SlideShare a Scribd company logo
Ge#ng	
  Started	
  with	
  Splunk	
  Enterprise	
  
Andrew	
  Goodall	
  
Sales	
  Engineer,	
  Australia	
  &	
  New	
  Zealand	
  
What	
  is	
  Splunk	
  Enterprise?	
  
Deployment	
  and	
  IntegraAon	
  
Searching,	
  AlerAng,	
  and	
  ReporAng	
  
Universal	
  Indexing	
  Explained	
  
DemonstraAon	
  
AGENDA
3	
  
Spelunking:	
  
	
   to	
  explore	
  underground	
  caves	
  
Splunking:	
  
to	
  explore	
  large	
  amounts	
  of	
  machine	
  data	
  (volume	
  at	
  velocity)	
  
Big	
  Data	
  Comes	
  from	
  Machines	
  
Volume | Velocity | Variety | Variability
GPS,	
  
RFID,	
  
Hypervisor,	
  
Web	
  Servers,	
  
Email,	
  Messaging	
  
Clickstreams,	
  Mobile,	
  	
  
Telephony,	
  IVR,	
  Databases,	
  
Sensors,	
  TelemaJcs,	
  Storage,	
  
Servers,	
  Security	
  Devices,	
  Desktops	
  	
  
4	
  
5	
  
Make	
  machine	
  data	
  accessible,	
  
usable	
  and	
  valuable	
  to	
  everyone.	
  	
  
5	
  5	
  5	
  
6	
  
Industry	
  Leading	
  PlaLorm	
  For	
  Machine	
  Data	
  
	
  Machine	
  Data:	
  Any	
  LocaJon,	
  Type,	
  Volume	
  
Online	
  
Services	
  
Web	
  
Services	
  
Servers	
  
Security	
   GPS	
  
LocaAon	
  
Storage	
  
Desktops	
  
Networks	
  
Packaged	
  
ApplicaAons	
  
Custom	
  
ApplicaAons	
  Messaging	
  
Telecoms	
  
Online	
  
Shopping	
  
Cart	
  
Web	
  
Clickstreams	
  
Databases	
  
Energy	
  
Meters	
  
Call	
  Detail	
  
Records	
  
Smartphones	
  
and	
  Devices	
  
RFID	
  
On-­‐	
  
Premises	
  
Private	
  	
  
Cloud	
  
Public	
  	
  
Cloud	
  
PlaLorm	
  Support	
  (Apps	
  /	
  API	
  /	
  SDKs)	
  
Enterprise	
  Scalability	
  
Universal	
  Indexing	
  
Answer	
  Any	
  QuesJon	
  
Developer	
  
PlaLorm	
  
Report	
  and	
  	
  
analyze	
  
Custom	
  	
  
dashboards	
  
Monitor	
  	
  
and	
  alert	
  
Ad	
  hoc	
  	
  
search	
  
Industry	
  Leading	
  PlaLorm	
  For	
  Machine	
  Data	
  
	
  Machine	
  Data:	
  Any	
  LocaJon,	
  Type,	
  Volume	
  
Online	
  
Services	
  
Web	
  
Services	
  
Servers	
  
Security	
   GPS	
  
LocaAon	
  
Storage	
  
Desktops	
  
Networks	
  
Packaged	
  
ApplicaAons	
  
Custom	
  
ApplicaAons	
  Messaging	
  
Telecoms	
  
Online	
  
Shopping	
  
Cart	
  
Web	
  
Clickstreams	
  
Databases	
  
Energy	
  
Meters	
  
Call	
  Detail	
  
Records	
  
Smartphones	
  
and	
  Devices	
  
RFID	
  
On-­‐	
  
Premises	
  
Private	
  	
  
Cloud	
  
Public	
  	
  
Cloud	
  
PlaLorm	
  Support	
  (Apps	
  /	
  API	
  /	
  SDKs)	
  
Enterprise	
  Scalability	
  
Universal	
  Indexing	
  
Answer	
  Any	
  QuesJon	
  
Developer	
  
PlaLorm	
  
Report	
  and	
  	
  
analyze	
  
Custom	
  	
  
dashboards	
  
Monitor	
  	
  
and	
  alert	
  
Ad	
  hoc	
  	
  
search	
  
Any	
  amount,	
  any	
  locaAon,	
  any	
  source	
  
Schema-­‐
on-­‐the-­‐fly	
  
Universal	
  
indexing	
  
No	
  	
  
back-­‐end	
  
RDBMS	
  
No	
  need	
  	
  
to	
  filter	
  
data	
  
Deploying	
  Splunk	
  Enterprise	
  
9	
  
1.	
  
2.	
  
3.	
  
4.	
  
Simple	
  Steps	
  to	
  Deploy	
  Splunk	
  Enterprise	
  
Download	
  
Install	
  
Forward	
  data	
  
Search	
  
Databases	
  
Networks	
  
Servers	
  
Virtual	
  
Machines	
  
Smart	
  
phones	
  
and	
  
Devices	
  
Custom	
  
ApplicaAons	
  
Security	
  
Web	
  Server	
  
Sensors	
  
Four	
  steps	
  
FREE	
  	
  
ONLINE	
  SANDBOX	
  
FREE	
  	
  
DOWNLOAD	
  
FREE	
  	
  
AMAZON	
  MACHINE	
  
IMAGES	
  (AMI)	
  
10	
  
Easy	
  to	
  Try	
  &	
  Get	
  Started	
  
1	
   3	
  2	
  
Getting Started with Splunk Enterprise
Getting Started with Splunk Enterprise
Getting Started with Splunk Enterprise
14	
  
Define	
  Product	
  Roles	
  
! Searching	
  and	
  ReporAng	
  (Search	
  Head)	
  
	
  
! Indexing	
  and	
  Search	
  Services	
  (Indexer)	
  
	
  
! Data	
  CollecAon	
  and	
  Forwarding	
  (Forwarder)	
  
! Data	
  Governor	
  (Cluster	
  Master)	
  
! Distributed	
  Management	
  (Deployment	
  Server)	
  
	
  
Databases	
  
Networks	
  
Servers	
  
Virtual	
  
Machines	
  
Smart	
  
phones	
  
and	
  
Devices	
  
Custom	
  
ApplicaAons	
  
Security	
  
Web	
  Server	
  
Sensors	
  
Scales	
  to	
  Hundreds	
  of	
  TBs/Day	
  
Enterprise-­‐class	
  Scale,	
  Resilience	
  and	
  Interoperability	
  
Send	
  data	
  from	
  thousands	
  of	
  servers	
  using	
  any	
  combinaAon	
  of	
  Splunk	
  forwarders	
  	
  	
  
Auto	
  load-­‐balanced	
  forwarding	
  to	
  Splunk	
  Indexers	
  
Offload	
  search	
  load	
  to	
  Splunk	
  Search	
  Heads	
  
Visibility	
  Across	
  Datacenters	
  
!   Distributed	
  search	
  unifies	
  the	
  view	
  	
  
across	
  locaAons	
  
	
  
!   Role-­‐based	
  access	
  controls	
  how	
  far	
  a	
  given	
  
user's	
  search	
  will	
  span	
  
New	
  York	
   Tokyo	
  
London	
   Cloud	
  
Ingests	
  Data	
  From	
  Heterogeneous	
  Data	
  Sources	
  
Agent	
  and	
  Agent-­‐less	
  Approach	
  for	
  Flexibility	
  
perf	
  
shell	
  
code	
  
Mounted	
  File	
  Systems	
  
hostnamemount	
  
syslog	
  
TCP/UDP	
  
Event	
  Logs	
  	
  
Performance	
  
AcJve	
  	
  
Directory	
  
syslog	
  hosts	
  
and	
  network	
  devices	
  
Unix,	
  Linux	
  and	
  Windows	
  hosts	
  
Custom	
  apps	
  and	
  scripted	
  API	
  connecJons	
  
Local	
  File	
  Monitoring	
  
log	
  filesconfig	
  files	
  
dumps	
  and	
  trace	
  files	
  
Windows	
  Inputs	
  
Event	
  Logs	
  
performance	
  counters	
  
registry	
  monitoring	
  
Ac@ve	
  Directory	
  monitoring	
  
virtual	
  
host	
  
Windows	
  
Scripted	
  Inputs	
  
shell	
  scripts	
  custom	
  
parsers	
  batch	
  loading	
  
	
  
Agent-­‐less	
  Data	
  Input	
   Splunk	
  Forwarder	
  
Mainframes	
  *nix	
  
Forwards	
  Events	
  to	
  Third-­‐party	
  Systems	
  
Problem	
  InvesAgaAon	
  
Service	
  Desk	
  
Event	
  Console	
  
SIEM	
  
RAW	
  	
  
Formaced	
  
Searching	
  
AlerJng	
  
ReporJng	
  
Turn	
  Machine	
  Data	
  Into	
  OperaJonal	
  Intelligence	
  
PlaLorm	
  Support	
  (Apps	
  /	
  API	
  /	
  SDKs)	
  
Enterprise	
  Scalability	
  
Universal	
  Indexing	
  
Answer	
  Any	
  QuesJon	
  
Developer	
  
PlaLorm	
  
Report	
  and	
  	
  
analyze	
  
Custom	
  	
  
dashboards	
  
Monitor	
  	
  
and	
  alert	
  
Ad	
  hoc	
  	
  
search	
  
Search	
  All	
  Your	
  Machine	
  Data	
  	
  
Search	
  all	
  your	
  data	
  
Results	
  right	
  away	
  
Schema	
  on	
  the	
  fly	
  
•  Search	
  across	
  real-­‐Ame	
  and	
  historical	
  
data	
  
•  Over	
  135	
  search	
  commands	
  built	
  in	
  	
  
•  See	
  results	
  instantly	
  
Data	
  
Parsing	
  Queue	
  
Parsing	
  Pipeline	
  
•  Source,	
  event	
  typing	
  
•  Character	
  set	
  
normalizaAon	
  
•  Line	
  breaking	
  
•  Timestamp	
  
idenAficaAon	
  
•  Regex	
  transforms	
  
Indexing	
  
Pipeline	
  
Real-­‐
Ame	
  
Buffer	
  
Raw	
  data	
  
Index	
  Files	
  
Real-­‐Ame	
  
Search	
  
Process	
  
Monitor	
  
Input	
   Index	
  Queue	
  
TCP/UDP	
  
Input	
  
Scripted	
  
Input	
  
Splunk	
  
Index	
  
Enrich	
  Raw	
  Data	
  to	
  Make	
  More	
  Meaningful	
  
Create	
  addiAonal	
  fields	
  from	
  the	
  
raw	
  data	
  with	
  a	
  lookup	
  to	
  an	
  
external	
  data	
  source	
   LDAP,	
  
AD	
  
Watch	
  
Lists	
  
CRM/ERP	
  
CMDB	
  
External	
  Data	
  Sources	
  
Insight	
  comes	
  out	
  
Data	
  goes	
  in	
  
AcJonable	
  AlerJng	
  
Alerts	
  
•  Create	
  alerts	
  based	
  on	
  any	
  
search	
  
•  Customize	
  content	
  and	
  
format	
  of	
  email	
  alerts	
  
•  Provide	
  context	
  
•  Highlight	
  next	
  steps	
  
•  Enable	
  custom	
  workflows	
  
•  Trigger	
  a	
  script	
  
•  SMS	
  alert	
  
•  SNMP	
  trap	
  
•  Other	
  
Combine	
  Reports	
  to	
  Create	
  Dashboards	
  
Use	
  the	
  built-­‐in	
  	
  
dashboard	
  editor	
  
Or	
  embed	
  the	
  reports	
  into	
  
external	
  sites	
  like	
  a	
  wiki	
  
Turning	
  Machine	
  Data	
  Into	
  OperaJonal	
  Intelligence	
  
ReacJve	
  
Search	
  
and	
  
InvesAgate	
  
ProacAve	
  
Monitoring	
  
and	
  AlerAng	
  
OperaAonal	
  
Visibility	
  
ProacJve	
  
Real-­‐Ame	
  	
  
Business	
  	
  
Insight	
  
Summary	
  
•  Real-­‐Ame	
  architecture	
  	
  
•  Schema-­‐on-­‐the-­‐fly	
  
•  Massive	
  scalability	
  
•  Easy	
  reporAng	
  and	
  analyAcs	
  
•  Plaiorm	
  for	
  all	
  machine	
  data	
  
27	
  
Turning	
  Machine	
  Data	
  Into	
  Business	
  Value	
  
Index	
  Untapped	
  Data:	
  Any	
  Source,	
  Type,	
  Volume	
  
Online	
  
Services	
  
Web	
  
Services	
  
Servers	
  
Security	
   GPS	
  
LocaAon	
  
Storage	
  
Desktops	
  
Networks	
  
Packaged	
  
ApplicaAons	
  
Custom	
  
ApplicaAons	
  Messaging	
  
Telecoms	
  
Online	
  
Shopping	
  
Cart	
  
Web	
  
Clickstreams	
  
Databases	
  
Energy	
  
Meters	
  
Call	
  Detail	
  
Records	
  
Smartphones	
  
and	
  Devices	
  
RFID	
  
On-­‐	
  
Premises	
  
Private	
  	
  
Cloud	
  
Public	
  	
  
Cloud	
  
	
  Ask	
  Any	
  QuesJon	
  
ApplicaJon	
  Delivery	
  
Security,	
  Compliance	
  and	
  
Fraud	
  
IT	
  OperaJons	
  
Business	
  AnalyJcs	
  
Industrial	
  Data	
  and	
  
the	
  Internet	
  of	
  Things	
  
COLLECT	
  DATA	
  
FROM	
  ANYWHERE	
  
SEARCH	
  
AND	
  ANALYZE	
  
EVERYTHING	
  
GAIN	
  REAL-­‐TIME	
  
OPERATIONAL	
  
INTELLIGENCE	
  
The	
  Power	
  of	
  Splunk	
  
28	
  
29	
  
Why	
  Splunk?	
  
FAST	
  TIME-­‐TO-­‐VALUE	
  
ONE	
  PLATFORM,	
  MULTIPLE	
  USE	
  CASES	
  
VISIBILITY	
  ACROSS	
  STACK,	
  NOT	
  JUST	
  SILOS	
  
ASK	
  ANY	
  QUESTION	
  OF	
  DATA	
  
ANY	
  DATA,	
  ANY	
  SOURCE	
  OR	
  DEPLOYMENT	
  MODEL	
  
Phases	
  of	
  OperaJonal	
  Intelligence	
  
ReacJve	
  
Search	
  
and	
  
InvesAgate	
  
ProacAve	
  
Monitoring	
  
and	
  AlerAng	
  
OperaAonal	
  
Visibility	
  
ProacJve	
  
Real-­‐Ame	
  	
  
Business	
  	
  
Insight	
  
Dev.splunk.com	
  40,000+	
  quesJons	
  
and	
  answers	
  
600+	
  apps	
   Local	
  User	
  Groups	
  	
  
and	
  
SplunkLive!	
  events	
  
31	
  
Thriving	
  Community	
  
1.	
  
2.	
  
3.	
  
4.	
  
Simple	
  Steps	
  to	
  Deploy	
  Splunk	
  Enterprise	
  
Download	
  
Install	
  
Forward	
  data	
  
Search	
  
Databases	
  
Networks	
  
Servers	
  
Virtual	
  
Machines	
  
Smart	
  
phones	
  
and	
  
Devices	
  
Custom	
  
ApplicaAons	
  
Security	
  
Web	
  Server	
  
Sensors	
  
Four	
  steps	
  
Thank	
  you	
  
QuesJons?	
  

More Related Content

What's hot (19)

PPTX
Taking Splunk to the Next Level - Architecture Breakout Session
Splunk
 
PPTX
Splunk live beginner training nyc
Dimitri McKay - CISSP
 
PPTX
Splunk Architecture overview
Alex Fok
 
PDF
Splunk as a_big_data_platform_for_developers_spring_one2gx
Damien Dallimore
 
PPTX
Getting Started with Splunk Breakout Session
Splunk
 
PPTX
Taking Splunk to the Next Level - Architecture Breakout Session
Splunk
 
PPTX
Taking Splunk to the Next Level - Technical
Splunk
 
PPTX
SplunkLive! Presentation - Data Onboarding with Splunk
Splunk
 
PPTX
SplunkLive! San Francisco Dec 2012 - Intuit
Splunk
 
PPTX
Advanced Use Cases for Analytics Breakout Session
Splunk
 
PPTX
Splunk Implementation and Usage - Garmin
Splunk
 
PPTX
LEGO: Data Driven Growth Hacking Powered by Big Data
DataWorks Summit/Hadoop Summit
 
PPTX
Solr + Hadoop: Interactive Search for Hadoop
gregchanan
 
PPTX
Disrupting Big Data with Apache Spark in the Cloud
Jen Aman
 
PDF
Kinesis vs-kafka-and-kafka-deep-dive
Yifeng Jiang
 
PPTX
Customer Presentation - Financial Services Organization
Splunk
 
PDF
Data Onboarding
Splunk
 
PDF
Etl is Dead; Long Live Streams
confluent
 
PDF
Reliable and Scalable Data Ingestion at Airbnb
DataWorks Summit/Hadoop Summit
 
Taking Splunk to the Next Level - Architecture Breakout Session
Splunk
 
Splunk live beginner training nyc
Dimitri McKay - CISSP
 
Splunk Architecture overview
Alex Fok
 
Splunk as a_big_data_platform_for_developers_spring_one2gx
Damien Dallimore
 
Getting Started with Splunk Breakout Session
Splunk
 
Taking Splunk to the Next Level - Architecture Breakout Session
Splunk
 
Taking Splunk to the Next Level - Technical
Splunk
 
SplunkLive! Presentation - Data Onboarding with Splunk
Splunk
 
SplunkLive! San Francisco Dec 2012 - Intuit
Splunk
 
Advanced Use Cases for Analytics Breakout Session
Splunk
 
Splunk Implementation and Usage - Garmin
Splunk
 
LEGO: Data Driven Growth Hacking Powered by Big Data
DataWorks Summit/Hadoop Summit
 
Solr + Hadoop: Interactive Search for Hadoop
gregchanan
 
Disrupting Big Data with Apache Spark in the Cloud
Jen Aman
 
Kinesis vs-kafka-and-kafka-deep-dive
Yifeng Jiang
 
Customer Presentation - Financial Services Organization
Splunk
 
Data Onboarding
Splunk
 
Etl is Dead; Long Live Streams
confluent
 
Reliable and Scalable Data Ingestion at Airbnb
DataWorks Summit/Hadoop Summit
 

Similar to Getting Started with Splunk Enterprise (20)

PDF
Getting Started with Splunk Enterprise
Splunk
 
PPTX
Getting Started with Splunk Enterprise
Shannon Cuthbertson
 
PPTX
Getting Started with Splunk Enterprise
Splunk
 
PDF
SplunkLive! Amsterdam 2015 Breakout - Getting Started with Splunk
Splunk
 
PPTX
Getting Started with Splunk Enterprise Hands-On
Splunk
 
PPTX
Getting Started with Splunk Breakout Session
Splunk
 
PDF
Getting Started with Splunk Enterprise
Splunk
 
PPTX
Getting Started with Splunk Enterprise Hands-On
Splunk
 
PPTX
Getting Started with Splunk Enterprise
Splunk
 
PPTX
Getting Started with Splunk Enterprises
Splunk
 
PPTX
Getting Started with Splunk Enterprise Hands-On
Splunk
 
PPTX
Getting Started with Splunk Enterprise Hands-On Breakout Session
Splunk
 
PPTX
Getting Started with Splunk (Hands-On)
Splunk
 
PPTX
SplunkLive! London 2016 Splunk Overview
Splunk
 
PPTX
SplunkLive! Tampa: Getting Started Session
Splunk
 
PPTX
Getting Started with Splunk Enterprise
Splunk
 
PPTX
Getting Started with Splunk Breakout Session
Splunk
 
PDF
SplunkLive! Stockholm 2015 breakout - Getting started with Splunk Enterprise
Splunk
 
PPTX
Getting Started with Splunk Enterprise
Splunk
 
PPTX
Getting Started with Splunk Enterprise
Splunk
 
Getting Started with Splunk Enterprise
Splunk
 
Getting Started with Splunk Enterprise
Shannon Cuthbertson
 
Getting Started with Splunk Enterprise
Splunk
 
SplunkLive! Amsterdam 2015 Breakout - Getting Started with Splunk
Splunk
 
Getting Started with Splunk Enterprise Hands-On
Splunk
 
Getting Started with Splunk Breakout Session
Splunk
 
Getting Started with Splunk Enterprise
Splunk
 
Getting Started with Splunk Enterprise Hands-On
Splunk
 
Getting Started with Splunk Enterprise
Splunk
 
Getting Started with Splunk Enterprises
Splunk
 
Getting Started with Splunk Enterprise Hands-On
Splunk
 
Getting Started with Splunk Enterprise Hands-On Breakout Session
Splunk
 
Getting Started with Splunk (Hands-On)
Splunk
 
SplunkLive! London 2016 Splunk Overview
Splunk
 
SplunkLive! Tampa: Getting Started Session
Splunk
 
Getting Started with Splunk Enterprise
Splunk
 
Getting Started with Splunk Breakout Session
Splunk
 
SplunkLive! Stockholm 2015 breakout - Getting started with Splunk Enterprise
Splunk
 
Getting Started with Splunk Enterprise
Splunk
 
Getting Started with Splunk Enterprise
Splunk
 
Ad

More from Splunk (20)

PDF
Splunk Leadership Forum Wien - 20.05.2025
Splunk
 
PDF
Splunk Security Update | Public Sector Summit Germany 2025
Splunk
 
PDF
Building Resilience with Energy Management for the Public Sector
Splunk
 
PDF
IT-Lagebild: Observability for Resilience (SVA)
Splunk
 
PDF
Nach dem SOC-Aufbau ist vor der Automatisierung (OFD Baden-Württemberg)
Splunk
 
PDF
Monitoring einer Sicheren Inter-Netzwerk Architektur (SINA)
Splunk
 
PDF
Praktische Erfahrungen mit dem Attack Analyser (gematik)
Splunk
 
PDF
Cisco XDR & Splunk SIEM - stronger together (DATAGROUP Cyber Security)
Splunk
 
PDF
Security - Mit Sicherheit zum Erfolg (Telekom)
Splunk
 
PDF
One Cisco - Splunk Public Sector Summit Germany April 2025
Splunk
 
PDF
.conf Go 2023 - Data analysis as a routine
Splunk
 
PDF
.conf Go 2023 - How KPN drives Customer Satisfaction on IPTV
Splunk
 
PDF
.conf Go 2023 - Navegando la normativa SOX (Telefónica)
Splunk
 
PDF
.conf Go 2023 - Raiffeisen Bank International
Splunk
 
PDF
.conf Go 2023 - På liv og død Om sikkerhetsarbeid i Norsk helsenett
Splunk
 
PDF
.conf Go 2023 - Many roads lead to Rome - this was our journey (Julius Bär)
Splunk
 
PDF
.conf Go 2023 - Das passende Rezept für die digitale (Security) Revolution zu...
Splunk
 
PDF
.conf go 2023 - Cyber Resilienz – Herausforderungen und Ansatz für Energiever...
Splunk
 
PDF
.conf go 2023 - De NOC a CSIRT (Cellnex)
Splunk
 
PDF
conf go 2023 - El camino hacia la ciberseguridad (ABANCA)
Splunk
 
Splunk Leadership Forum Wien - 20.05.2025
Splunk
 
Splunk Security Update | Public Sector Summit Germany 2025
Splunk
 
Building Resilience with Energy Management for the Public Sector
Splunk
 
IT-Lagebild: Observability for Resilience (SVA)
Splunk
 
Nach dem SOC-Aufbau ist vor der Automatisierung (OFD Baden-Württemberg)
Splunk
 
Monitoring einer Sicheren Inter-Netzwerk Architektur (SINA)
Splunk
 
Praktische Erfahrungen mit dem Attack Analyser (gematik)
Splunk
 
Cisco XDR & Splunk SIEM - stronger together (DATAGROUP Cyber Security)
Splunk
 
Security - Mit Sicherheit zum Erfolg (Telekom)
Splunk
 
One Cisco - Splunk Public Sector Summit Germany April 2025
Splunk
 
.conf Go 2023 - Data analysis as a routine
Splunk
 
.conf Go 2023 - How KPN drives Customer Satisfaction on IPTV
Splunk
 
.conf Go 2023 - Navegando la normativa SOX (Telefónica)
Splunk
 
.conf Go 2023 - Raiffeisen Bank International
Splunk
 
.conf Go 2023 - På liv og død Om sikkerhetsarbeid i Norsk helsenett
Splunk
 
.conf Go 2023 - Many roads lead to Rome - this was our journey (Julius Bär)
Splunk
 
.conf Go 2023 - Das passende Rezept für die digitale (Security) Revolution zu...
Splunk
 
.conf go 2023 - Cyber Resilienz – Herausforderungen und Ansatz für Energiever...
Splunk
 
.conf go 2023 - De NOC a CSIRT (Cellnex)
Splunk
 
conf go 2023 - El camino hacia la ciberseguridad (ABANCA)
Splunk
 
Ad

Recently uploaded (20)

PDF
HubSpot Main Hub: A Unified Growth Platform
Jaswinder Singh
 
PDF
Jak MŚP w Europie Środkowo-Wschodniej odnajdują się w świecie AI
dominikamizerska1
 
PDF
What Makes Contify’s News API Stand Out: Key Features at a Glance
Contify
 
PDF
Newgen 2022-Forrester Newgen TEI_13 05 2022-The-Total-Economic-Impact-Newgen-...
darshakparmar
 
PDF
New from BookNet Canada for 2025: BNC BiblioShare - Tech Forum 2025
BookNet Canada
 
PDF
IoT-Powered Industrial Transformation – Smart Manufacturing to Connected Heal...
Rejig Digital
 
PDF
Empower Inclusion Through Accessible Java Applications
Ana-Maria Mihalceanu
 
PDF
Exolore The Essential AI Tools in 2025.pdf
Srinivasan M
 
PDF
Smart Trailers 2025 Update with History and Overview
Paul Menig
 
PDF
Using FME to Develop Self-Service CAD Applications for a Major UK Police Force
Safe Software
 
PPTX
AUTOMATION AND ROBOTICS IN PHARMA INDUSTRY.pptx
sameeraaabegumm
 
PPTX
OpenID AuthZEN - Analyst Briefing July 2025
David Brossard
 
PDF
Bitcoin for Millennials podcast with Bram, Power Laws of Bitcoin
Stephen Perrenod
 
PDF
July Patch Tuesday
Ivanti
 
PPTX
COMPARISON OF RASTER ANALYSIS TOOLS OF QGIS AND ARCGIS
Sharanya Sarkar
 
PDF
CIFDAQ Market Wrap for the week of 4th July 2025
CIFDAQ
 
PDF
Building Real-Time Digital Twins with IBM Maximo & ArcGIS Indoors
Safe Software
 
PDF
The Rise of AI and IoT in Mobile App Tech.pdf
IMG Global Infotech
 
PDF
From Code to Challenge: Crafting Skill-Based Games That Engage and Reward
aiyshauae
 
PDF
Biography of Daniel Podor.pdf
Daniel Podor
 
HubSpot Main Hub: A Unified Growth Platform
Jaswinder Singh
 
Jak MŚP w Europie Środkowo-Wschodniej odnajdują się w świecie AI
dominikamizerska1
 
What Makes Contify’s News API Stand Out: Key Features at a Glance
Contify
 
Newgen 2022-Forrester Newgen TEI_13 05 2022-The-Total-Economic-Impact-Newgen-...
darshakparmar
 
New from BookNet Canada for 2025: BNC BiblioShare - Tech Forum 2025
BookNet Canada
 
IoT-Powered Industrial Transformation – Smart Manufacturing to Connected Heal...
Rejig Digital
 
Empower Inclusion Through Accessible Java Applications
Ana-Maria Mihalceanu
 
Exolore The Essential AI Tools in 2025.pdf
Srinivasan M
 
Smart Trailers 2025 Update with History and Overview
Paul Menig
 
Using FME to Develop Self-Service CAD Applications for a Major UK Police Force
Safe Software
 
AUTOMATION AND ROBOTICS IN PHARMA INDUSTRY.pptx
sameeraaabegumm
 
OpenID AuthZEN - Analyst Briefing July 2025
David Brossard
 
Bitcoin for Millennials podcast with Bram, Power Laws of Bitcoin
Stephen Perrenod
 
July Patch Tuesday
Ivanti
 
COMPARISON OF RASTER ANALYSIS TOOLS OF QGIS AND ARCGIS
Sharanya Sarkar
 
CIFDAQ Market Wrap for the week of 4th July 2025
CIFDAQ
 
Building Real-Time Digital Twins with IBM Maximo & ArcGIS Indoors
Safe Software
 
The Rise of AI and IoT in Mobile App Tech.pdf
IMG Global Infotech
 
From Code to Challenge: Crafting Skill-Based Games That Engage and Reward
aiyshauae
 
Biography of Daniel Podor.pdf
Daniel Podor
 

Getting Started with Splunk Enterprise

  • 1. Ge#ng  Started  with  Splunk  Enterprise   Andrew  Goodall   Sales  Engineer,  Australia  &  New  Zealand  
  • 2. What  is  Splunk  Enterprise?   Deployment  and  IntegraAon   Searching,  AlerAng,  and  ReporAng   Universal  Indexing  Explained   DemonstraAon   AGENDA
  • 3. 3   Spelunking:     to  explore  underground  caves   Splunking:   to  explore  large  amounts  of  machine  data  (volume  at  velocity)  
  • 4. Big  Data  Comes  from  Machines   Volume | Velocity | Variety | Variability GPS,   RFID,   Hypervisor,   Web  Servers,   Email,  Messaging   Clickstreams,  Mobile,     Telephony,  IVR,  Databases,   Sensors,  TelemaJcs,  Storage,   Servers,  Security  Devices,  Desktops     4  
  • 5. 5   Make  machine  data  accessible,   usable  and  valuable  to  everyone.     5  5  5  
  • 6. 6   Industry  Leading  PlaLorm  For  Machine  Data    Machine  Data:  Any  LocaJon,  Type,  Volume   Online   Services   Web   Services   Servers   Security   GPS   LocaAon   Storage   Desktops   Networks   Packaged   ApplicaAons   Custom   ApplicaAons  Messaging   Telecoms   Online   Shopping   Cart   Web   Clickstreams   Databases   Energy   Meters   Call  Detail   Records   Smartphones   and  Devices   RFID   On-­‐   Premises   Private     Cloud   Public     Cloud   PlaLorm  Support  (Apps  /  API  /  SDKs)   Enterprise  Scalability   Universal  Indexing   Answer  Any  QuesJon   Developer   PlaLorm   Report  and     analyze   Custom     dashboards   Monitor     and  alert   Ad  hoc     search  
  • 7. Industry  Leading  PlaLorm  For  Machine  Data    Machine  Data:  Any  LocaJon,  Type,  Volume   Online   Services   Web   Services   Servers   Security   GPS   LocaAon   Storage   Desktops   Networks   Packaged   ApplicaAons   Custom   ApplicaAons  Messaging   Telecoms   Online   Shopping   Cart   Web   Clickstreams   Databases   Energy   Meters   Call  Detail   Records   Smartphones   and  Devices   RFID   On-­‐   Premises   Private     Cloud   Public     Cloud   PlaLorm  Support  (Apps  /  API  /  SDKs)   Enterprise  Scalability   Universal  Indexing   Answer  Any  QuesJon   Developer   PlaLorm   Report  and     analyze   Custom     dashboards   Monitor     and  alert   Ad  hoc     search   Any  amount,  any  locaAon,  any  source   Schema-­‐ on-­‐the-­‐fly   Universal   indexing   No     back-­‐end   RDBMS   No  need     to  filter   data  
  • 9. 9   1.   2.   3.   4.   Simple  Steps  to  Deploy  Splunk  Enterprise   Download   Install   Forward  data   Search   Databases   Networks   Servers   Virtual   Machines   Smart   phones   and   Devices   Custom   ApplicaAons   Security   Web  Server   Sensors   Four  steps  
  • 10. FREE     ONLINE  SANDBOX   FREE     DOWNLOAD   FREE     AMAZON  MACHINE   IMAGES  (AMI)   10   Easy  to  Try  &  Get  Started   1   3  2  
  • 14. 14   Define  Product  Roles   ! Searching  and  ReporAng  (Search  Head)     ! Indexing  and  Search  Services  (Indexer)     ! Data  CollecAon  and  Forwarding  (Forwarder)   ! Data  Governor  (Cluster  Master)   ! Distributed  Management  (Deployment  Server)     Databases   Networks   Servers   Virtual   Machines   Smart   phones   and   Devices   Custom   ApplicaAons   Security   Web  Server   Sensors  
  • 15. Scales  to  Hundreds  of  TBs/Day   Enterprise-­‐class  Scale,  Resilience  and  Interoperability   Send  data  from  thousands  of  servers  using  any  combinaAon  of  Splunk  forwarders       Auto  load-­‐balanced  forwarding  to  Splunk  Indexers   Offload  search  load  to  Splunk  Search  Heads  
  • 16. Visibility  Across  Datacenters   !   Distributed  search  unifies  the  view     across  locaAons     !   Role-­‐based  access  controls  how  far  a  given   user's  search  will  span   New  York   Tokyo   London   Cloud  
  • 17. Ingests  Data  From  Heterogeneous  Data  Sources   Agent  and  Agent-­‐less  Approach  for  Flexibility   perf   shell   code   Mounted  File  Systems   hostnamemount   syslog   TCP/UDP   Event  Logs     Performance   AcJve     Directory   syslog  hosts   and  network  devices   Unix,  Linux  and  Windows  hosts   Custom  apps  and  scripted  API  connecJons   Local  File  Monitoring   log  filesconfig  files   dumps  and  trace  files   Windows  Inputs   Event  Logs   performance  counters   registry  monitoring   Ac@ve  Directory  monitoring   virtual   host   Windows   Scripted  Inputs   shell  scripts  custom   parsers  batch  loading     Agent-­‐less  Data  Input   Splunk  Forwarder   Mainframes  *nix  
  • 18. Forwards  Events  to  Third-­‐party  Systems   Problem  InvesAgaAon   Service  Desk   Event  Console   SIEM   RAW     Formaced  
  • 20. Turn  Machine  Data  Into  OperaJonal  Intelligence   PlaLorm  Support  (Apps  /  API  /  SDKs)   Enterprise  Scalability   Universal  Indexing   Answer  Any  QuesJon   Developer   PlaLorm   Report  and     analyze   Custom     dashboards   Monitor     and  alert   Ad  hoc     search  
  • 21. Search  All  Your  Machine  Data     Search  all  your  data   Results  right  away   Schema  on  the  fly   •  Search  across  real-­‐Ame  and  historical   data   •  Over  135  search  commands  built  in     •  See  results  instantly   Data   Parsing  Queue   Parsing  Pipeline   •  Source,  event  typing   •  Character  set   normalizaAon   •  Line  breaking   •  Timestamp   idenAficaAon   •  Regex  transforms   Indexing   Pipeline   Real-­‐ Ame   Buffer   Raw  data   Index  Files   Real-­‐Ame   Search   Process   Monitor   Input   Index  Queue   TCP/UDP   Input   Scripted   Input   Splunk   Index  
  • 22. Enrich  Raw  Data  to  Make  More  Meaningful   Create  addiAonal  fields  from  the   raw  data  with  a  lookup  to  an   external  data  source   LDAP,   AD   Watch   Lists   CRM/ERP   CMDB   External  Data  Sources   Insight  comes  out   Data  goes  in  
  • 23. AcJonable  AlerJng   Alerts   •  Create  alerts  based  on  any   search   •  Customize  content  and   format  of  email  alerts   •  Provide  context   •  Highlight  next  steps   •  Enable  custom  workflows   •  Trigger  a  script   •  SMS  alert   •  SNMP  trap   •  Other  
  • 24. Combine  Reports  to  Create  Dashboards   Use  the  built-­‐in     dashboard  editor   Or  embed  the  reports  into   external  sites  like  a  wiki  
  • 25. Turning  Machine  Data  Into  OperaJonal  Intelligence   ReacJve   Search   and   InvesAgate   ProacAve   Monitoring   and  AlerAng   OperaAonal   Visibility   ProacJve   Real-­‐Ame     Business     Insight  
  • 26. Summary   •  Real-­‐Ame  architecture     •  Schema-­‐on-­‐the-­‐fly   •  Massive  scalability   •  Easy  reporAng  and  analyAcs   •  Plaiorm  for  all  machine  data  
  • 27. 27   Turning  Machine  Data  Into  Business  Value   Index  Untapped  Data:  Any  Source,  Type,  Volume   Online   Services   Web   Services   Servers   Security   GPS   LocaAon   Storage   Desktops   Networks   Packaged   ApplicaAons   Custom   ApplicaAons  Messaging   Telecoms   Online   Shopping   Cart   Web   Clickstreams   Databases   Energy   Meters   Call  Detail   Records   Smartphones   and  Devices   RFID   On-­‐   Premises   Private     Cloud   Public     Cloud    Ask  Any  QuesJon   ApplicaJon  Delivery   Security,  Compliance  and   Fraud   IT  OperaJons   Business  AnalyJcs   Industrial  Data  and   the  Internet  of  Things  
  • 28. COLLECT  DATA   FROM  ANYWHERE   SEARCH   AND  ANALYZE   EVERYTHING   GAIN  REAL-­‐TIME   OPERATIONAL   INTELLIGENCE   The  Power  of  Splunk   28  
  • 29. 29   Why  Splunk?   FAST  TIME-­‐TO-­‐VALUE   ONE  PLATFORM,  MULTIPLE  USE  CASES   VISIBILITY  ACROSS  STACK,  NOT  JUST  SILOS   ASK  ANY  QUESTION  OF  DATA   ANY  DATA,  ANY  SOURCE  OR  DEPLOYMENT  MODEL  
  • 30. Phases  of  OperaJonal  Intelligence   ReacJve   Search   and   InvesAgate   ProacAve   Monitoring   and  AlerAng   OperaAonal   Visibility   ProacJve   Real-­‐Ame     Business     Insight  
  • 31. Dev.splunk.com  40,000+  quesJons   and  answers   600+  apps   Local  User  Groups     and   SplunkLive!  events   31   Thriving  Community  
  • 32. 1.   2.   3.   4.   Simple  Steps  to  Deploy  Splunk  Enterprise   Download   Install   Forward  data   Search   Databases   Networks   Servers   Virtual   Machines   Smart   phones   and   Devices   Custom   ApplicaAons   Security   Web  Server   Sensors   Four  steps