Data Models for Developers

Size: px
Start display at page:

Download "Data Models for Developers"

Transcription

1 Copyright 2013 Splunk Inc. Data Models for Developers Alice Neels So<ware Engineer, Splunk Brian Bingham So<ware Engineer, Splunk Content #splunkconf

2 Legal NoKces During the course of this presentakon, we may make forward- looking statements regarding future events or the expected performance of the company. We caukon you that such statements reflect our current expectakons and eskmates based on factors currently known to us and that actual events or results could differ materially. For important factors that may cause actual results to differ from those contained in our forward- looking statements, please review our filings with the SEC. The forward- looking statements made in this presentakon are being made as of the Kme and date of its live presentakon. If reviewed a<er its live presentakon, this presentakon may not contain current or accurate informakon. We do not assume any obligakon to update any forward- looking statements we may make. In addikon, any informakon about our roadmap outlines our general product direckon and is subject to change at any Kme without nokce. It is for informakonal purposes only and shall not, be incorporated into any contract or other commitment. Splunk undertakes no obligakon either to develop the features or funckonality described or to include any such feature or funckonality in a future release. Splunk, Splunk>, Splunk Storm, Listen to Your Data, SPL and The Engine for Machine Data are trademarks and registered trademarks of Splunk Inc. in the United States and other countries. All other brand names, product names, or trademarks belong to their respeccve owners Splunk Inc. All rights reserved. 2

3 Alice: About Us! At Splunk since 2011! Before this, UW CSE, then worked on ios at Apple! On the core search team! Backend architect for Data Model Brian:! Splunk since 2012! Past Life - 15 years as an SA! Lead Dev for Infra- Ops Content Team! Major Apps: VMware, ES, and several others 3

4 Agenda! What is data model, and why do I care?! Data models 101! Building a data model! AcceleraKon and management! Using data models! Q&A 4

5 What is a Data Model?

6 search and filter munge report clean- up sourcetype=access_combined source = "/home/ssorkin/banner_access.log gz" eval unique=(uid + useragent) stats dc(unique) by os_name rename dc(unique) as "Unique Visitors" os_name as "OperaKng System" 6

7 What is a Data Model? A data model is a search- Cme mapping of data onto a hierarchical structure Encapsulate the knowledge needed to build a search Pivot reports are build on top of Data Models Data- independent Screenshot here 7

8 Who is it for?! Admins/power users build data models! Business users use data models via Pivot UI! Data models can be used in apps to organize and generate searches 8

9 Why do I Care?! Search is hard! Admins and power users know how their data works! Non- technical users (usually) don t! A data model makes it easy to share and organize that knowledge 9

10 But Really! This search ( sourcetype="access_*" OR sourcetype="iis*" ) ( uri="*" ) uri=* uri_path=* status=* clientip=* referer=* useragent=* ( status=2* ) ( uri_path!=*.php OR uri_path!=*.html OR uri_path!=*.shtml OR uri_path!=*.rhtml OR uri_path! =*.asp ) ( uri_path=*.avi OR uri_path=*.swf ) ( uri_path=*.itpc OR uri_path=*.xml ) litsearch ( sourcetype=access_* OR sourcetype=iis* ) ( uri="*" ) uri=* uri_path=* status=* clientip=* referer=* useragent=* ( status=2* ) ( uri_path!=*.php OR uri_path!=*.html OR uri_path!=*.shtml OR uri_path!=*.rhtml OR uri_path!=*.asp ) ( uri_path=*.avi OR uri_path=*.swf ) ( uri_path=*.itpc OR uri_path=*.xml ) eval newx = " " eval "useragent ::: status"='useragent'+" ::: "+'status' addinfo type=count label=prereport_events fields keepcolorder=t "newx" "prestats_reserved_*" "psrsvd_*" "useragent ::: status" fillnull value=null "useragent ::: status" prestats count by newx "useragent ::: status"!! Becomes this search pivot WebIntelligence PodcastDownload count(podcastdownload) AS "Count of PodcastDownload" SPLITCOL useragent SPLITCOL status FILTER uri isnotnull NUMCOLS 100! And that s cool! 10

11 How Can I Use It? Three ways 1. Use the pivot UI to build dashboards with simple XML 2. Use the search commands (data model, pivot, tstats) to simplify building searches 3. Use data model rest endpoints 11

12 Data Models 101

13 A Data Model is a CollecKon of Objects Screenshot here 13

14 Objects Have Constraints and A/ributes Screenshot here 14

15 Child Objects Inherit Constraints and Asributes Screenshot here 15

16 Child Objects Inherit Constraints and Asributes 16

17 Pivot UI Subhead events Count of http_success events, split by useragent fields 17

18 More Info! See slides from other data models talks: AnalyKcs with Splunk Enterprise 1 & 2 18

19 Building Data Models

20 Three Root Object Types! Event maps to Splunk events requires constraints and asributes Search maps to arbitrary Splunk search (may include generakng, transforming and reporkng search commands) requires search string and asributes TransacKon maps to groups of Splunk events or groups of Splunk search results requires objects to group, fields/ condikons to group by, and asributes

21 Three Root Object Types! Event maps to Splunk events requires constraints and asributes! Search maps to arbitrary Splunk search (may include generakng, transforming and reporkng search commands) requires search string and asributes TransacKon maps to groups of Splunk events or groups of Splunk search results requires objects to group, fields/ condikons to group by, and asributes

22 Three Root Object Types! Event maps to Splunk events requires constraints and asributes! Search maps to arbitrary Splunk search (may include generakng, transforming and reporkng search commands) requires search string and asributes! TransacKon maps to groups of Splunk events or groups of Splunk search results requires objects to group, fields/ condikons to group by, and asributes

23 Child Object Facts! A child object is a type of its parent object: e.g. An HTTP_Success object is a type of HTTP_Access! Adding a child object is essenkally a way of adding a filter on the parents! A parent- child relakonship makes it easy to do queries like What percentage of my HTTP_Access events are HTTP_Success events? 23

24 Object Asributes! Auto- Extracted default and pre- defined fields! Eval Expression a new field based on an expression that you define! Lookup leverage an exiskng lookup table! Regular Expression extract a new field based on regex! Geo IP add geographical fields such as lat / lon, country, etc.

25 Object Asributes! Set field types! Configure various flags Note: Child object configurakon can differ from parent

26 Display Names! Models have a modelname and a displayname! Objects have an objectname and a displayname! They re usually the same! modelname and objectname are used internally and in search, must be unique, and can only contain! displayname is what s displayed to label charts and graphs 26

27 Other Stuff! Search and transackon objects can have children too it works the same way (they re filters)! Only event- based objects are accelerated (more on that later)! Performance degrades with the depth of the hierarchy 27

28 Other Splunk Knowledge Objects

29 How it Works with! Various Splunk knowledge objects can help make your data model more powerful! If you already have event types/tags etc., you can absolutely use these in your object constraints and asributes! When starkng from scratch, consider using your data model to do the same thing 29

30 Event Types: Background! Event types in Splunk Enterprise are a way of separakng out a single source file, into separate classificakons. Example: Apache access logs: 400 s and 200 s are in the same file, these can be broken out and used in search E.g. sourcetype=apache_access hsp_code=* NOT hsp_code=4* becomes: evensype=apache_success Can be used for tags 30

31 Event Types With Data Model! Before: set up event types via Manager E.g. Two event types: apache_success and apache_failure! With data models: in most cases, use a data model object E.g. One data model apache, with 2 objects, success and failure.! Objects provide extra power and flexibility! 31

32 Tags! A tag is associated with a parkcular field/value combinakon, or with whether a field is present on an event! In apps, the best use case for tags, is to link up mulkple data sources together based on a common goal! Most o<en based on event types. Example: tag=authenkcakon tag=success could be used to Ke together evensypes from LDAP, MySQL, Unix, MS AcKve Directory or VPN where a user successfully logged in, like evensype = ldap_auth_success or vpn_auth_success! Add through Manager 32

33 Tags with Data Model! Data model may be used with tags in several ways: To create fields that make it easier to define objects ê Usually event type tags used to make several different sources fit a common model An asribute of an object: ê Frequently a way of finding out field tagging differences in events. Great for finding out missing fields or extrackons for creakng objects that are based on a field value ê Can also use calculated fields for this 33

34 Macros, Saved Searches! Data model does not replace the common use cases for macros or saved searches, and it s important to understand when to use what! For dashboards, saving a pivot report may be preferable to saving a search (easier to modify and maintain and share)! Macros happen at a lower level of the search than data model best prackce is to NOT mix and match 34

35 Knowledge Objects Summary! There are a lot of Splunk Enterprise features that can be used with data models! By combining these features, we get lots of power and flexibility! Data model helps you manage complex data! Which features you should use will depend on your needs and data, but keep it simple! 35

36 AcceleraKon and Management

37 What is a Data Model Really?! Data models are stored as JSON files on disk (spec in docs)! They live in <myapp>/local/data/models (or <myapp>/default/ data/models for pre- installed models)! They also have associated conf stanzas and metadata

38 It Looks Like this

39 EdiKng JSON At your own risk!! EdiKng data models by hand: NOT SUPPORTED! Very easy to shoot yourself in the foot, hard to recover! When you edit models via the UI, we validate them! ExcepKon: Installing a model by adding the file to <myapp>/<local OR default>/data/models is probably okay 39

40 DeleKng a Model! Use the UI! This will do appropriate cleanup for you! If you go delekng files on disk, it s easy to break things

41 Permissions! Data models have permissions just like other splunk knowledge objects! Permissions are per model, NOT per object! Edit permissions through the UI

42 Permissions cont.! Data models exist in a parkcular app! Different user roles may or may not have read or write access! If your model relies on lookups, etc., they need to also be available in that app

43 Data Model AcceleraKon Admin or Power User Turn on acceleration via UI Setting written to conf file Backend Magic Polling: is are there new accelerated models? Kick off collection accelerakon Run search using on- disk accelerakon Non- technical User Run a pivot report no accelerakon Kick off ad- hoc accelerakon and run search 43

44 AcceleraKon Facts! Works with search- head pooling we collect on indexers! Only the first event- based object and its children are accelerated! No accelerakon for search and transackon- based objects! No edikng accelerated models

45 Using Data Models

46 Pivot Interface! Build a data model! Build a report with Pivot! Embed report in a dashboard

47 Demo 47

48 Search Commands! You can use data models in the search language! They re basically just macros

49 datamodel! Look at models datamodel Returns JSON model descripkons as separate events! Look at just one model datamodel mymodel Returns JSON model descripkon for just one model! Look at an object datamodel mymodel myobject Returns JSON object descripkon! Run the search for an object datamodel mymodel myobject search Runs the search

50 datamodel cont.! Model name and object name must be the internal names, not the display names! No accelerakon

51 pivot! Any table you can build in the pivot UI can be expressed with the pivot command! Syntax is to complex to fully cover here see docs! Open in search from pivot UI uses the pivot command! The pivot command will take advantage of accelerakon where available! Example: pivot WebIntelligence HTTP_Request count(is_http_success) AS "Count of is_http_success" count(is_http_error) AS "Count of is_http_error" count(is_http_redirect) AS "Count of is_http_redirect" FILTER status!= 404!

52 Demo 52

53 REST Endpoints! See docs for details! Two main endpoints: servicesns/<user>/<app>/datamodel/model examine models and change se~ngs servicesns/<user>/<app>/datamodel/pivot get the search for a pivot report

54 Demo 54

55 Next Steps 1 2 Download the.conf2013 Mobile App If not iphone, ipad or Android, use the Web App Take the survey & WIN A PASS FOR.CONF2014 Or one of these bags! 55

56 Q&A

57 THANK YOU

HomeAway Let s Stay Together

HomeAway Let s Stay Together Copyright 2014 Splunk Inc. Splunk @ HomeAway Let s Stay Together René X. Parra So>ware Architect, HomeAway Disclaimer During the course of this presentakon, we may make forward- looking statements regarding

More information

HTTP Event Collector in Splunk 6.5 More Super Powers!

HTTP Event Collector in Splunk 6.5 More Super Powers! Copyright 2016 Splunk Inc. HTTP Event Collector in Splunk 6.5 More Super Powers! Itay Neeman Director of Engineering, Splunk Shakeel Mohamed SoJware Engineer, Splunk Disclaimer During the course of this

More information

Splunking Wind Turbines and Keeping the Earth Green

Splunking Wind Turbines and Keeping the Earth Green Copyright 2015 Splunk Inc. Splunking Wind Turbines and Keeping the Earth Green Marijan Fofonjka Senior developer, INFIGO IS Ante MarKnić Business Unit Director, KONČAR Disclaimer During the course of this

More information

Understanding Splunk AcceleraGon Technologies David Marquardt

Understanding Splunk AcceleraGon Technologies David Marquardt Copyright 2013 Splunk Inc. Understanding Splunk AcceleraGon Technologies David Marquardt Senior So?ware Engineer #splunkconf Legal NoGces During the course of this presentagon, we may make forward- looking

More information

Search Language Intermediate Lincoln Bowser

Search Language Intermediate Lincoln Bowser Copyright 2013 Splunk Inc. Search Language Intermediate Lincoln Bowser Sr. Technical Instructor, Splunk #splunkconf Legal NoFces During the course of this presentafon, we may make forward- looking statements

More information

Visualizing the Health of Your Mobile App

Visualizing the Health of Your Mobile App Visualizing the Health of Your Mobile App Jay Tamboli ios Engineer, Capital One September 26, 2017 Washington, DC Forward-Looking Statements During the course of this presentation, we may make forward-looking

More information

Best Prac:ces + New Feature Overview for the Latest Version of Splunk Deployment Server

Best Prac:ces + New Feature Overview for the Latest Version of Splunk Deployment Server Copyright 2013 Splunk Inc. Best Prac:ces + New Feature Overview for the Latest Version of Splunk Deployment Server Gen: Zaimi Professional Services #splunkconf Legal No:ces During the course of this presenta:on,

More information

Best Practices and Better Practices for Users

Best Practices and Better Practices for Users Best Practices and Better Practices for Users while you get settled Latest Slides: https://splunk.box.com/v/blueprints-practices-user Collaborate: #bestpractices Sign Up @ http://splk.it/slack Load Feedback

More information

DB Connect Is Back. and it is better than ever. Tyler Muth Denis Vergnes. September 2017 Washington, DC

DB Connect Is Back. and it is better than ever. Tyler Muth Denis Vergnes. September 2017 Washington, DC DB Connect Is Back and it is better than ever Tyler Muth Denis Vergnes September 2017 Washington, DC Forward-Looking Statements During the course of this presentation, we may make forward-looking statements

More information

Search Language - Beginner Mitch Fleischman

Search Language - Beginner Mitch Fleischman Copyright 2013 Splunk Inc. Search Language - Beginner Mitch Fleischman Senior Instructor #splunkconf Legal NoDces During the course of this presentadon, we may make forward- looking statements regarding

More information

Time ACer Time Comparing Time Ranges in Splunk Lisa Guinn

Time ACer Time Comparing Time Ranges in Splunk Lisa Guinn Copyright 2013 Splunk Inc. Time ACer Time Comparing Time Ranges in Splunk Lisa Guinn Sr Instructor, Splunk #splunkconf Legal NoGces During the course of this presentagon, we may make forward- looking statements

More information

Next Generation Dashboards

Next Generation Dashboards Next Generation Dashboards Stephen Luedtke Sr. Technical Marketing Manager September 27, 2017 Washington, DC Forward-Looking Statements During the course of this presentation, we may make forward-looking

More information

Building Your First Splunk App with the Splunk Web Framework

Building Your First Splunk App with the Splunk Web Framework Copyright 2013 Splunk Inc. Building Your First Splunk App with the Splunk Web Framework Itay Neeman Dev Manager, Splunk Sea@le #splunkconf Legal NoMces During the course of this presentamon, we may make

More information

Metrics Analysis with the Splunk Platform

Metrics Analysis with the Splunk Platform Metrics Analysis with the Splunk Platform How to work with metrics for Monitoring, Alerting, and ad-hoc analysis at scale Michael Porath Product Management, Splunk Allan Yan Principal Software Engineer,

More information

Dashboard Time Selection

Dashboard Time Selection Dashboard Time Selection Balancing flexibility with a series of system-crushing searches Chuck Gilbert Analyst, chuck_gilbert@comcast.com September 2017 Washington, DC Forward-Looking Statements During

More information

Create Dashboards that People Love

Create Dashboards that People Love Create Dashboards that People Love Introducing Splunk Dashboard Design Guidelines Iryna Vogler User Experience Design September 26, 2017 Washington, DC Forward-Looking Statements During the course of this

More information

How to actually use Splunk Data Models

How to actually use Splunk Data Models Copyright 2014 Splunk Inc. How to actually use Splunk Data Models David Clawson SplunkYoda Disclaimer During the course of this presentadon, we may make forward- looking statements regarding future events

More information

Data Onboarding. Where Do I begin? Luke Netto Senior Professional Services Splunk. September 26, 2017 Washington, DC

Data Onboarding. Where Do I begin? Luke Netto Senior Professional Services Splunk. September 26, 2017 Washington, DC Data Onboarding Where Do I begin? Luke Netto Senior Professional Services Consultant @ Splunk September 26, 2017 Washington, DC Forward-Looking Statements During the course of this presentation, we may

More information

Measuring HEC Performance For Fun and Profit

Measuring HEC Performance For Fun and Profit Measuring HEC Performance For Fun and Profit Itay Neeman Director, Engineering, Splunk Clif Gordon Principal Software Engineer, Splunk September 2017 Washington, DC Forward-Looking Statements During the

More information

Atlassian s Journey Into Splunk

Atlassian s Journey Into Splunk Atlassian s Journey Into Splunk The Building Of Our Logging Pipeline On AWS Tim Clancy Engineering Manager, Observability James Mackie Infrastructure Engineer, Observability September 2017 Washington,

More information

Search Optimization. Alex James. Karthik Sabhanatarajan. Principal Product Manager, Splunk. Senior Software Engineer, Splunk

Search Optimization. Alex James. Karthik Sabhanatarajan. Principal Product Manager, Splunk. Senior Software Engineer, Splunk Copyright 2016 Splunk Inc. Search Optimization Alex James Principal Product Manager, Splunk & Karthik Sabhanatarajan Senior Software Engineer, Splunk Session Outline Why Optimize SPL? What does optimization

More information

What You Think Is Real Is Not Real, Learn How Splunk Uncovered The Truth!

What You Think Is Real Is Not Real, Learn How Splunk Uncovered The Truth! What You Think Is Real Is Not Real, Learn How Splunk Uncovered The Truth! Jeff Kent President m- mobo Alex Gitelzon System Administrator, APM Dennis Morton Splunk Expert m- mobo Copyright 2015 Splunk Inc.

More information

Squeezing all the Juice out of Splunk Enterprise Security

Squeezing all the Juice out of Splunk Enterprise Security Squeezing all the Juice out of Splunk Enterprise Security Marquis Montgomery, CISSP Sr. Staff Security Consultant, Splunk Jae Jung Professional Services Consultant, Splunk September 23 25, 2017 Washington,

More information

Onboard Data into Splunk, Correctly

Onboard Data into Splunk, Correctly Copyright 2013 Splunk Inc. Onboard Data into Splunk, Correctly Ma:hew Se=pane Professional Services Manager, Splunk #splunkconf Legal NoJces During the course of this presentajon, we may make forward-

More information

Data Obfuscation and Field Protection in Splunk

Data Obfuscation and Field Protection in Splunk Data Obfuscation and Field Protection in Splunk Angelo Brancato Security Specialist Dirk Nitschke Senior Sales Engineer 28 September 2017 Washington, DC 2017 SPLUNK INC. Agenda Protect Your Machine Data

More information

Need for Speed: Unleashing the Power of SecOps with Adaptive Response. Malhar Shah CEO, Crest Data Systems Meera Shankar Alliance Manager, Splunk

Need for Speed: Unleashing the Power of SecOps with Adaptive Response. Malhar Shah CEO, Crest Data Systems Meera Shankar Alliance Manager, Splunk Need for Speed: Unleashing the Power of SecOps with Adaptive Response Malhar Shah CEO, Crest Data Systems Meera Shankar Alliance Manager, Splunk September 27, 2017 Washington, DC Forward-Looking Statements

More information

FFIEC Cybersecurity Assessment Tool

FFIEC Cybersecurity Assessment Tool FFIEC Cybersecurity Assessment Tool Cybersecurity Controls & Incidence Mappings for Splunk Enterprise, Enterprise Security, User Behavior Analytics Curtis Johnson Senior Sales Engineer & Security SME September

More information

Extending SPL with Custom Search Commands

Extending SPL with Custom Search Commands Extending SPL with Custom Search Commands Jacob Leverich Director of Engineering 2017/08/11 Washington, DC Forward-Looking Statements During the course of this presentation, we may make forward-looking

More information

Running Splunk Enterprise within Docker

Running Splunk Enterprise within Docker Running Splunk Enterprise within Docker Michael Clayfield Partner Consultant 03/09/2017 1.1 Forward-Looking Statements During the course of this presentation, we may make forward-looking statements regarding

More information

Making the Most of the Splunk Scheduler

Making the Most of the Splunk Scheduler Making the Most of the Splunk Scheduler Paul J. Lucas Principal Software Engineer, Splunk September 25 28, 2017 Washington, DC Forward-Looking Statements During the course of this presentation, we may

More information

Using Splunk Enterprise To Optimize Tailored Long-term Data Retention

Using Splunk Enterprise To Optimize Tailored Long-term Data Retention Using Splunk Enterprise To Optimize Tailored Long-term Data Retention Tomasz Bania Incident Response Lead, Dolby Eric Krieser Splunk Professional Services September 2017 Washington, DC Forward-Looking

More information

Docker and Splunk Development

Docker and Splunk Development Docker and Splunk Development Empowering Splunk Development with Docker Ron Cooper & David Kraemer Booz Allen Hamilton 26 September 2017 Washington, DC Forward-Looking Statements During the course of this

More information

Tracking Logs at Zillow with Lookups & JIRA

Tracking Logs at Zillow with Lookups & JIRA Tracking Logs at Zillow with Lookups & JIRA Seth Thomas, Jon Wentworth September 27 Washington, DC Forward-Looking Statements During the course of this presentation, we may make forward-looking statements

More information

Splunking with Multiple Personalities

Splunking with Multiple Personalities Splunking with Multiple Personalities Extending Role Based Access Control to achieve fine grain security of your data Sabrina Lea Senior Sales Engineer, Splunk Shaun C Splunk Customer September 2017 Forward-Looking

More information

Search Head Clustering Basics To Best Practices

Search Head Clustering Basics To Best Practices Search Head Clustering Basics To Best Practices Bharath Aleti Product Manager, Splunk Manu Jose Sr. Software Engineer, Splunk September 2017 Washington, DC Forward-Looking Statements During the course

More information

Bring Context To Your Machine Data With Hadoop, RDBMS & Splunk

Bring Context To Your Machine Data With Hadoop, RDBMS & Splunk Bring Context To Your Machine Data With Hadoop, RDBMS & Splunk Raanan Dagan and Rohit Pujari September 25, 2017 Washington, DC Forward-Looking Statements During the course of this presentation, we may

More information

The Power of Data Normalization. A look at the Common Information Model

The Power of Data Normalization. A look at the Common Information Model The Power of Data Normalization A look at the Common Information Model Mark Bonsack, CISSP Vladimir Skoryk, CISSP, CCFE, CHFI, CISA, CISM, RGTT Staff Sales Engineer, Splunk PS Supreme Architect, Splunk

More information

Fields, Indexed Tokens, And You

Fields, Indexed Tokens, And You Fields, Indexed Tokens, And You Martin Müller Professional Services Consultant, Consist Software Solutions GmbH September 42 nd, 2017 Washington, DC Forward-Looking Statements During the course of this

More information

A Trip Through The Splunk Data Ingestion And Retrieval Pipeline

A Trip Through The Splunk Data Ingestion And Retrieval Pipeline A Trip Through The Splunk Data Ingestion And Retrieval Pipeline Harold Murn Senior Systems Engineer 2017-09-27 Washington, DC Forward-Looking Statements During the course of this presentation, we may make

More information

Architecting Splunk For High Availability And Disaster Recovery

Architecting Splunk For High Availability And Disaster Recovery Architecting Splunk For High Availability And Disaster Recovery Sean Delaney Principal Architect, Splunk September 2017 Washington, DC Forward-Looking Statements During the course of this presentation,

More information

Dashboards & Visualizations: What s New

Dashboards & Visualizations: What s New Dashboards & Visualizations: What s New Nicholas Filippi Product Management, Splunk Patrick Ogdin Product Management, Splunk September 2017 Washington, DC Welcome Patrick Ogdin Product Management, Splunk

More information

Adding Depth to Dashboards

Adding Depth to Dashboards Copyright 2015 Splunk Inc. Adding Depth to Dashboards Pierre Brunel Splunk Disclaimer During the course of this presentacon, we may make forward looking statements regarding future events or the expected

More information

IntegraBng Splunk Data and FuncBonality Using the Splunk SDK for Java

IntegraBng Splunk Data and FuncBonality Using the Splunk SDK for Java Copyright 2013 Splunk Inc. IntegraBng Splunk Data and FuncBonality Using the Splunk SDK for Java Damien Dallimore Developer Evangelist @ Splunk #splunkconf Legal NoBces During the course of this presentabon,

More information

Dashboard Wizardry. Advanced Dashboard Interactivity. Siegfried Puchbauer Principal Software Engineer Yuxiang Kou Software Engineer

Dashboard Wizardry. Advanced Dashboard Interactivity. Siegfried Puchbauer Principal Software Engineer Yuxiang Kou Software Engineer Dashboard Wizardry Advanced Dashboard Interactivity Siegfried Puchbauer Principal Software Engineer Yuxiang Kou Software Engineer September 25, 2017 Washington, DC Brought To You By Siegfried Puchbauer

More information

Vector Issue Tracker and License Manager - Administrator s Guide. Configuring and Maintaining Vector Issue Tracker and License Manager

Vector Issue Tracker and License Manager - Administrator s Guide. Configuring and Maintaining Vector Issue Tracker and License Manager Vector Issue Tracker and License Manager - Administrator s Guide Configuring and Maintaining Vector Issue Tracker and License Manager Copyright Vector Networks Limited, MetaQuest Software Inc. and NetSupport

More information

MB2-712 Q&As Microsoft Dynamics CRM 2016 Customization and Configuration

MB2-712 Q&As Microsoft Dynamics CRM 2016 Customization and Configuration CertBus.com MB2-712 Q&As Microsoft Dynamics CRM 2016 Customization and Configuration Pass Microsoft MB2-712 Exam with 100% Guarantee Free Download Real Questions & Answers PDF and VCE file from: 100% Passing

More information

Bringing Sweetness to Sour Patch Tuesday

Bringing Sweetness to Sour Patch Tuesday Bringing Sweetness to Sour Patch Tuesday Pacific Northwest National Laboratory Justin Brown & Arzu Gosney September 27, 2017 Washington, DC Forward-Looking Statements During the course of this presentation,

More information

Introducing Splunk Validated Architectures (SVA)

Introducing Splunk Validated Architectures (SVA) Introducing Splunk Validated Architectures (SVA) Optimizing Your Path To Success With Splunk Sean Delaney Principal Architect Stefan Sievert Staff Architect September 2017 Washington, DC Forward-Looking

More information

Scaling Indexer Clustering

Scaling Indexer Clustering Scaling Indexer Clustering 5 Million Unique Buckets and Beyond Cher-Hung Chang Principal Software Engineer Tameem Anwar Software Engineer 09/26/2017 Washington, DC Forward-Looking Statements During the

More information

Splunk & AWS. Gain real-time insights from your data at scale. Ray Zhu Product Manager, AWS Elias Haddad Product Manager, Splunk

Splunk & AWS. Gain real-time insights from your data at scale. Ray Zhu Product Manager, AWS Elias Haddad Product Manager, Splunk Splunk & AWS Gain real-time insights from your data at scale Ray Zhu Product Manager, AWS Elias Haddad Product Manager, Splunk Forward-Looking Statements During the course of this presentation, we may

More information

Making Sense of Web Fraud With Splunk Stream

Making Sense of Web Fraud With Splunk Stream Making Sense of Web Fraud With Splunk Stream An in-depth look at Stream use cases and customer success stories with a focus on stream:http Jim Apger Minister of Mayhem Senior Security Architect Matthew

More information

Monitoring Docker Containers with Splunk

Monitoring Docker Containers with Splunk Monitoring Docker Containers with Splunk Marc Chéné Product Manager Sept 27, 2017 Washington, DC Forward-Looking Statements During the course of this presentation, we may make forward-looking statements

More information

Indexer Clustering Internals & Performance

Indexer Clustering Internals & Performance Indexer Clustering Internals & Performance Da Xu Chloe Yeung September 28, 2017 Washington, DC Forward-Looking Statements During the course of this presentation, we may make forward-looking statements

More information

Essentials to creating your own Security Posture using Splunk Enterprise

Essentials to creating your own Security Posture using Splunk Enterprise Essentials to creating your own Security Posture using Splunk Enterprise Using Splunk to maximize the efficiency and effectiveness of the SOC / IR Richard W. McKee, MS-ISA, CISSP Principal Cyber Security

More information

IN: US:

IN: US: About Intellipaat Intellipaat is a fast-growing professional training provider that is offering training in over 150 most sought-after tools and technologies. We have a learner base of 600,000 in over

More information

Enterprise Security Biology

Enterprise Security Biology Enterprise Security Biology Dissecting the Threat Intelligence Framework John Stoner Staff Security Architect US Public Sector and then some September 2017 Forward-Looking Statements During the course

More information

Docker Universal Control Plane Deploy and Manage On-Premises, Your Dockerized Distributed Applications

Docker Universal Control Plane Deploy and Manage On-Premises, Your Dockerized Distributed Applications Technical Brief Docker Universal Control Plane Deploy and Manage On-Premises, Your Dockerized Distributed Applications As application teams deploy their Dockerized applications into production environments,

More information

Indexer Clustering Fixups

Indexer Clustering Fixups Indexer Clustering Fixups Cluster recovery process Da Xu Engineering Splunk Forward-Looking Statements During the course of this presentation, we may make forward-looking statements regarding future events

More information

Copyright 2015 Splunk Inc. The state of Splunk. Using the KVStore to maintain App State. Stefan Sievert. Client Architect, Splunk Inc.

Copyright 2015 Splunk Inc. The state of Splunk. Using the KVStore to maintain App State. Stefan Sievert. Client Architect, Splunk Inc. Copyright 2015 Splunk Inc. The state of Splunk Using the KVStore to maintain App State Stefan Sievert Client Architect, Splunk Inc. Disclaimer During the course of this presentagon, we may make forward

More information

The Art of Detection. Using Splunk Enterprise Security

The Art of Detection. Using Splunk Enterprise Security The Art of Detection Using Splunk Enterprise Security Doug Brown Senior Information Security Analyst, Red Hat 95B6 922E 47D2 7BC3 D1AF F62C 82BC 992E 7CDD 63B6 September 27, 2017 Washington, DC PRESENTATIONS.

More information

Develop Mobile Front Ends Using Mobile Application Framework A - 2

Develop Mobile Front Ends Using Mobile Application Framework A - 2 Develop Mobile Front Ends Using Mobile Application Framework A - 2 Develop Mobile Front Ends Using Mobile Application Framework A - 3 Develop Mobile Front Ends Using Mobile Application Framework A - 4

More information

Dragons and Splunk Do Not Do Well In Captivity

Dragons and Splunk Do Not Do Well In Captivity Dragons and Splunk Do Not Do Well In Captivity Tame Splunk Dragons Before Winter Comes Kyle Prins & Keith Quebodeaux DellEMC Splunk Ninjas September 2017 Washington, DC Forward-Looking Statements During

More information

Splunk for Akamai Cloud Monitor

Splunk for Akamai Cloud Monitor Copyright 2015 Splunk Inc. Splunk for Akamai Cloud Monitor Pierre Pellissier Leela Kesireddy Performance Management PayPal, Inc. Disclaimer During the course of this presentaeon, we may make forward looking

More information

Configuration Guide. How to connect to an IPSec VPN using an iphone in ios. Overview

Configuration Guide. How to connect to an IPSec VPN using an iphone in ios. Overview Configuration Guide How to connect to an IPSec VPN using an iphone in ios Overview Currently, users can conveniently use the built-in IPSec client on an iphone to connect to a VPN server. IPSec VPN can

More information

Replication of summary data in indexer cluster

Replication of summary data in indexer cluster Copyright 2016 Splunk Inc. Replication of summary data in indexer cluster Dhruva Kumar Bhagi Sr. Software engineer Splunk Inc. Disclaimer During the course of this presentation, we may make forward looking

More information

Copyright 2013 Splunk Inc. Hardening Splunk. Alex Eisen Chief Security Expat R&D Eng / Product Security #splunkconf

Copyright 2013 Splunk Inc. Hardening Splunk. Alex Eisen Chief Security Expat R&D Eng / Product Security #splunkconf Copyright 2013 Splunk Inc. Hardening Splunk Alex Eisen Chief Security Expat R&D Eng / Product Security #splunkconf Legal NoIces During the course of this presentaion, we may make forward- looking statements

More information

Cross-Platform Parallels: Understanding SharePoint (Online) Through Notes-colored glasses

Cross-Platform Parallels: Understanding SharePoint (Online) Through Notes-colored glasses Cross-Platform Parallels: Understanding SharePoint (Online) Through Notes-colored glasses Presented by Ben Menesi Speaker Head of Product at Ytria IBM Notes Domino Admin & Dev. for the past 10 years Actually

More information

Modernizing InfoSec Training and IT Operations at USF

Modernizing InfoSec Training and IT Operations at USF Modernizing InfoSec Training and IT Operations at USF Goodbye Tedious Tasks! A Novel Automation Framework Leveraging Splunk Tim Ip, Senior Security Engineer Nicholas Recchia, Director & Information Security

More information

Enterprise Vault Best Practices

Enterprise Vault Best Practices Enterprise Vault Best Practices Implementing SharePoint Archiving This document contains information on best practices when implementing Enterprise Vault for SharePoint If you have any feedback or questions

More information

Splunk N Box. Splunk Multi-Site Clusters In 20 Minutes or Less! Mohamad Hassan Sales Engineer. 9/25/2017 Washington, DC

Splunk N Box. Splunk Multi-Site Clusters In 20 Minutes or Less! Mohamad Hassan Sales Engineer. 9/25/2017 Washington, DC Splunk N Box Splunk Multi-Site Clusters In 20 Minutes or Less! Mohamad Hassan Sales Engineer 9/25/2017 Washington, DC Forward-Looking Statements During the course of this presentation, we may make forward-looking

More information

Splunk For Google Analytics

Splunk For Google Analytics Copyright 2016 Splunk Inc. Splunk For Google Analytics Charles Adriaenssens, Business Analytics Lead Rory Blake, Staff PS Consultant Disclaimer During the course of this presentation, we may make forward

More information

What's New in Laserfiche Rio, Laserfiche Avante, Laserfiche Forms, and Laserfiche Connector White Paper

What's New in Laserfiche Rio, Laserfiche Avante, Laserfiche Forms, and Laserfiche Connector White Paper What's New in Laserfiche Rio, Laserfiche Avante, Laserfiche Forms, and Laserfiche Connector 10.2 White Paper Table of Contents New Features in the Laserfiche Server, Web Client, and Windows Client... 4

More information

Light IT Up! Better Monitoring in Splunk with Custom Actions, Search Commands and Dashboards JUSTIN BROWN

Light IT Up! Better Monitoring in Splunk with Custom Actions, Search Commands and Dashboards JUSTIN BROWN Light IT Up! Better Monitoring in Splunk with Custom Actions, Search Commands and Dashboards JUSTIN BROWN Pacific Northwest National Laboratory NLIT 2018 Light IT Up! Better Monitoring in Splunk with Custom

More information

Getting Started with Rational Team Concert

Getting Started with Rational Team Concert Getting Started with Rational Team Concert or RTC in 16 Steps Kai-Uwe Maetzel IBM Rational Software kai-uwe_maetzel@us.ibm.com SDP 20 2009 IBM Corporation This Presentation is Good for You if You know

More information

Centrify for Splunk Integration Guide

Centrify for Splunk Integration Guide July 2018 Centrify Corporation Abstract This guide is written for Centrify Infrastructure Services customers who want to integrate Centrify events with Splunk. Legal Notice This document and the software

More information

Perceptive Experience Content Apps

Perceptive Experience Content Apps Perceptive Experience Content Apps Technical Specifications Version: 1.4.0 Written by: Product Knowledge, R&D Date: Monday, July 18, 2016 2014-2016 Lexmark International Technology, S.A. All rights reserved.

More information

DRS: Advanced Concepts, Best Practices and Future Directions

DRS: Advanced Concepts, Best Practices and Future Directions INF-VSP2825 DRS: Advanced Concepts, Best Practices and Future Directions Aashish Parikh, VMware, Inc. Ajay Gulati, VMware, Inc. #vmworldinf Disclaimer This session may contain product features that are

More information

Splunk Helping in Productivity

Splunk Helping in Productivity Splunk Helping in Productivity Sumit Nagal Principal Engineer, Intuit @sumitnagal 27-Sept-2017 Washington, DC Forward-Looking Statements During the course of this presentation, we may make forward-looking

More information

Symbio Manual. Administrator Role

Symbio Manual. Administrator Role Symbio Manual Administrator Role Version date: November 18 2018 Ploetz + Zeller GmbH Symbio Manual - Administrator Role 2 Content 1 Introduction 9 1.1 About this document 9 1.2 Before you start 9 1.3 Support

More information

Demystifying Newforma Indexing David Dark Development Liaison. September 15, 2015

Demystifying Newforma Indexing David Dark Development Liaison. September 15, 2015 Demystifying Newforma Indexing David Dark Development Liaison September 15, 2015 About David Dark David Dark Development Liaison ddark@newforma.com linkedin.com/in/davidrdark Agenda 1. Indexing History

More information

Symbio Manual. Administrator Role

Symbio Manual. Administrator Role Symbio Manual Administrator Role Version date: November 18 2018 Ploetz + Zeller GmbH Symbio Manual - Administrator Role 2 Content 1 Introduction 9 1.1 About this document 9 1.2 Before you start 9 1.3 Support

More information

Liferay User Management. Kar Joon Chew Oct 2011

Liferay User Management. Kar Joon Chew Oct 2011 Liferay User Management Kar Joon Chew Oct 2011 Terminology You will See 2 Understand the Relationship 3 Resource Resources are scoped into portal, group, page, and content model-resource and application

More information

<Insert Picture Here> Looking at Performance - What s new in MySQL Workbench 6.2

<Insert Picture Here> Looking at Performance - What s new in MySQL Workbench 6.2 Looking at Performance - What s new in MySQL Workbench 6.2 Mario Beck MySQL Sales Consulting Manager EMEA The following is intended to outline our general product direction. It is

More information

Inside Secrets From Support- How to Solve the Top 10 Support Issues

Inside Secrets From Support- How to Solve the Top 10 Support Issues Copyright 2014 Splunk Inc. Inside Secrets From Support- How to Solve the Top 10 Support Issues Barak Reeves Sales Engineer, Splunk Todd Gow Sales Engineer, Splunk Disclaimer During the course of this presentajon,

More information

Matrix42 Mobile. Technical Documentation. Matrix42 Mobile v September Copyright 2015 VMware, Inc. All rights reserved

Matrix42 Mobile. Technical Documentation. Matrix42 Mobile v September Copyright 2015 VMware, Inc. All rights reserved Matrix42 Mobile Technical Documentation Copyright 2015 VMware, Inc. All rights reserved Instructions for App Vendors: Please fill in the appropriate field for each section. If you do not have capabilities

More information

GroupWise Architecture and Best Practices. WebAccess. Kiran Palagiri Team Lead GroupWise WebAccess

GroupWise Architecture and Best Practices. WebAccess. Kiran Palagiri Team Lead GroupWise WebAccess GroupWise Architecture and Best Practices WebAccess Kiran Palagiri Team Lead GroupWise WebAccess kpalagiri@novell.com Ed Hanley Senior Architect ed.hanley@novell.com Agenda Kiran Palagiri Architectural

More information

Connect with Remedy: SmartIT: Social Event Manager Webinar Q&A

Connect with Remedy: SmartIT: Social Event Manager Webinar Q&A Connect with Remedy: SmartIT: Social Event Manager Webinar Q&A Q: Will Desktop/browser alerts be added to notification capabilities on SmartIT? A: In general we don't provide guidance on future capabilities.

More information

User Guide HelpSystems Insite 1.6

User Guide HelpSystems Insite 1.6 User Guide HelpSystems Insite 1.6 Copyright Copyright HelpSystems, LLC. HelpSystems Insite, OPAL, OPerator Assistance Language, Robot ALERT, Robot AUTOTUNE, Robot CLIENT, Robot CONSOLE, Robot CORRAL, Robot

More information

PAC485 Managing Datacenter Resources Using the VirtualCenter Distributed Resource Scheduler

PAC485 Managing Datacenter Resources Using the VirtualCenter Distributed Resource Scheduler PAC485 Managing Datacenter Resources Using the VirtualCenter Distributed Resource Scheduler Carl Waldspurger Principal Engineer, R&D This presentation may contain VMware confidential information. Copyright

More information

Power BI 1 - Create a dashboard on powerbi.com... 1 Power BI 2 - Model Data with the Power BI Desktop... 1

Power BI 1 - Create a dashboard on powerbi.com... 1 Power BI 2 - Model Data with the Power BI Desktop... 1 Our course outlines are 1 and 2 hour sessions (all courses 1 hour unless stated) that are designed to be delivered presentation style with an instructor guiding attendees through scenario based examples

More information

Netfilter Iptables for Splunk Documentation

Netfilter Iptables for Splunk Documentation Netfilter Iptables for Splunk Documentation Release 0 Guilhem Marchand Oct 06, 2017 Contents 1 Overview: 3 1.1 About the Netfilter Iptables application for Splunk........................... 3 1.2 Release

More information

Mozy. Administrator Guide

Mozy. Administrator Guide Mozy Administrator Guide Preface 2017 Mozy, Inc. All rights reserved. Information in this document is subject to change without notice. The software described in this document is furnished under a license

More information

KV Store: Hammer Time

KV Store: Hammer Time Copyright 2016 Splunk Inc. KV Store: Hammer Time Nadine Miller Technical Support Engineer, Splunk aka 'vraptor' on IRC and Slack Disclaimer During the course of this presentation, we may make forward looking

More information

Android Enterprise OEMConfig Setup. Guide to help OEM developers create OEMConfig applications to enforce proprietary and privileged APIs.

Android Enterprise OEMConfig Setup. Guide to help OEM developers create OEMConfig applications to enforce proprietary and privileged APIs. Android Enterprise OEMConfig Setup Guide to help OEM developers create OEMConfig applications to enforce proprietary and privileged APIs. OEMConfig Use case To help meet advanced customer use cases that

More information

Copyright 2012, Oracle and/or its affiliates. All rights reserved. Insert Information Protection Policy Classification from Slide 13

Copyright 2012, Oracle and/or its affiliates. All rights reserved. Insert Information Protection Policy Classification from Slide 13 1 Roadmap Dave Bain PeopleSoft Product Management 2 The following is intended to outline our general product direction. It is intended for information purposes only, and may not be incorporated into any

More information

NetIQ AppManager, Version 8 New Features

NetIQ AppManager, Version 8 New Features NetIQ AppManager, Version 8 New Features January 2012 NETIQ APPMANAGER 8: NEW FEATURES 1 Table of Contents Introduction: NetIQ AppManager 8 New Features... 5 NetIQ AppManager Setup... 5 Operations... 5

More information

2012 Microsoft Corporation. All rights reserved. Microsoft, Active Directory, Excel, Lync, Outlook, SharePoint, Silverlight, SQL Server, Windows,

2012 Microsoft Corporation. All rights reserved. Microsoft, Active Directory, Excel, Lync, Outlook, SharePoint, Silverlight, SQL Server, Windows, 2012 Microsoft Corporation. All rights reserved. Microsoft, Active Directory, Excel, Lync, Outlook, SharePoint, Silverlight, SQL Server, Windows, Windows Server, and other product names are or may be registered

More information

Oracle Enterprise Manager Ops Center. Introduction. Creating Oracle Solaris 11 Zones Guide 12c Release 1 ( )

Oracle Enterprise Manager Ops Center. Introduction. Creating Oracle Solaris 11 Zones Guide 12c Release 1 ( ) Oracle Enterprise Manager Ops Center Creating Oracle Solaris 11 Zones Guide 12c Release 1 (12.1.0.0.0) E27336-01 April 2012 This guide provides an end-to-end example for how to use Oracle Enterprise Manager

More information

GETTING STARTED WITH THE BLOOMZ APP

GETTING STARTED WITH THE BLOOMZ APP GETTING STARTED WITH THE BLOOMZ APP The following instructions will help you navigate through our app and familiarize with some of the app s features. Notice that, while this is an in-depth look into some

More information

Seamless Dynamic Web (and Smart Device!) Reporting with SAS D.J. Penix, Pinnacle Solutions, Indianapolis, IN

Seamless Dynamic Web (and Smart Device!) Reporting with SAS D.J. Penix, Pinnacle Solutions, Indianapolis, IN Paper RIV05 Seamless Dynamic Web (and Smart Device!) Reporting with SAS D.J. Penix, Pinnacle Solutions, Indianapolis, IN ABSTRACT The SAS Business Intelligence platform provides a wide variety of reporting

More information