Copyright	©	2016	Splunk	Inc.
Splunk	101
2
Our	Plan	of	Action
1.Machine	Data/Big	Data	- setting	the	stage
2.How	does	Splunk	fit	in	the	landscape
3.What	differentiates Splunk
4.Components	that	make	up	Splunk
5.Demo	- How	it	works
3
What	is	machine	data?
Challenges: Volume | Velocity | Variety | Variability
GPS,
RFID,
Hypervisor,
Web	Servers,
Email,	Messaging,
Clickstreams,	Mobile,	
Telephony,	IVR,	Databases,
Sensors,	Telematics,	Storage,
Servers,	Security	Devices,	Desktops	
3
Splunk’s	Mission:
Making machine	data	accessible,
usable	and	valuable	to	everyone.
4
What	Does	Machine	Data	Look	Like?
Sources
Order	Processing
Twitter
Care	IVR
Middleware	
Error
5
Machine	Data	Contains	Critical	Insights
Customer	ID Order	ID
Customer’s	Tweet	
Time	Waiting	On	Hold
Twitter	ID
Product	ID
Company’s	Twitter	ID
Customer	ID
Order	ID
Customer	ID
Sources
Order	Processing
Twitter
Care	IVR
Middleware	
Error
6
Splunk	Unlocks	Critical	Insights
Order	ID
Customer’s	Tweet	
Time	Waiting	On	Hold
Product	ID
Company’s	Twitter	ID
Order	ID
Customer	ID
Twitter	ID
Customer	ID
Customer	ID
Sources
Order	Processing
Twitter
Care	IVR
Middleware	
Error
7
THE	Industry	Leading	Platform	For	Machine	Data
Machine	Data:	Any	Location,	Type,	Volume
Online	
Services Web	
Services
Servers
Security GPS	
Location
Storage
Desktops
Networks
Packaged	
Applications
Custom
ApplicationsMessaging
Telecoms
Online	
Shopping	
Cart
Web	
Clickstreams
Databases
Energy	
Meters
Call	Detail	
Records
Smartphones	
and	Devices
RFID
On-
Premises
Private	
Cloud
Public	
Cloud
Platform	Support	(Apps	/	API	/	SDKs)
Enterprise	Scalability
Universal	Indexing
Answer	Any	Question
Developer
Platform
Report	
and	
analyze
Custom	
dashboards
Monitor	
and	alert
Ad	hoc	
search
No	backend	database
Schema-on-the-fly
No	need	to	filter	data
Quick	time	to	value
Agile	reporting	and	analytics
Real-time	architecture
8
VMware
Platform	for	Machine	Data
Splunk	Solutions	>	Easy	to	Adopt
Exchange PCISecurity
Across	Data	Sources,	Use	Cases	&	Consumption	Models
IT	Svc	Int
Splunk	Premium	Solutions Rich	Ecosystem	of	Apps
ITSI UBA
UBA
Mainframe
Data
Relational
Databases
MobileForwarders Syslog/TCP IoT
Devices
Network
Wire	Data
Hadoop	
&	NoSQL
Installing	&	Using	Splunk	
(Live	Demonstration	&	Walkthrough)
10
1.
2.
3.
4.
Getting	Started
Download
Install	&	Start
Forward	Data
Search
Databases
Networks
Servers
Virtual	
Machines
Smart	
phones	
and	
Devices
Custom
Applications
Security
WebServer
Sensors
Four	steps:
11
1. Download	Splunk Enterprise	-
http://www.splunk.com/en_us/download/splunk-enterprise.html
– Or	Google	“splunk download”	->	Download	Splunk Enterprise	for	Free
2. Download	Tutorial	Data	– http://www.splunkbook.com ,	3rd link	under	
“Related	Links”	OR	
http://docs.splunk.com/images/Tutorial/tutorialdata.zip
Downloading	Splunk Enterprise	+	Tutorial	Data
Copyright	©	2015	Splunk	Inc.
Copyright	©	2015	Splunk	Inc.
Copyright	©	2015	Splunk	Inc.
Copyright	©	2015	Splunk	Inc.
Copyright	©	2015	Splunk	Inc.
17
Searches	used
fail*
buttercupgames
buttercupgames status>200
buttercupgames |	stats	count	by	status
buttercupgames status=404	|	stats	count,	sparkline by	uri_path
buttercupgames status>200	|	timechart count	by	uri_path
buttercupgames status>200	|	iplocation clientip |	geostats count
18
Dashboard
Deployments	&	Architecture
20
Single	Instance	or	Distributed?
Single	environment Distributed	Environment
Recommended	Specs:
12	CPU	Cores/12GB	RAM/800+	IOPs
A	Splunk	install	can	be	one	or	all	roles…
21
Scales	to	Hundreds	of	TBs/Day
Enterprise-class	Scale,	Resilience	and	Interoperability
Collect	machine	data	from	thousands	sources	via	Splunk	forwarders		
Compress	and	store	data	on	Splunk	Indexers
Initiate	searches	and	visualize	results	via	Search	Heads
Forwarders
Indexer
Search Head
22
Over	1100	Apps	@	http://splunkbase.splunk.com
2
23
Education	Resources
23
Splunk	Education
• www.splunk.com/education
Using	Splunk,	Searching	and	Reporting,	Developing	Apps,	
Administering	Splunk,	and	more!
Books
• Implementing	Splunk:	Big	Data	Essentials	for	Operational	Intelligence
• Splunk	Essentials
• Exploring	Splunk
• Splunk	Operational	Intelligence	Cookbook
24
Supplemental	Information
24
Download
• www.splunk.com/download
Search	Tutorial:
• docs.splunk.com/Documentation/Splunk/latest/SearchTutorial
Tutorial	Data:
• docs.splunk.com/images/Tutorial/tutorialdata.zip
25
Time	to	start	SPLUNKING!!!
1. Splunk	is	Free	– Download	and	get	started	today
2. Quick	Time	to	Value
3. Data	Gold	Mines	– what	informational	fortune	awaits?!
4. Leverage	the	Splunk	Community
• splunkbase.com
• answers.splunk.com
• blogs.splunk.com
Happy	Splunking!
Copyright	©	2016	Splunk	Inc.
Thank	You

Splunk 101