Understanding Splunk AcceleraGon Technologies David Marquardt

Size: px
Start display at page:

Download "Understanding Splunk AcceleraGon Technologies David Marquardt"

Transcription

1 Copyright 2013 Splunk Inc. Understanding Splunk AcceleraGon Technologies David Marquardt Senior So?ware Engineer #splunkconf

2 Legal NoGces During the course of this presentagon, we may make forward- looking statements regarding future events or the expected performance of the company. We caugon you that such statements reflect our current expectagons and esgmates based on factors currently known to us and that actual events or results could differ materially. For important factors that may cause actual results to differ from those contained in our forward- looking statements, please review our filings with the SEC. The forward- looking statements made in this presentagon are being made as of the Gme and date of its live presentagon. If reviewed a?er its live presentagon, this presentagon may not contain current or accurate informagon. We do not assume any obligagon to update any forward- looking statements we may make. In addigon, any informagon about our roadmap outlines our general product direcgon and is subject to change at any Gme without nogce. It is for informagonal purposes only and shall not, be incorporated into any contract or other commitment. Splunk undertakes no obligagon either to develop the features or funcgonality described or to include any such feature or funcgonality in a future release. Splunk, Splunk>, Splunk Storm, Listen to Your Data, SPL and The Engine for Machine Data are trademarks and registered trademarks of Splunk Inc. in the United States and other countries. All other brand names, product names, or trademarks belong to their respeccve owners Splunk Inc. All rights reserved. 2

3 About Me! Been coding core splunkd for over 5 years! Worked on various components: eval/where commands MulG- index search AuthenGcaGon/authorizaGon Rawdata Now high performance analygcs store 3

4 Agenda! Overview Current Index Structure! Review How ReporGng is Currently Done! How We Can Do Be`er! Demo 4

5 Splunk Enterprise Index Structure IDX 3 IDX 2 IDX 1 Source/Sourcetype/Host Metadata Home Path 1 source : : /my/log 2 source: : /blah et et lt lt it it hot_v1_100 *.data *.tsidx rawdata TSIDX cream apple beer coke ice java LEXICON hot_v1_101 apple POSTING db_lt_et_101 beer Cold Path db_lt_et_80 Thawed Path db_lt_et_70 Rawdata an apple a day keeps doctor away apple pie and ice cream is delicious 5

6 TSIDX? What? Time series index! Inverted index opgmized for Gme! Two basic components Lexicon Arrays of informagon about events Why: Given a Gme range and query, where s my matching data? 6

7 Lexicon Raw Events Deep likes Bud light Amrit likes Makers Ledion likes cognac Dave likes Jack Daniels Zhang likes vodka Deep likes Makers Dave likes Makers Term PosCngs List Amrit 1 Bud 0 Daniels 3 Dave 3,6 Deep 0,5 Jack 3 Ledion 2 Makers 1,5,6 Zhang 4 cognac 2 likes 0,1,2,3,4,5,6 light 0 vodka 4 7

8 Values Arrays PosCng value Seek address _Cme host source sourcetype Raw events Deep likes Bud light Amrit likes Makers Ledion likes cognac Dave likes Jack Daniels Zhang likes vodka Deep likes Makers Dave likes Makers 8

9 Okay, How Do I Search? Query: likes (vodka OR cognac) STEP 1: Consult the lex, combining posgngs lists! Doing an OR? Use a union! Doing an AND? Use an intersecgon vodka OR cognac = (4) U (2) = (2, 4) likes (vodka OR cognac) = (0,1,2,3,4,5,6) int. (2, 4) = (2, 4) We now have the right posgng values! Term PosCngs List Amrit 1 Bud 0 Daniels 3 Dave 3,6 Deep 0,5 Jack 3 Ledion 2 Makers 1,5,6 Zhang 4 cognac 2 likes 0,1,2,3,4,5,6 light 0 vodka 4 9

10 ConverGng PosGng Values to Events PosCng value Seek addr _Cme host source sourcetype evenjype STEP 2: Use the values array to look up _Gme, seek address, host, source, sourcetype for (2, 4) STEP 3: Use the seek addresses to read rawdata at offsets (120, 170) Ledion likes cognac Zhang likes vodka STEP 4: Back to search land; field extracgons, lookups, etc. 10

11 Reading Compressed Rawdata journal.gz Example: Reading offsets (120, 170) 1. Group offsets into residing chunks 120 falls into range (78, 148) 170 falls into range (148, 236) 2. Read data off disk and decompress EXPENSIVE! 11

12 How Expensive? Example bucket: 521,629 events Limited to ~175,000 events per second 12

13 What Are We Doing in TSIDX Land? In SQL terms: SELECT _time, seekaddr, host, source, sourcetype!!where <some query>! And then we re off to rawdata and search land How can we do more here?! OR even: SELECT foo, bar WHERE <some query> SELECT avg(baz), stdev(baz) WHERE <some query> GROUPBY foo, bar! 13

14 Indexed Fields Term PosCngs list bar::ab 1,3,7,39,98 bar::cez 0,6,9,12 bar::xyz 3,4,5,6 baz::1 3,6,85 baz::2567 0,5 baz::462 3,24,45 baz::98 2,3,5,8,9 baz:: ,5,6,76,99 foo::afdjsi 4,567,2345 foo::aghdafo 2,234,6667 foo::bazcxuid 0,1,623,7777 foo::cef 0,1,2,3,4,43 foo::zaz 4 Big idea: Use the lexicon as a field value store! By simply separagng fields and values with :: we can store sufficient informagon to run more interesgng queries 14

15 How Does it Work? Term PosCngs list bar::ab 1,3,7,39,98 bar::cez 0,6,9,12 bar::xyz 3,4,5,6 baz::1 3,6,85 baz::2567 0,5 baz::462 3,24,45 baz::98 2,3,5,8,9 baz:: ,5,6,76,99 foo::afdjsi 4,567,2345 foo::aghdafo 2,234,6667 foo::bazcxuid 0,1,623,7777 foo::cef 0,1,2,3,4,43 foo::zaz 4 SELECT sum(baz) WHERE bar=xyz!! Evaluate query: 3,4,5,6! Iterate over baz, updagng sum for matching events baz::1 ê Sum += 2 * 1 baz::2567 ê Sum += 1 * 2567 baz::462 ê Sum += 1 * 462 baz::98 ê Sum += 2 * 98 baz::99023 ê Sum += 2 *

16 How Can You Use This in Splunk Enterprise 5.x? tscollect! Creates TSIDX files in the indexed fields format! index=main fields a, b, c tscollect namespace=demo! Only admins can run this indexes_edit capability tstats! Runs stats over the TSIDX files in the created namespace! tstats avg(a) from demo groupby b, c 16

17 Drawbacks to the Splunk Enterprise 5.x Approach! Only on the search head! No retengon policy or limits! Manual process How to schedule collect? Timing problems Fault tolerance? Data lag Search head $SPLUNK_DB/tsidxstats Indexer 1 Indexer 2 Indexer N 17

18 Splunk Enterprise 6: Making it Easy What data do we want to accelerate? 18

19 Create a Data Model 19

20 Splunk Enterprise 6: Making it Easy How do we accelerate that data? 20

21 Click The Checkbox! 21

22 Introducing the High Performance AnalyGcs Store! AutomaGcally collected Handles Gming issues, backfill! AutomaGcally maintained Search head Uses acceleragon window! Stored on the indexers Peer to the buckets! Fault tolerant collecgon Indexer 1 Indexer 2 Indexer N 22

23 Completely Transparent!! No administragon overhead! Missing collecgon data filled in by search No data lag!! AnalyGc queries just get faster! Results come from HPAS first! Checking acceleragon status Data models management page Job inspector 23

24 Great, How Do I Use it?! In pivot: AutomaGcally used when acceleragon is on!! Manually: tstats from datamodel=<name> 24

25 What About Report AcceleraGon? Report AcceleraGon High Performance AnalyGcs Store! Accelerates a pargcular search! Stores results of map step! Pre- computed aggregate! Doesn t help for high- cardinality! Typically lower storage costs But requires storage per- search! Accelerates an engre dataset! Stores field value informagon! Nothing pre- computed! Works well for high- cardinality! Higher storage costs (~25%) Storage shared by all searches on datamodel Varies by collecgon: # events, fields, values 25

26 Splunk Enterprise 6: Making it Easy What if I already have indexed fields? 26

27 Bonus!! You can query exisgng indexed fields directly! Just omit the FROM clause in tstats You can specify indexes in WHERE clause Supports search filters Search head! Don t forget the default indexed fields! host, source, sourcetype _indexgme, linecount, punct date_second, date_minute, etc. 27

28 More InformaGon! Data models h`p://docs.splunk.com/documentagon/splunk/6.0/knowledge/ Managedatamodels! AcceleraGon h`p://docs.splunk.com/documentagon/splunk/6.0/knowledge/ Acceleratedatamodels! tstats command h`p://docs.splunk.com/documentagon/splunk/6.0/searchreference/tstats 28

29 Demo

30 Key Takeaway Build a datamodel and try it yourself! 30

31 Next Steps 1 2 Download the.conf2013 Mobile App If not iphone, ipad or Android, use the Web App Take the survey & WIN A PASS FOR.CONF2014 Or one of these bags! 3 Go to the Search Party! Marquee Nightclub at The Cosmopolitan Today, 7:30-10:30pm 31

32 QuesGons?

33 THANK YOU

Time ACer Time Comparing Time Ranges in Splunk Lisa Guinn

Time ACer Time Comparing Time Ranges in Splunk Lisa Guinn Copyright 2013 Splunk Inc. Time ACer Time Comparing Time Ranges in Splunk Lisa Guinn Sr Instructor, Splunk #splunkconf Legal NoGces During the course of this presentagon, we may make forward- looking statements

More information

Copyright 2015 Splunk Inc. The state of Splunk. Using the KVStore to maintain App State. Stefan Sievert. Client Architect, Splunk Inc.

Copyright 2015 Splunk Inc. The state of Splunk. Using the KVStore to maintain App State. Stefan Sievert. Client Architect, Splunk Inc. Copyright 2015 Splunk Inc. The state of Splunk Using the KVStore to maintain App State Stefan Sievert Client Architect, Splunk Inc. Disclaimer During the course of this presentagon, we may make forward

More information

How to Scale: From _raw to tstats (and beyond!)

How to Scale: From _raw to tstats (and beyond!) Copyright 2016 Splunk Inc. How to Scale: From _raw to tstats (and beyond!) David Veuve Staff Security Strategist, Splunk Disclaimer During the course of this presentation, we may make forward looking statements

More information

Puppet Enterprise And Splunk PlaJorm: Improve Your ApplicaGon Delivery Velocity

Puppet Enterprise And Splunk PlaJorm: Improve Your ApplicaGon Delivery Velocity Copyright 2016 Splunk Inc. Puppet Enterprise And Splunk PlaJorm: Improve Your ApplicaGon Delivery Velocity Deepak Giridharagopal CTO & Chief Architect, Puppet Stela Udovicic Product MarkeGng, Splunk Disclaimer

More information

Splunk for Ad Hoc Explora2on of Twi6er (and more) Stephen Sorkin VP Engineering, Splunk

Splunk for Ad Hoc Explora2on of Twi6er (and more) Stephen Sorkin VP Engineering, Splunk Splunk for Ad Hoc Explora2on of Twi6er (and more) Stephen Sorkin VP Engineering, Splunk Who am I Berkeley PhD dropout. LeH to work at HP Labs. At Splunk since 2005. VP Engineering since 2010. Run the core

More information

"I Want That Cool Viz in Splunk!"

I Want That Cool Viz in Splunk! Copyright 2014 Splunk Inc. "I Want That Cool Viz in Splunk!" Satoshi Kawasaki Consultant, Splunk Disclaimer During the course of this presentagon, we may make forward- looking statements regarding future

More information

DB Connect Is Back. and it is better than ever. Tyler Muth Denis Vergnes. September 2017 Washington, DC

DB Connect Is Back. and it is better than ever. Tyler Muth Denis Vergnes. September 2017 Washington, DC DB Connect Is Back and it is better than ever Tyler Muth Denis Vergnes September 2017 Washington, DC Forward-Looking Statements During the course of this presentation, we may make forward-looking statements

More information

Search Language - Beginner Mitch Fleischman

Search Language - Beginner Mitch Fleischman Copyright 2013 Splunk Inc. Search Language - Beginner Mitch Fleischman Senior Instructor #splunkconf Legal NoDces During the course of this presentadon, we may make forward- looking statements regarding

More information

Search Language Intermediate Lincoln Bowser

Search Language Intermediate Lincoln Bowser Copyright 2013 Splunk Inc. Search Language Intermediate Lincoln Bowser Sr. Technical Instructor, Splunk #splunkconf Legal NoFces During the course of this presentafon, we may make forward- looking statements

More information

Using Splunk Enterprise To Optimize Tailored Long-term Data Retention

Using Splunk Enterprise To Optimize Tailored Long-term Data Retention Using Splunk Enterprise To Optimize Tailored Long-term Data Retention Tomasz Bania Incident Response Lead, Dolby Eric Krieser Splunk Professional Services September 2017 Washington, DC Forward-Looking

More information

Best Prac:ces + New Feature Overview for the Latest Version of Splunk Deployment Server

Best Prac:ces + New Feature Overview for the Latest Version of Splunk Deployment Server Copyright 2013 Splunk Inc. Best Prac:ces + New Feature Overview for the Latest Version of Splunk Deployment Server Gen: Zaimi Professional Services #splunkconf Legal No:ces During the course of this presenta:on,

More information

Data Models for Developers

Data Models for Developers Copyright 2013 Splunk Inc. Data Models for Developers Alice Neels So

More information

A Trip Through The Splunk Data Ingestion And Retrieval Pipeline

A Trip Through The Splunk Data Ingestion And Retrieval Pipeline A Trip Through The Splunk Data Ingestion And Retrieval Pipeline Harold Murn Senior Systems Engineer 2017-09-27 Washington, DC Forward-Looking Statements During the course of this presentation, we may make

More information

Fields, Indexed Tokens, And You

Fields, Indexed Tokens, And You Fields, Indexed Tokens, And You Martin Müller Professional Services Consultant, Consist Software Solutions GmbH September 42 nd, 2017 Washington, DC Forward-Looking Statements During the course of this

More information

Dashboard Time Selection

Dashboard Time Selection Dashboard Time Selection Balancing flexibility with a series of system-crushing searches Chuck Gilbert Analyst, chuck_gilbert@comcast.com September 2017 Washington, DC Forward-Looking Statements During

More information

Squeezing all the Juice out of Splunk Enterprise Security

Squeezing all the Juice out of Splunk Enterprise Security Squeezing all the Juice out of Splunk Enterprise Security Marquis Montgomery, CISSP Sr. Staff Security Consultant, Splunk Jae Jung Professional Services Consultant, Splunk September 23 25, 2017 Washington,

More information

Create Dashboards that People Love

Create Dashboards that People Love Create Dashboards that People Love Introducing Splunk Dashboard Design Guidelines Iryna Vogler User Experience Design September 26, 2017 Washington, DC Forward-Looking Statements During the course of this

More information

Metrics Analysis with the Splunk Platform

Metrics Analysis with the Splunk Platform Metrics Analysis with the Splunk Platform How to work with metrics for Monitoring, Alerting, and ad-hoc analysis at scale Michael Porath Product Management, Splunk Allan Yan Principal Software Engineer,

More information

Best Practices and Better Practices for Users

Best Practices and Better Practices for Users Best Practices and Better Practices for Users while you get settled Latest Slides: https://splunk.box.com/v/blueprints-practices-user Collaborate: #bestpractices Sign Up @ http://splk.it/slack Load Feedback

More information

Visualizing the Health of Your Mobile App

Visualizing the Health of Your Mobile App Visualizing the Health of Your Mobile App Jay Tamboli ios Engineer, Capital One September 26, 2017 Washington, DC Forward-Looking Statements During the course of this presentation, we may make forward-looking

More information

Scaling Indexer Clustering

Scaling Indexer Clustering Scaling Indexer Clustering 5 Million Unique Buckets and Beyond Cher-Hung Chang Principal Software Engineer Tameem Anwar Software Engineer 09/26/2017 Washington, DC Forward-Looking Statements During the

More information

Onboard Data into Splunk, Correctly

Onboard Data into Splunk, Correctly Copyright 2013 Splunk Inc. Onboard Data into Splunk, Correctly Ma:hew Se=pane Professional Services Manager, Splunk #splunkconf Legal NoJces During the course of this presentajon, we may make forward-

More information

Building Your First Splunk App with the Splunk Web Framework

Building Your First Splunk App with the Splunk Web Framework Copyright 2013 Splunk Inc. Building Your First Splunk App with the Splunk Web Framework Itay Neeman Dev Manager, Splunk Sea@le #splunkconf Legal NoMces During the course of this presentamon, we may make

More information

Monitoring Docker Containers with Splunk

Monitoring Docker Containers with Splunk Monitoring Docker Containers with Splunk Marc Chéné Product Manager Sept 27, 2017 Washington, DC Forward-Looking Statements During the course of this presentation, we may make forward-looking statements

More information

Docker and Splunk Development

Docker and Splunk Development Docker and Splunk Development Empowering Splunk Development with Docker Ron Cooper & David Kraemer Booz Allen Hamilton 26 September 2017 Washington, DC Forward-Looking Statements During the course of this

More information

FFIEC Cybersecurity Assessment Tool

FFIEC Cybersecurity Assessment Tool FFIEC Cybersecurity Assessment Tool Cybersecurity Controls & Incidence Mappings for Splunk Enterprise, Enterprise Security, User Behavior Analytics Curtis Johnson Senior Sales Engineer & Security SME September

More information

Measuring HEC Performance For Fun and Profit

Measuring HEC Performance For Fun and Profit Measuring HEC Performance For Fun and Profit Itay Neeman Director, Engineering, Splunk Clif Gordon Principal Software Engineer, Splunk September 2017 Washington, DC Forward-Looking Statements During the

More information

IntegraBng Splunk Data and FuncBonality Using the Splunk SDK for Java

IntegraBng Splunk Data and FuncBonality Using the Splunk SDK for Java Copyright 2013 Splunk Inc. IntegraBng Splunk Data and FuncBonality Using the Splunk SDK for Java Damien Dallimore Developer Evangelist @ Splunk #splunkconf Legal NoBces During the course of this presentabon,

More information

Splunk & AWS. Gain real-time insights from your data at scale. Ray Zhu Product Manager, AWS Elias Haddad Product Manager, Splunk

Splunk & AWS. Gain real-time insights from your data at scale. Ray Zhu Product Manager, AWS Elias Haddad Product Manager, Splunk Splunk & AWS Gain real-time insights from your data at scale Ray Zhu Product Manager, AWS Elias Haddad Product Manager, Splunk Forward-Looking Statements During the course of this presentation, we may

More information

Replication of summary data in indexer cluster

Replication of summary data in indexer cluster Copyright 2016 Splunk Inc. Replication of summary data in indexer cluster Dhruva Kumar Bhagi Sr. Software engineer Splunk Inc. Disclaimer During the course of this presentation, we may make forward looking

More information

Indexer Clustering Fixups

Indexer Clustering Fixups Indexer Clustering Fixups Cluster recovery process Da Xu Engineering Splunk Forward-Looking Statements During the course of this presentation, we may make forward-looking statements regarding future events

More information

Running Splunk Enterprise within Docker

Running Splunk Enterprise within Docker Running Splunk Enterprise within Docker Michael Clayfield Partner Consultant 03/09/2017 1.1 Forward-Looking Statements During the course of this presentation, we may make forward-looking statements regarding

More information

Extending SPL with Custom Search Commands

Extending SPL with Custom Search Commands Extending SPL with Custom Search Commands Jacob Leverich Director of Engineering 2017/08/11 Washington, DC Forward-Looking Statements During the course of this presentation, we may make forward-looking

More information

The Power of Data Normalization. A look at the Common Information Model

The Power of Data Normalization. A look at the Common Information Model The Power of Data Normalization A look at the Common Information Model Mark Bonsack, CISSP Vladimir Skoryk, CISSP, CCFE, CHFI, CISA, CISM, RGTT Staff Sales Engineer, Splunk PS Supreme Architect, Splunk

More information

Architecting Splunk For High Availability And Disaster Recovery

Architecting Splunk For High Availability And Disaster Recovery Architecting Splunk For High Availability And Disaster Recovery Sean Delaney Principal Architect, Splunk September 2017 Washington, DC Forward-Looking Statements During the course of this presentation,

More information

Data Obfuscation and Field Protection in Splunk

Data Obfuscation and Field Protection in Splunk Data Obfuscation and Field Protection in Splunk Angelo Brancato Security Specialist Dirk Nitschke Senior Sales Engineer 28 September 2017 Washington, DC 2017 SPLUNK INC. Agenda Protect Your Machine Data

More information

Atlassian s Journey Into Splunk

Atlassian s Journey Into Splunk Atlassian s Journey Into Splunk The Building Of Our Logging Pipeline On AWS Tim Clancy Engineering Manager, Observability James Mackie Infrastructure Engineer, Observability September 2017 Washington,

More information

Indexer Clustering Internals & Performance

Indexer Clustering Internals & Performance Indexer Clustering Internals & Performance Da Xu Chloe Yeung September 28, 2017 Washington, DC Forward-Looking Statements During the course of this presentation, we may make forward-looking statements

More information

Data Onboarding. Where Do I begin? Luke Netto Senior Professional Services Splunk. September 26, 2017 Washington, DC

Data Onboarding. Where Do I begin? Luke Netto Senior Professional Services Splunk. September 26, 2017 Washington, DC Data Onboarding Where Do I begin? Luke Netto Senior Professional Services Consultant @ Splunk September 26, 2017 Washington, DC Forward-Looking Statements During the course of this presentation, we may

More information

Next Generation Dashboards

Next Generation Dashboards Next Generation Dashboards Stephen Luedtke Sr. Technical Marketing Manager September 27, 2017 Washington, DC Forward-Looking Statements During the course of this presentation, we may make forward-looking

More information

Dashboard Wizardry. Advanced Dashboard Interactivity. Siegfried Puchbauer Principal Software Engineer Yuxiang Kou Software Engineer

Dashboard Wizardry. Advanced Dashboard Interactivity. Siegfried Puchbauer Principal Software Engineer Yuxiang Kou Software Engineer Dashboard Wizardry Advanced Dashboard Interactivity Siegfried Puchbauer Principal Software Engineer Yuxiang Kou Software Engineer September 25, 2017 Washington, DC Brought To You By Siegfried Puchbauer

More information

Splunking with Multiple Personalities

Splunking with Multiple Personalities Splunking with Multiple Personalities Extending Role Based Access Control to achieve fine grain security of your data Sabrina Lea Senior Sales Engineer, Splunk Shaun C Splunk Customer September 2017 Forward-Looking

More information

Dashboards & Visualizations: What s New

Dashboards & Visualizations: What s New Dashboards & Visualizations: What s New Nicholas Filippi Product Management, Splunk Patrick Ogdin Product Management, Splunk September 2017 Washington, DC Welcome Patrick Ogdin Product Management, Splunk

More information

Bring Context To Your Machine Data With Hadoop, RDBMS & Splunk

Bring Context To Your Machine Data With Hadoop, RDBMS & Splunk Bring Context To Your Machine Data With Hadoop, RDBMS & Splunk Raanan Dagan and Rohit Pujari September 25, 2017 Washington, DC Forward-Looking Statements During the course of this presentation, we may

More information

Modernizing InfoSec Training and IT Operations at USF

Modernizing InfoSec Training and IT Operations at USF Modernizing InfoSec Training and IT Operations at USF Goodbye Tedious Tasks! A Novel Automation Framework Leveraging Splunk Tim Ip, Senior Security Engineer Nicholas Recchia, Director & Information Security

More information

Copyright 2014 Splunk Inc. Data On- Boarding. Andrew Duca Sr. Professional Services Consultant, Splunk

Copyright 2014 Splunk Inc. Data On- Boarding. Andrew Duca Sr. Professional Services Consultant, Splunk Copyright 2014 Splunk Inc. Data On- Boarding Andrew Duca Sr. Professional Services Consultant, Splunk Disclaimer During the course of this presentagon, we may make forward- looking statements regarding

More information

Revealing the Magic. The Lifecycle of a Splunk Search. Kellen Green Senior Software Engineer. September 27th, 2017 Washington, DC

Revealing the Magic. The Lifecycle of a Splunk Search. Kellen Green Senior Software Engineer. September 27th, 2017 Washington, DC Revealing the Magic The Lifecycle of a Splunk Search Kellen Green Senior Software Engineer September 27th, 2017 Washington, DC About Myself web developer 2017 SPLUNK INC. 1. Develop a deeper understanding

More information

Introducing Splunk Validated Architectures (SVA)

Introducing Splunk Validated Architectures (SVA) Introducing Splunk Validated Architectures (SVA) Optimizing Your Path To Success With Splunk Sean Delaney Principal Architect Stefan Sievert Staff Architect September 2017 Washington, DC Forward-Looking

More information

Easing Into Clustering

Easing Into Clustering Copyright 2016 Splunk Inc. Easing Into Clustering Lisa Guinn Sr. Instructor, Splunk Disclaimer During the course of this presentabon, we may make forward looking statements regarding future events or the

More information

Splunk N Box. Splunk Multi-Site Clusters In 20 Minutes or Less! Mohamad Hassan Sales Engineer. 9/25/2017 Washington, DC

Splunk N Box. Splunk Multi-Site Clusters In 20 Minutes or Less! Mohamad Hassan Sales Engineer. 9/25/2017 Washington, DC Splunk N Box Splunk Multi-Site Clusters In 20 Minutes or Less! Mohamad Hassan Sales Engineer 9/25/2017 Washington, DC Forward-Looking Statements During the course of this presentation, we may make forward-looking

More information

Search Head Clustering Basics To Best Practices

Search Head Clustering Basics To Best Practices Search Head Clustering Basics To Best Practices Bharath Aleti Product Manager, Splunk Manu Jose Sr. Software Engineer, Splunk September 2017 Washington, DC Forward-Looking Statements During the course

More information

Bringing Sweetness to Sour Patch Tuesday

Bringing Sweetness to Sour Patch Tuesday Bringing Sweetness to Sour Patch Tuesday Pacific Northwest National Laboratory Justin Brown & Arzu Gosney September 27, 2017 Washington, DC Forward-Looking Statements During the course of this presentation,

More information

Bucket Diversity: Choosing Your Search Mate Wisely

Bucket Diversity: Choosing Your Search Mate Wisely Copyright 2016 Splunk Inc. Bucket Diversity: Choosing Your Search Mate Wisely Dean Jackson Principal Systems Engineer, DELL EMC Simon O Brien Senior Sales Engineer, Splunk WHO WE ARE 2 Disclaimer During

More information

Making the Most of the Splunk Scheduler

Making the Most of the Splunk Scheduler Making the Most of the Splunk Scheduler Paul J. Lucas Principal Software Engineer, Splunk September 25 28, 2017 Washington, DC Forward-Looking Statements During the course of this presentation, we may

More information

Search Optimization. Alex James. Karthik Sabhanatarajan. Principal Product Manager, Splunk. Senior Software Engineer, Splunk

Search Optimization. Alex James. Karthik Sabhanatarajan. Principal Product Manager, Splunk. Senior Software Engineer, Splunk Copyright 2016 Splunk Inc. Search Optimization Alex James Principal Product Manager, Splunk & Karthik Sabhanatarajan Senior Software Engineer, Splunk Session Outline Why Optimize SPL? What does optimization

More information

Need for Speed: Unleashing the Power of SecOps with Adaptive Response. Malhar Shah CEO, Crest Data Systems Meera Shankar Alliance Manager, Splunk

Need for Speed: Unleashing the Power of SecOps with Adaptive Response. Malhar Shah CEO, Crest Data Systems Meera Shankar Alliance Manager, Splunk Need for Speed: Unleashing the Power of SecOps with Adaptive Response Malhar Shah CEO, Crest Data Systems Meera Shankar Alliance Manager, Splunk September 27, 2017 Washington, DC Forward-Looking Statements

More information

Components. Screen Keyboard* Camera. Touch Pad. Mouse* Remote CPU. USB Port. * = wireless

Components. Screen Keyboard* Camera. Touch Pad. Mouse* Remote CPU. USB Port. * = wireless Contents Components p.2 Power Up The System p.3 Record Camera Full Screen p.6 Record Computer Full Screen p.13 Record Audio Only p.20 Record Hybrid Computer/Camera p.25 MulG- Modality Recordings p. 36

More information

Essentials to creating your own Security Posture using Splunk Enterprise

Essentials to creating your own Security Posture using Splunk Enterprise Essentials to creating your own Security Posture using Splunk Enterprise Using Splunk to maximize the efficiency and effectiveness of the SOC / IR Richard W. McKee, MS-ISA, CISSP Principal Cyber Security

More information

Technical Deep Dive Splunk Cloud. Copyright 2015 Splunk Inc.

Technical Deep Dive Splunk Cloud. Copyright 2015 Splunk Inc. Technical Deep Dive Splunk Cloud Copyright 2015 Splunk Inc. Disclaimer During the course of this presentaaon, we may make forward looking statements regarding future events or the expected performance

More information

Dremel: Interactive Analysis of Web-Scale Database

Dremel: Interactive Analysis of Web-Scale Database Dremel: Interactive Analysis of Web-Scale Database Presented by Jian Fang Most parts of these slides are stolen from here: http://bit.ly/hipzeg What is Dremel Trillion-record, multi-terabyte datasets at

More information

Tracking Logs at Zillow with Lookups & JIRA

Tracking Logs at Zillow with Lookups & JIRA Tracking Logs at Zillow with Lookups & JIRA Seth Thomas, Jon Wentworth September 27 Washington, DC Forward-Looking Statements During the course of this presentation, we may make forward-looking statements

More information

Performance Innovations with Oracle Database In-Memory

Performance Innovations with Oracle Database In-Memory Performance Innovations with Oracle Database In-Memory Eric Cohen Solution Architect Safe Harbor Statement The following is intended to outline our general product direction. It is intended for information

More information

Splunk and Spark. Liu- yuan Lai. So;ware Engineer, Splunk

Splunk and Spark. Liu- yuan Lai. So;ware Engineer, Splunk Copyright 2015 Splunk Inc. Splunk and Spark Liu- yuan Lai So;ware Engineer, Splunk Disclaimer During the course of this presentaeon, we may make forward looking statements regarding future events or the

More information

Copyright 2013 Splunk Inc. Hardening Splunk. Alex Eisen Chief Security Expat R&D Eng / Product Security #splunkconf

Copyright 2013 Splunk Inc. Hardening Splunk. Alex Eisen Chief Security Expat R&D Eng / Product Security #splunkconf Copyright 2013 Splunk Inc. Hardening Splunk Alex Eisen Chief Security Expat R&D Eng / Product Security #splunkconf Legal NoIces During the course of this presentaion, we may make forward- looking statements

More information

Inside Secrets From Support- How to Solve the Top 10 Support Issues

Inside Secrets From Support- How to Solve the Top 10 Support Issues Copyright 2014 Splunk Inc. Inside Secrets From Support- How to Solve the Top 10 Support Issues Barak Reeves Sales Engineer, Splunk Todd Gow Sales Engineer, Splunk Disclaimer During the course of this presentajon,

More information

Using Splunk to Protect Students, Faculty and the University

Using Splunk to Protect Students, Faculty and the University Copyright 2014 Splunk Inc. Using Splunk to Protect Students, Faculty and the University Chris Kurtz System Architect Arizona State University Disclaimer During the course of this presentagon, we may make

More information

Automating Information Lifecycle Management with

Automating Information Lifecycle Management with Automating Information Lifecycle Management with Oracle Database 2c The following is intended to outline our general product direction. It is intended for information purposes only, and may not be incorporated

More information

Adding Depth to Dashboards

Adding Depth to Dashboards Copyright 2015 Splunk Inc. Adding Depth to Dashboards Pierre Brunel Splunk Disclaimer During the course of this presentacon, we may make forward looking statements regarding future events or the expected

More information

Database In- Memory and Exadata: Do I sgll need Exadata?

Database In- Memory and Exadata: Do I sgll need Exadata? Database In- Memory and Exadata: Do I sgll need Exadata? Mathew Steinberg Exadata and Database In- Memory Product Management IOUG BIWA Summit January 27-29, 2014 Redwood City, CA Oracle ConfidenGal Internal/Restricted/Highly

More information

Making Sense of Web Fraud With Splunk Stream

Making Sense of Web Fraud With Splunk Stream Making Sense of Web Fraud With Splunk Stream An in-depth look at Stream use cases and customer success stories with a focus on stream:http Jim Apger Minister of Mayhem Senior Security Architect Matthew

More information

Dragons and Splunk Do Not Do Well In Captivity

Dragons and Splunk Do Not Do Well In Captivity Dragons and Splunk Do Not Do Well In Captivity Tame Splunk Dragons Before Winter Comes Kyle Prins & Keith Quebodeaux DellEMC Splunk Ninjas September 2017 Washington, DC Forward-Looking Statements During

More information

Indexer Clustering Tips & Tricks

Indexer Clustering Tips & Tricks Copyright 2015 Splunk Inc. Indexer Clustering Tips & Tricks Da Xu dxu@splunk.com So@ware Engineer, Splunk Disclaimer During the course of this presentaion, we may make forward looking statements regarding

More information

Copyright 2015 Splunk Inc. Smart Splunking. Jeff Champagne, Splunk Kate Engel, Morgan Stanley

Copyright 2015 Splunk Inc. Smart Splunking. Jeff Champagne, Splunk Kate Engel, Morgan Stanley Copyright 2015 Splunk Inc. Smart Splunking Jeff Champagne, Splunk Kate Engel, Morgan Stanley Jeff Champagne jchampagne@splunk.com Client Architect Who s this dude? Splunk user since 2011 Started with Splunk

More information

Troubleshooting AWS App

Troubleshooting AWS App Troubleshooting AWS App Workshop Splunk Add-on for AWS 4.3+ Kamilo Amir Splunk Cloud Architect Table of Contents TROUBLESHOOTING SPLUNK APP / ADD-ON FOR AWS 4 PERMISSIONS REVIEW 4 SEARCHES 5 VALIDATE HEC

More information

Copyright 2012, Oracle and/or its affiliates. All rights reserved.

Copyright 2012, Oracle and/or its affiliates. All rights reserved. 1 The following is intended to outline our general product direction. It is intended for information purposes only, and may not be incorporated into any contract. It is not a commitment to deliver any

More information

Building Python Messaging Apps with Oracle Database

Building Python Messaging Apps with Oracle Database Building Python Messaging Apps with Oracle Database CON 7344 Anthony Tuininga ConsulGng Member of Technical Staff Data Access Development, Oracle Database October 3 rd, 2017 Safe Harbor Statement The following

More information

HomeAway Let s Stay Together

HomeAway Let s Stay Together Copyright 2014 Splunk Inc. Splunk @ HomeAway Let s Stay Together René X. Parra So>ware Architect, HomeAway Disclaimer During the course of this presentakon, we may make forward- looking statements regarding

More information

Faster Splunk App Cer=fica=on with Splunk AppInspect

Faster Splunk App Cer=fica=on with Splunk AppInspect Copyright 2016 Splunk Inc. Faster Splunk App Cer=fica=on with Splunk AppInspect Andy Nortrup Product Manager, Splunk Grigori Melnik Director, Product Management, Splunk Disclaimer During the course of this

More information

Copyright 2013 Splunk Inc. Data Science. Ron Naken. Principal Engineer #splunkconf

Copyright 2013 Splunk Inc. Data Science. Ron Naken. Principal Engineer #splunkconf Copyright 2013 Splunk Inc. Data Science Ron Naken Principal Engineer #splunkconf Legal NoCces During the course of this presentacon, we may make forward- looking statements regarding future events or the

More information

Harnessing 6.3 Performance and Scalability

Harnessing 6.3 Performance and Scalability Copyright 2015 Splunk Inc. Harnessing 6.3 Performance and Scalability Abhinav NekkanF Tameem Anwar Sourav Pal Splunk Disclaimer During the course of this presentafon, we may make forward looking statements

More information

Wonderware Mobile Reporting SmartGlance & Wonderware Mobile Reporting Connector

Wonderware Mobile Reporting SmartGlance & Wonderware Mobile Reporting Connector Software Datasheet Summary Mobile Reporting Wonderware Mobile Reporting SmartGlance & Wonderware Mobile Reporting Connector offered by Invensys provides real-time access to critical KPIs and process data

More information

Understanding and Using Fields

Understanding and Using Fields Copyright 2015 Splunk Inc. Understanding and Using Fields Jesse Miller Product Manager, Splunk Clara Lee SoCware Engineer, Splunk Disclaimer During the course of this presentaion, we may make forward looking

More information

Agenda. Introduce the Tale of Two developers. Domino Top Secret. Back to the Future with the Domino

Agenda. Introduce the Tale of Two developers. Domino Top Secret. Back to the Future with the Domino Agenda Introduce the Tale of Two developers Domino Top Secret Industry Scenario based demo and the reach of Domino Apps Back to the Future with the Domino the Secure NOSQL Database with Node.js Hint: June

More information

What You Think Is Real Is Not Real, Learn How Splunk Uncovered The Truth!

What You Think Is Real Is Not Real, Learn How Splunk Uncovered The Truth! What You Think Is Real Is Not Real, Learn How Splunk Uncovered The Truth! Jeff Kent President m- mobo Alex Gitelzon System Administrator, APM Dennis Morton Splunk Expert m- mobo Copyright 2015 Splunk Inc.

More information

Vendor: IBM. Exam Code: Exam Name: IBM Certified Specialist Netezza Performance Software v6.0. Version: Demo

Vendor: IBM. Exam Code: Exam Name: IBM Certified Specialist Netezza Performance Software v6.0. Version: Demo Vendor: IBM Exam Code: 000-553 Exam Name: IBM Certified Specialist Netezza Performance Software v6.0 Version: Demo QUESTION NO: 1 Which CREATE DATABASE attributes are required? A. The database name. B.

More information

COMP 110/L Lecture 10. Kyle Dewey

COMP 110/L Lecture 10. Kyle Dewey COMP 110/L Lecture 10 Kyle Dewey switch Outline switch Problem if is verbose when checking many conditions. Problem if is verbose when checking many conditions. if (x == 5) { return foo ; else if (x ==

More information

Enterprise Security Biology

Enterprise Security Biology Enterprise Security Biology Dissecting the Threat Intelligence Framework John Stoner Staff Security Architect US Public Sector and then some September 2017 Forward-Looking Statements During the course

More information

<Insert Picture Here> DBA s New Best Friend: Advanced SQL Tuning Features of Oracle Database 11g

<Insert Picture Here> DBA s New Best Friend: Advanced SQL Tuning Features of Oracle Database 11g DBA s New Best Friend: Advanced SQL Tuning Features of Oracle Database 11g Peter Belknap, Sergey Koltakov, Jack Raitto The following is intended to outline our general product direction.

More information

230 Million Tweets per day

230 Million Tweets per day Tweets per day Queries per day Indexing latency Avg. query response time Earlybird - Realtime Search @twitter Michael Busch @michibusch michael@twitter.com buschmi@apache.org Earlybird - Realtime Search

More information

Extract API: Build sophisticated data models with the Extract API

Extract API: Build sophisticated data models with the Extract API Welcome # T C 1 8 Extract API: Build sophisticated data models with the Extract API Justin Craycraft Senior Sales Consultant Tableau / Customer Consulting My Office Photo Used with permission Agenda 1)

More information

Advanced Database Systems

Advanced Database Systems Lecture IV Query Processing Kyumars Sheykh Esmaili Basic Steps in Query Processing 2 Query Optimization Many equivalent execution plans Choosing the best one Based on Heuristics, Cost Will be discussed

More information

Integrating Splunk with AWS services:

Integrating Splunk with AWS services: Integrating Splunk with AWS services: Using Redshi+, Elas0c Map Reduce (EMR), Amazon Machine Learning & S3 to gain ac0onable insights via predic0ve analy0cs via Splunk Patrick Shumate Solutions Architect,

More information

Lecture 4. Lecture

Lecture 4. Lecture Interfaces Classes Building blocks Methods Arrays Example: BitArray Packages D0010E Object- Oriented Programming and Design InformaGon hiding Graphics and interacgon Example: A blinking signal Access Modifiers

More information

Lotus Technical Night School XPages and RDBMS

Lotus Technical Night School XPages and RDBMS Lotus Technical Night School XPages and RDBMS Note: Information regarding potential future products is intended to outline our general product direction and it should not be relied on in making a purchasing

More information

Wonderware Mobile Reporting

Wonderware Mobile Reporting Software Datasheet Summary Wonderware Mobile Reporting Wonderware Mobile SmartGlance & Wonderware Mobile Reporting Connector Reporting provides real-time access to critical KPIs and process data via popular

More information

Seamless Dynamic Web (and Smart Device!) Reporting with SAS D.J. Penix, Pinnacle Solutions, Indianapolis, IN

Seamless Dynamic Web (and Smart Device!) Reporting with SAS D.J. Penix, Pinnacle Solutions, Indianapolis, IN Paper RIV05 Seamless Dynamic Web (and Smart Device!) Reporting with SAS D.J. Penix, Pinnacle Solutions, Indianapolis, IN ABSTRACT The SAS Business Intelligence platform provides a wide variety of reporting

More information

Construct a sharable GPU farm for Data Scientist. Layne Peng DellEMC OCTO TRIGr

Construct a sharable GPU farm for Data Scientist. Layne Peng DellEMC OCTO TRIGr Construct a sharable GPU farm for Data Scientist Layne Peng OCTO TRIGr Agenda Introduction Problems of consuming GPU GPU-as-a Service (project ) How to manage GPU in farm? How to schedule jobs to GPU?

More information

Copyright 2014 Splunk Inc. Search in 500 easy steps. Julian Harty. SE, Splunk>

Copyright 2014 Splunk Inc. Search in 500 easy steps. Julian Harty. SE, Splunk> Copyright 2014 Splunk Inc. Search Op@miza@on in 500 easy steps Julian Harty SE, Splunk> Disclaimer During the course of this presenta@on, we may make forward looking statements regarding future events

More information

In-Memory Data Management

In-Memory Data Management In-Memory Data Management Martin Faust Research Assistant Research Group of Prof. Hasso Plattner Hasso Plattner Institute for Software Engineering University of Potsdam Agenda 2 1. Changed Hardware 2.

More information

Revit + FormIt Dynamo Studio = Awesome!

Revit + FormIt Dynamo Studio = Awesome! Revit + FormIt 360 + Dynamo Studio = Awesome! Carl Storms IMAGINiT Technologies - Senior Applications Expert @thebimsider Join the conversation #AU2016 Class summary This lab session will focus on some

More information