSUMMIT SYDNEY (Public).pdf
Neo4j
 
PPTX
Applied-Statistics-Mastering-Data-Driven-Decisions.pptx
parmaryashparmaryash
 
PDF
Data_Analytics_vs_Data_Science_vs_BI_by_CA_Suvidha_Chaplot.pdf
CA Suvidha Chaplot
 
PDF
Accelerating Oracle Database 23ai Troubleshooting with Oracle AHF Fleet Insig...
Sandesh Rao
 
PPTX
Simple and concise overview about Quantum computing..pptx
mughal641
 
Agile Chennai 18-19 July 2025 Ideathon | AI Powered Microfinance Literacy Gui...
AgileNetwork
 
Make GenAI investments go further with the Dell AI Factory
Principled Technologies
 
GDG Cloud Munich - Intro - Luiz Carneiro - #BuildWithAI - July - Abdel.pdf
Luiz Carneiro
 
The Future of Artificial Intelligence (AI)
Mukul
 
AI and Robotics for Human Well-being.pptx
JAYMIN SUTHAR
 
Responsible AI and AI Ethics - By Sylvester Ebhonu
Sylvester Ebhonu
 
What-is-the-World-Wide-Web -- Introduction
tonifi9488
 
The Future of AI & Machine Learning.pptx
pritsen4700
 
A Strategic Analysis of the MVNO Wave in Emerging Markets.pdf
IPLOOK Networks
 
cloud computing vai.pptx for the project
vaibhavdobariyal79
 
Brief History of Internet - Early Days of Internet
sutharharshit158
 
Dev Dives: Automate, test, and deploy in one place—with Unified Developer Exp...
AndreeaTom
 
Google I/O Extended 2025 Baku - all ppts
HusseinMalikMammadli
 
Structs to JSON: How Go Powers REST APIs
Emily Achieng
 
Presentation about Hardware and Software in Computer
snehamodhawadiya
 
MASTERDECK GRAPHSUMMIT SYDNEY (Public).pdf
Neo4j
 
Applied-Statistics-Mastering-Data-Driven-Decisions.pptx
parmaryashparmaryash
 
Data_Analytics_vs_Data_Science_vs_BI_by_CA_Suvidha_Chaplot.pdf
CA Suvidha Chaplot
 
Accelerating Oracle Database 23ai Troubleshooting with Oracle AHF Fleet Insig...
Sandesh Rao
 
Simple and concise overview about Quantum computing..pptx
mughal641
 

Getting Started with Splunk Enterprise Hands-On

  • 1. Copyright © 2015 Splunk Inc. Wayne Carter Senior Sales Engineer Getting Started with Splunk Enterprise http://www.splunk.com/download http://docs.splunk.com/images/Tutorial/tutorialdata.zip
  • 2. Legal Notices During the course of this presentation, we may make forward-looking statements regarding future events or the expected performance of the company. We caution you that such statements reflect our current expectations and estimates based on factors currently known to us and that actual events or results could differ materially. For important factors that may cause actual results to differ from those contained in our forward-looking statements, please review our filings with the SEC. The forward- looking statements made in this presentation are being made as of the time and date of its live presentation. If reviewed after its live presentation, this presentation may not contain current or accurate information. We do not assume any obligation to update any forward-looking statements we may make. In addition, any information about our roadmap outlines our general product direction and is subject to change at any time without notice. It is for informational purposes only and shall not be incorporated into any contract or other commitment. Splunk undertakes no obligation either to develop the features or functionality described or to include any such feature or functionality in a future release. 2
  • 3. 3 Making machine data accessible, usable and valuable to everyone. 3
  • 4. Our Plan of Action 4 1.Setting the stage. 2.How does Splunk fit in the landscape? 3.What differentiates Splunk? 4.Components that make up Splunk? 5.Demo - How it works?
  • 5. The Accelerating Pace of Data Volume | Velocity | Variety | Variability GPS, RFID, Hypervisor, Web Servers, Email, Messaging, Clickstreams, Mobile, Telephony, IVR, Databases, Sensors, Telematics, Storage, Servers, Security Devices, Desktops Machine data is the fastest growing, most complex, most valuable area of big data 5
  • 6. Industry Leading Platform For Machine Data Machine Data: Any Location, Type, Volume Online Services Web Services Servers Security GPS Location Storage Desktops Networks Packaged Applications Custom ApplicationsMessaging Telecoms Online Shopping Cart Web Clickstreams Databases Energy Meters Call Detail Records Smartphones and Devices RFID On- Premises Private Cloud Public Cloud Platform Support (Apps / API / SDKs) Enterprise Scalability Universal Indexing Answer Any Question Developer Platform Report and analyze Custom dashboards Monitor and alert Ad hoc search Universal Machine Data Platform No backend database No custom connectors No need to filter data Schema-on-the-fly Quick time to value Agile statistics and reporting Real-time architecture
  • 7. perf shell API Mounted File Systems hostnamemount syslog TCP/UDP Event Logs Performance Active Directory syslog hosts and network devices Unix, Linux and Windows hosts Local File Monitoring Splunk Forwarder virtual host Windows Scripted or Modular Inputs shell scripts API subscriptions Mainframes*nix Wire Data Splunk App for Stream Efficient Time Based Indexing Splunk Differentiators
  • 8. Splunk Differentiators 8 • Role Based Access Control • Define roles and assign users to them. • Integrate with LDAP or SSO. • Centralized Access • Allows multiple users across the organization to securely leverage same instance with multiple data types. • Align data access to policies in the organization • Secure Data Transmission • Universal Forwarders provides easy, reliable, secure data collection from remote sources. • SSL security, data compression, configurable throttling and buffering.
  • 9. Splunk Components 9 Data Collection Layer - Universal Forwarders, syslog, API, TCP, Scripts, Wire, etc. Data Indexing Layer – Indexer(s). Data Presentation Layer– Search Head(s) Universal Forwarder
  • 10. 1. 2. 3. 4. How to Get Started Download Install Forward Data Search Databases Networks Servers Virtual Machines Smart phones and Devices Custom Applications Security WebServer Sensors Four steps:
  • 11. Demo – How it Works 11 1. Installing and Starting Splunk 2. Ingesting Data 3. Search Basics • Search Bar • Time Picker • Extracted Fields 4. Dynamic Field Extraction 5. Alerting 6. Statistics and Reporting 7. Command Language 8. Splunk Applications
  • 13. Supplemental Information 13 Get the following at splunk.does-it.net Download • www.splunk.com/download Search Tutorial: • docs.splunk.com/Documentation/Splunk/latest/SearchTutorial Tutorial Data: • docs.splunk.com/images/Tutorial/tutorialdata.zip
  • 14. Education Resources 14 Splunk Education • www.splunk.com/education Using Splunk, Searching and Reporting, Developing Apps, Administering Splunk, and more! Books • Implementing Splunk: Big Data Essentials for Operational Intelligence • Splunk Essentials • Exploring Splunk • Splunk Operational Intelligence Cookbook
  • 15. Things to Remember 15 1. Splunk is Free – Download and get started today 2. Quick Time to Value 3. Data Gold Mines – what informational fortune awaits?! 4. Leverage the Splunk Community • splunkbase.splunk.com • answers.splunk.com • blogs.splunk.com 5. Happy Splunking!!

Editor's Notes

  • #4: Splunk’s mission is to make YOUR machine data accessible, usable and valuable to everyone. It’s this overarching mission that drives our company and products that we deliver.
  • #6: Data is growing and embodies new characteristics not found in traditional structured data: Volume, Velocity, Variety, Variability. "Big data" is a term applied to these expanding data sets whose size is beyond the ability of commonly used software tools to capture, manage, and process the data within a tolerable elapsed time. Machine data is one of the fastest, growing, most complex and most valuable segments of big data and embodies new characteristics not found in traditional structured data terms of Volume, Velocity, Variety, Variability. All the webservers, applications, network devices – all of the technology infrastructure running an enterprise or organization – generates massive streams of data, digital exhaust per say. It comes in an array of unpredictable formats that are difficult to process and analyze by traditional methods or in a timely manner. So why is this “machine data” valuable? Because it contains a trace - a categorical record - of user behavior, cyber-security risks, application behavior, service levels, fraudulent activity and customer experiences.
  • #7: All of this is accomplished with: No backend database No custom connectors Without filtering data Without knowing the questions before hand. While Providing a quick time to value With agile statistics and reporting All in real-time
  • #8: Getting data into Splunk is designed to be as flexible and easy as possible. In most cases you’ll find that no configuration is required; you just have to determine what data to collect and which method you want to use to get it into Splunk. Splunk is THE universal machine data platform. It goes beyond ingesting just log files, ingesting data from syslog, scripts, system events, API’s, even wire data! The result is beautifully indexed time-based series events, previously in disparate silos that can now be cross-correlated and made accessible to everyone your organization. Notice here that we are ingesting local files, data from syslogs, output from scripts and even wire data. Let’s see how the Splunk platform supports all this data collection.
  • #10: Three major tiers and components of Splunk Distribution Data Collection Layer -> This is where data is collected by or sent into Splunk. The star of the show here is Splunk’s Universal Forwarder which provides reliable, secure data collection from remote sources and forwards that data into Splunk Enterprise for indexing and consolidation. Data Indexing Layer -> The Data Collection Layer’s job is to collect and/or forward data to the Data Indexing Layer - Powered by Splunk Indexers. Indexers are just a collection of indexes which are logical containers for data to reside in. Data Presentation Layer -> Powered by Search Heads is responsible for distributing searches to the indexing layer, aggregate the final results, and present it to the end user. Viewing the data -> No special or custom client needed! Simply use your favorite browser and point to your Search Head. Now, in modestly small deployments the data indexing and searching will be done with the same Splunk Enterprise Instance.
  • #11: It only takes minutes to download and install Splunk on the platform of your choice, bringing you fast time to value. Once Splunk has been downloaded and installed the next step is to get data into a Splunk instance. The data then becomes searchable from a single place! Since Splunk stores only a copy of the raw data, searches won’t affect the end devices data comes from. Having a central place to search your data not only simplifies things, it also decreases risk since a user doesn’t have to log into the end devices. Splunk can be installed on a single small instance, such as a laptop, or installed on multiple servers to scale as needed. The ability to scale from a single desktop to an enterprise is another of our key differentiators. When installed on multiple servers the functions can be split up to meet any performance, security, or availability requirements.
  • #12: Lets say you are a Web Site Administrator. You recently received user complaints that that web pages are failing and not returning content when it should. Let’s use Splunk to search this data, to not only determine problems that happened but factors associated with or contributing to it.
  • #13: Start up a brand new Splunk Have a ready data set, typically use tutorial Literally drag and drop. Go back to components, what make them up Run two manual queries, paints picture of we can do. Patterns Create a data model (Use instant pivot) Create output Do something completely impressive. (create party on third party system, 3d graph, alert, something tangible outside of Splunk)   Highlight best Splunk 6 features, add data, patterns, instant pivot,
  • #15: Data is growing and embodies new characteristics not found in traditional structured data: Volume, Velocity, Variety, Variability. "Big data" is a term applied to these expanding data sets whose size is beyond the ability of commonly used software tools to capture, manage, and process the data within a tolerable elapsed time. Machine data is one of the fastest, growing, most complex and most valuable segments of big data and embodies new characteristics not found in traditional structured data terms of Volume, Velocity, Variety, Variability. All the webservers, applications, network devices – all of the technology infrastructure running an enterprise or organization – generates massive streams of data, digital exhaust per say. It comes in an array of unpredictable formats that are difficult to process and analyze by traditional methods or in a timely manner. So why is this “machine data” valuable? Because it contains a trace - a categorical record - of user behavior, cyber-security risks, application behavior, service levels, fraudulent activity and customer experiences.