Docker and Splunk Development

Similar documents
DB Connect Is Back. and it is better than ever. Tyler Muth Denis Vergnes. September 2017 Washington, DC

Create Dashboards that People Love

Running Splunk Enterprise within Docker

FFIEC Cybersecurity Assessment Tool

Measuring HEC Performance For Fun and Profit

Dragons and Splunk Do Not Do Well In Captivity

Dashboard Time Selection

Introducing Splunk Validated Architectures (SVA)

Using Splunk Enterprise To Optimize Tailored Long-term Data Retention

Next Generation Dashboards

Visualizing the Health of Your Mobile App

Scaling Indexer Clustering

Splunk N Box. Splunk Multi-Site Clusters In 20 Minutes or Less! Mohamad Hassan Sales Engineer. 9/25/2017 Washington, DC

Indexer Clustering Fixups

Architecting Splunk For High Availability And Disaster Recovery

Data Obfuscation and Field Protection in Splunk

Indexer Clustering Internals & Performance

A Trip Through The Splunk Data Ingestion And Retrieval Pipeline

Making the Most of the Splunk Scheduler

Atlassian s Journey Into Splunk

Splunk & AWS. Gain real-time insights from your data at scale. Ray Zhu Product Manager, AWS Elias Haddad Product Manager, Splunk

Bring Context To Your Machine Data With Hadoop, RDBMS & Splunk

Dashboard Wizardry. Advanced Dashboard Interactivity. Siegfried Puchbauer Principal Software Engineer Yuxiang Kou Software Engineer

Metrics Analysis with the Splunk Platform

The Power of Data Normalization. A look at the Common Information Model

Need for Speed: Unleashing the Power of SecOps with Adaptive Response. Malhar Shah CEO, Crest Data Systems Meera Shankar Alliance Manager, Splunk

Data Onboarding. Where Do I begin? Luke Netto Senior Professional Services Splunk. September 26, 2017 Washington, DC

Search Head Clustering Basics To Best Practices

Deployment Patterns using Docker and Chef

Dashboards & Visualizations: What s New

Making Sense of Web Fraud With Splunk Stream

Monitoring Docker Containers with Splunk

Modernizing InfoSec Training and IT Operations at USF

Best Practices and Better Practices for Users

Bringing Sweetness to Sour Patch Tuesday

Building a Threat-Based Cyber Team

Splunking with Multiple Personalities

Merging Enterprise Applications with Docker* Container Technology

Essentials to creating your own Security Posture using Splunk Enterprise

Docker Networking In OpenStack What you need to know now. Fawad Khaliq

Logging, Monitoring, and Alerting

IBM Bluemix compute capabilities IBM Corporation

Extending SPL with Custom Search Commands

Tracking Logs at Zillow with Lookups & JIRA

Performance Testing in a Containerized World. Paola Rossaro

Fast and Easy Persistent Storage for Docker* Containers with Storidge and Intel

Best Prac:ces + New Feature Overview for the Latest Version of Splunk Deployment Server

CNA1699BU Running Docker on your Existing Infrastructure with vsphere Integrated Containers Martijn Baecke Patrick Daigle VMworld 2017 Content: Not fo

개발자와운영자를위한 DevOps 플랫폼 OpenShift Container Platform. Hyunsoo Senior Solution Architect 07.Feb.2017

VMworld 2017 Content: Not for publication #CNA1699BE CONFIDENTIAL 2

Roadmap: Operating Pentaho at Scale. Jens Bleuel Senior Product Manager, Pentaho

Unify DevOps and SecOps: Security Without Friction

Copyright 2012, Oracle and/or its affiliates. All rights reserved.

SUSE OpenStack Cloud. Enabling your SoftwareDefined Data Center. SUSE Expert Days. Nyers Gábor Trainer &

Squeezing all the Juice out of Splunk Enterprise Security

Search Language - Beginner Mitch Fleischman

Docker and Oracle Everything You Wanted To Know

CONTAINERS AND MICROSERVICES WITH CONTRAIL

Building Your First Splunk App with the Splunk Web Framework

Docker containers and/or/vs virtualization Overview. Tomasz Jordan Kruk, Ph.D. Warsaw University of Technology

Fields, Indexed Tokens, And You

Virtualization Introduction

Welcome to Tomorrow... Today

Migrating Applications with CloudCenter

Amir Zipory Senior Solutions Architect, Redhat Israel, Greece & Cyprus

Splunk Helping in Productivity

What is Dell EMC Cloud for Microsoft Azure Stack?

Xen Summit Spring 2007

Linux on System z: Making the Exception Exceptional

Practical Guide to Platform as a Service.

Red Hat Atomic Details Dockah, Dockah, Dockah! Containerization as a shift of paradigm for the GNU/Linux OS

A Hands on Introduction to Docker

Container Adoption for NFV Challenges & Opportunities. Sriram Natarajan, T-Labs Silicon Valley Innovation Center

Red Hat Container Strategy Ahmed El-Rayess

Advanced Cloud Infrastructures

PUBLIC AND HYBRID CLOUD: BREAKING DOWN BARRIERS

Cisco Container Platform

The Post-Cloud. Where Google, DevOps, and Docker Converge

Important DevOps Technologies (3+2+3days) for Deployment

Enterprise Security Biology

Transform Your Business with Hybrid Cloud

Disclaimer This presentation may contain product features that are currently under development. This overview of new technology represents no commitme

Securing your Virtualized Datacenter. Charu Chaubal Senior Architect, Technical Marketing 6 November, 2008

FIVE REASONS YOU SHOULD RUN CONTAINERS ON BARE METAL, NOT VMS

Cisco CloudCenter Solution with Cisco ACI: Common Use Cases

I keep hearing about DevOps What is it?

Adobe Digital Marketing s IT Transformation with OpenStack

Create a DBaaS Catalog in an Hour with a PaaS-Ready Infrastructure

From development to production

CONTAINER CLOUD SERVICE. Managing Containers Easily on Oracle Public Cloud

How to Put Your AF Server into a Container

An Oracle Technical White Paper September Oracle VM Templates for PeopleSoft

Azure Administrator Role

How Microsoft Azure Stack Streamlines Bi-Modal IT

Integrating Splunk And AWS Lambda

How to Dodge Container Availability Challenges in Production

TALK THUNDER SOFTWARE FOR BARE METAL HIGH-PERFORMANCE SOFTWARE FOR THE MODERN DATA CENTER WITH A10 DATASHEET YOUR CHOICE OF HARDWARE

HP SDN Document Portfolio Introduction

Przyspiesz tworzenie aplikacji przy pomocy Openshift Container Platform. Jarosław Stakuń Senior Solution Architect/Red Hat CEE

Data Center and Cloud Automation

Transcription:

Docker and Splunk Development Empowering Splunk Development with Docker Ron Cooper & David Kraemer Booz Allen Hamilton 26 September 2017 Washington, DC

Forward-Looking Statements During the course of this presentation, we may make forward-looking statements regarding future events or the expected performance of the company. We caution you that such statements reflect our current expectations and estimates based on factors currently known to us and that actual events or results could differ materially. For important factors that may cause actual results to differ from those contained in our forward-looking statements, please review our filings with the SEC. The forward-looking statements made in this presentation are being made as of the time and date of its live presentation. If reviewed after its live presentation, this presentation may not contain current or accurate information. We do not assume any obligation to update any forward looking statements we may make. In addition, any information about our roadmap outlines our general product direction and is subject to change at any time without notice. It is for informational purposes only and shall not be incorporated into any contract or other commitment. Splunk undertakes no obligation either to develop the features or functionality described or to include any such feature or functionality in a future release. Splunk, Splunk>, Listen to Your Data, The Engine for Machine Data, Splunk Cloud, Splunk Light and SPL are trademarks and registered trademarks of Splunk Inc. in the United States and other countries. All other brand names, product names, or trademarks belong to their respective owners. 2017 Splunk Inc. All rights reserved.

Agenda Demonstrating Docker for Splunk DevOps Provide a brief overview of Docker and Splunk benefits Why we chose Docker for DevOps Describe and demonstrate the Booz Allen use cases for Docker development

Who we are? Ron Cooper & David Kraemer Booz Allen Hamilton Commercial and Cyber Security

What is Docker? Why do I want to use Docker with Splunk?

What is Docker? Docker is not VM Docker is an Open Source container based technology Docker Separates Applications from Infrastructure using Container Technology, similar to how Virtual Machines separate the Operating System from Bare Metal. Size Startup Integration

Virtual Machine vs. Docker Container How do they compare? Virtual Machine Includes not only the virtualized application, dependent files and an entire guest OS Potential to weigh 10 s of GB Isolated resources and allocations per VM limitations Requires a Hypervisor layer Docker Container Contains just the application and its dependencies Isolated resources and allocation, with much more portability and efficiency Runs as an isolated process in userspace on the host operating system sharing the kernel with other containers

What is Docker? VM vs. Container

Docker Adoption Rate Interesting data points Docker Adoption is up 40% in One Year Docker Hosts Often Run Seven Containers at a Time Containers Churn 9x Faster Than VMs Source: Datadog

2017 SPLUNK INC. Inspiration.conf2016 Docker Be sure to check out for more fundamental Splunk/Docker fundamentals

Why We Choose Docker For DevOps Getting stuff done Easy to deploy purpose built Splunk Environments Quick deployment OS Independent Roll back to standard configurations Easy to contribute and support Have a portable testing environment Improve code quality and sharing

2017 SPLUNK INC. Proof of concept Spin up the environment you need Splunk n box

What is DevOps? Back to Fundamentals

DevOps Definition and Lifecycle DevOps (development and operations) is an enterprise software development phrase used to mean a type of agile relationship between development and IT operations. The goal of DevOps is to change and improve the relationship by advocating better communication and collaboration between these two business units. Source: Webopedia

Splunk Development Environments What does yours look like? No development environment? Single server? Mirror-of-production development environment? Some combination of the above?

Splunk Developer Woes Damnit, not again

2017 SPLUNK INC. Splunk Development Kit w/ Docker Splunk Docker deployment designed for ease of development

2017 SPLUNK INC. Key Takeaways Sparking creativity 1. Demonstrate how we can quickly test, develop and share code for Splunk DevOps utilizing Docker 2. Think of new ways to quickly deploy purpose built Splunk environments 3. Continue to recognize new, unique ways Docker can provide benefit to Splunk Architects and Developers alike

Our Code Reference Material All our links https://github.com/tetchytech/splunk.conf2017 Splunk n Box https://github.com/mhassan2/splunk-n-box Docker Adoption Data https://www.datadoghq.com/docker-adoption/.conf2016 How to Run Splunk as a Docker Image? http://conf.splunk.com/files/2016/slides/how-to-run-splunk-as-a-docker-image.pdf

Q&A Ron Cooper Cyber Security Architect David Kraemer Cyber Security Architect

2017 SPLUNK INC. Thank You Don't forget to rate this session in the.conf2017 mobile app