Splunk @ Amazon Startup - Austin, TX - 9/11/2008

43

description

Michael Wilde, Splunk Ninja, gives an overview of Splunk, and discusses ways in which Splunk has solved some of its challenges using Amazon\'s EC2 / S3 Web Service to accomplish business goals

Transcript of Splunk @ Amazon Startup - Austin, TX - 9/11/2008

Page 1: Splunk @ Amazon Startup - Austin, TX - 9/11/2008
Page 2: Splunk @ Amazon Startup - Austin, TX - 9/11/2008

The IT Search CompanyMichael Wilde, Director, SplunkPowered Associates

ninja

Page 3: Splunk @ Amazon Startup - Austin, TX - 9/11/2008

Imagine using the Internet without a search engine

The IT Search Company

Page 4: Splunk @ Amazon Startup - Austin, TX - 9/11/2008

The IT Search Company

Now imagine trying to find information buried in terabytes of data inside your data center

Page 5: Splunk @ Amazon Startup - Austin, TX - 9/11/2008

The IT Search Company

Splunk lets you search your entire IT infrastructure from one place in real time

Page 6: Splunk @ Amazon Startup - Austin, TX - 9/11/2008

The IT Search Company

Why Search?

Page 7: Splunk @ Amazon Startup - Austin, TX - 9/11/2008

The IT Search Company

Our IT infrastructures are too complex, dynamic, service oriented, virtualized and

mission critical. Existing management approaches haven’t kept up.

Page 8: Splunk @ Amazon Startup - Austin, TX - 9/11/2008

The IT Search Company

Search is scalable, versatile and keeps up with change. It turns

the data you already have into actionable information.

Page 9: Splunk @ Amazon Startup - Austin, TX - 9/11/2008

The IT Search Company

>Last 60 minutes

Search your IT infrastructure

Page 10: Splunk @ Amazon Startup - Austin, TX - 9/11/2008

OperationsTroubleshoot problems

The IT Search Company

>J2EE exception Last 60 minutes

Search your IT infrastructure

Page 11: Splunk @ Amazon Startup - Austin, TX - 9/11/2008

OperationsTroubleshoot problems

SecurityInvestigate attacks

The IT Search Company

>

Search your IT infrastructure

Last 24 hours

fail* password sshd

Page 12: Splunk @ Amazon Startup - Austin, TX - 9/11/2008

OperationsTroubleshoot problems

SecurityInvestigate attacks

ComplianceReporting and Controls

The IT Search Company

>

Search your IT infrastructure

file modify | chart by sourceLast 7 days

Page 13: Splunk @ Amazon Startup - Austin, TX - 9/11/2008

OperationsTroubleshoot problems

SecurityInvestigate attacks

ComplianceReporting and Controls

Business IntelligenceAnalyze transactions

The IT Search Company

>

Search your IT infrastructure

transaction fields=useridLast 7 days

Page 14: Splunk @ Amazon Startup - Austin, TX - 9/11/2008

OperationsTroubleshoot problems

SecurityInvestigate attacks

ComplianceReporting and Controls

Business IntelligenceAnalyze transactions

The IT Search Company

>

Search your IT infrastructure

transaction fields=useridLast 7 days

Page 15: Splunk @ Amazon Startup - Austin, TX - 9/11/2008

• Time search with interactive results

• Keyword search with quoted strings, wild cards, booleans and nesting

• Targeted field search

- Host, sources, events

- Custom fields

• Summary and statistical search

• Transaction search

• Right click integration with other applications

The IT Search Company

Search

Page 16: Splunk @ Amazon Startup - Austin, TX - 9/11/2008

• Save any search and run it on a schedule to create an alert

• Alerts can trigger notifications and/or actions based on the search results

• Notifications can be sent via email, SMS, RSS or SNMP and integrated with other management consoles

• Actions can trigger scripts to perform activities like restarting a server

The IT Search Company

Alert

Page 17: Splunk @ Amazon Startup - Austin, TX - 9/11/2008

The IT Search Company

Report• One click reports from search results

• Any field can be used to plot series

• Flexible chart outputs and formats

• Interactive charts provide one click drill down

• Select multiple fields to plot several series together

Page 18: Splunk @ Amazon Startup - Austin, TX - 9/11/2008

• Save knowledge to share with other users and groups- Searches- Alerts- Reports- Dashboards- Types, Tags, Actions

• Package knowledge as an application and share with other installations

The IT Search Company

Share

Page 19: Splunk @ Amazon Startup - Austin, TX - 9/11/2008

The IT Search Company

Visualize• Connect visualization apps to the

Splunk API

• Feed business intelligence and reporting applications with IT data using the Splunk API

• Create dynamic visualizations of data with using one of the Splunk SDKs- Flash- Python- C, C++- Java- .Net

Page 20: Splunk @ Amazon Startup - Austin, TX - 9/11/2008
Page 21: Splunk @ Amazon Startup - Austin, TX - 9/11/2008

Challenges solved with cloud computing

Page 22: Splunk @ Amazon Startup - Austin, TX - 9/11/2008

The IT Search Company

Running a Developers Camp

• First Splunk Developers Camp (August 4, 2008)

• 65 onsite, 298 watching live via Splunk.TV

• Give dev’s a place to work they can self administer, but how?

Page 23: Splunk @ Amazon Startup - Austin, TX - 9/11/2008

The IT Search Company

DevCamp - the Fabulatr

• Users don’t need AWS accounts

• Easy starting/stopping of EC2 instances

• Emails the instructions & SSH key

• Free, Open SourceKord Campbell, Chief Evangelist

Page 24: Splunk @ Amazon Startup - Austin, TX - 9/11/2008

The IT Search Company

DevCamp - the Fabulatr

• Users don’t need AWS accounts

• Easy starting/stopping of EC2 instances

• Emails the instructions & SSH key

• Free, Open SourceKord Campbell, Chief Evangelist

Page 26: Splunk @ Amazon Startup - Austin, TX - 9/11/2008

The IT Search Company

Sales Engineering

Page 27: Splunk @ Amazon Startup - Austin, TX - 9/11/2008

The IT Search Company

Sales Engineering

Page 28: Splunk @ Amazon Startup - Austin, TX - 9/11/2008

The IT Search Company

Sales Engineering

• Proofs of Concept (customer testing)

• Joint work with support

• A place to play

• Splunk Live Demos

Page 29: Splunk @ Amazon Startup - Austin, TX - 9/11/2008

The IT Search Company

Sales Engineering

• Proofs of Concept (customer testing)

• Joint work with support

• A place to play

• Splunk Live Demos

Page 30: Splunk @ Amazon Startup - Austin, TX - 9/11/2008

The IT Search Company

Sales Engineering

• Proofs of Concept (customer testing)

• Joint work with support

• A place to play

• Splunk Live Demos

Page 31: Splunk @ Amazon Startup - Austin, TX - 9/11/2008

The IT Search Company

Splunk Loves

Page 32: Splunk @ Amazon Startup - Austin, TX - 9/11/2008

The IT Search Company

Splunk Loves

•EC2 - running instances

Page 33: Splunk @ Amazon Startup - Austin, TX - 9/11/2008

The IT Search Company

Splunk Loves

•EC2 - running instances

•S3 - storing images

Page 34: Splunk @ Amazon Startup - Austin, TX - 9/11/2008

The IT Search Company

Splunk Loves

•EC2 - running instances

•S3 - storing images

•EBS - wicked laaarge disk storage & snapshotting

Page 35: Splunk @ Amazon Startup - Austin, TX - 9/11/2008

The IT Search Company

Splunk Loves

•EC2 - running instances

•S3 - storing images

•EBS - wicked laaarge disk storage & snapshotting

• Rightscale

Page 36: Splunk @ Amazon Startup - Austin, TX - 9/11/2008

The IT Search Company

Splunk Loves

•EC2 - running instances

•S3 - storing images

•EBS - wicked laaarge disk storage & snapshotting

• Rightscale

• Rightscale

Page 37: Splunk @ Amazon Startup - Austin, TX - 9/11/2008

The IT Search Company

Splunk Loves

•EC2 - running instances

•S3 - storing images

•EBS - wicked laaarge disk storage & snapshotting

• Rightscale

• Rightscale

•Rightscale

Page 38: Splunk @ Amazon Startup - Austin, TX - 9/11/2008

The IT Search Company

Page 39: Splunk @ Amazon Startup - Austin, TX - 9/11/2008

The IT Search Company

Page 40: Splunk @ Amazon Startup - Austin, TX - 9/11/2008

The IT Search Company

Page 41: Splunk @ Amazon Startup - Austin, TX - 9/11/2008

The IT Search Company

powered

Page 42: Splunk @ Amazon Startup - Austin, TX - 9/11/2008

The IT Search Company

Resources for You

download.splunk.com

rightscale.com

EC2 Fabulatr code.google.com/p/fabulatr

Page 43: Splunk @ Amazon Startup - Austin, TX - 9/11/2008

The IT Search Company

Questions