getting started with splunk enterprises

17
Copyright © 2015 Splunk Inc. Tony Vincent Sales Engineer Getting Started with Splunk Enterprise

Upload: splunk

Post on 21-Jan-2018

281 views

Category:

Technology


0 download

TRANSCRIPT

Page 1: Getting Started with Splunk Enterprises

Copyright © 2015 Splunk Inc.

Tony Vincent

Sales Engineer

Getting Started with Splunk Enterprise

Page 2: Getting Started with Splunk Enterprises

Legal NoticesDuring the course of this presentation, we may make forward-looking statements regarding future events or the expected performance of the company. We caution you that such statements reflect our current expectations and estimates based on factors currently known to us and that actual events or results could differ materially. For important factors that may cause actual results to differ from those contained in our forward-looking statements, please review our filings with the SEC. The forward-looking statements made in this presentation are being made as of the time and date of its live presentation. If reviewed after its live presentation, this presentation may not contain current or accurate information. We do not assume any obligation to update any forward-looking statements we may make. In addition, any information about our roadmap outlines our general product direction and is subject to change at any time without notice. It is for informational purposes only and shall not be incorporated into any contract or other commitment. Splunk undertakes no obligation either to develop the features or functionality described or to include any such feature or functionality in a future release.

2

Page 3: Getting Started with Splunk Enterprises

3

Making machine data accessible,usable and valuable to everyone.

3

Page 4: Getting Started with Splunk Enterprises

Our Plan of Action

4

1.Setting the stage.

2.How does Splunk fit in the landscape?

3.What differentiates Splunk?

4.Components that make up Splunk?

5.Demo - How it works?

Page 5: Getting Started with Splunk Enterprises

The Accelerating Pace of Data

Volume | Velocity | Variety | VariabilityGPS,

RFID,Hypervisor,

Web Servers,Email, Messaging,

Clickstreams, Mobile, Telephony, IVR, Databases,

Sensors, Telematics, Storage,Servers, Security Devices, Desktops

Machine data is the fastest growing, most complex, most valuable area of big data

7

Page 6: Getting Started with Splunk Enterprises

Industry Leading Platform For Machine Data

Machine Data: Any Location, Type, Volume

Online Services Web

Services

ServersSecurity GPS

Location

StorageDesktops

Networks

Packaged Applications

CustomApplicationsMessaging

TelecomsOnline

Shopping Cart

Web Clickstreams

Databases

Energy Meters

Call Detail Records

Smartphones and Devices

RFID

On-Premises

Private Cloud

Public Cloud

Platform Support (Apps / API / SDKs)

Enterprise Scalability

Universal Indexing

Answer Any Question

DeveloperPlatform

Report and

analyze

Custom dashboards

Monitor and alert

Ad hoc search

Universal Machine Data

Platform

No backend databaseNo custom connectorsNo need to filter dataSchema-on-the-flyQuick time to valueAgile statistics and reportingReal-time architecture

Page 7: Getting Started with Splunk Enterprises

perf

shellAPI

Mounted File Systems\\hostname\mount

syslogTCP/UDP

Event Logs Performance

Active Directory

syslog hostsand network devices

Unix, Linux and Windows hosts

Local File MonitoringSplunk Forwarder

virtualhost

Windows

Scripted or Modular Inputsshell scripts

API subscriptions

Mainframes*nix

Wire DataSplunk App for Stream

Efficient Time Based Indexing

Splunk Differentiators

Page 8: Getting Started with Splunk Enterprises

Splunk Differentiators

12

• Role Based Access Control• Define roles and assign users to them.• Integrate with LDAP or SSO.

• Centralized Access• Allows multiple users across the organization to securely leverage same

instance with multiple data types.• Align data access to policies in the organization

• Secure Data Transmission• Universal Forwarders provides easy, reliable, secure data collection

from remote sources.• SSL security, data compression, configurable throttling and buffering.

Page 9: Getting Started with Splunk Enterprises

Splunk Components

13

Data Collection Layer - Universal Forwarders, syslog, API, TCP, Scripts, Wire, etc.

Data Indexing Layer – Indexer(s).

Data Presentation Layer– Search Head(s)

Universal Forwarder

Page 10: Getting Started with Splunk Enterprises

1.

2.

3.

4.

How to Get Started

Download

Install

Forward Data

Search

Dat

abas

es

Net

wo

rks

Serv

ers

Vir

tual

M

ach

inesSmart

phones and

Devices

Cu

sto

mA

pp

licat

ion

s

Secu

rity

Web

Serv

er

Sen

sors

Four steps:

Page 11: Getting Started with Splunk Enterprises

Demo – How it Works

15

1. Installing and Starting Splunk2. Ingesting Data3. Search Basics

• Search Bar• Time Picker• Extracted Fields

4. Dynamic Field Extraction 5. Alerting6. Statistics and Reporting7. Command Language8. Splunk Applications

Page 12: Getting Started with Splunk Enterprises

Demo

16

Page 13: Getting Started with Splunk Enterprises

Supplemental Information

17

Get the following at splunk.does-it.net

Download• www.splunk.com/download

Search Tutorial:• docs.splunk.com/Documentation/Splunk/latest/SearchTutorial

Tutorial Data:• docs.splunk.com/images/Tutorial/tutorialdata.zip

Page 14: Getting Started with Splunk Enterprises

Education Resources

18

Splunk Education• www.splunk.com/education

Using Splunk, Searching and Reporting, Developing Apps, Administering Splunk, and more!

Books• Implementing Splunk: Big Data Essentials for Operational Intelligence• Splunk Essentials• Exploring Splunk• Splunk Operational Intelligence Cookbook

Page 15: Getting Started with Splunk Enterprises

Things to Remember

19

1. Splunk is Free – Download and get started today2. Quick Time to Value3. Data Gold Mines – what informational fortune awaits?!4. Leverage the Splunk Community

• splunkbase.splunk.com• answers.splunk.com• blogs.splunk.com

5. Happy Splunking!!

Page 16: Getting Started with Splunk Enterprises

Questions?

Page 17: Getting Started with Splunk Enterprises

Thank You