© 2019 SPLUNK INC.© 2019 SPLUNK INC.
Getting Started with Splunk
Turn Your Data into Answers
© 2019 SPLUNK INC.
During the course of this presentation, we may make forward-looking statements regarding future events or
the expected performance of the company. We caution you that such statements reflect our current
expectations and estimates based on factors currently known to us and that actual events or results could
differ materially. For important factors that may cause actual results to differ from those contained in our
forward-looking statements, please review our filings with the SEC.
The forward-looking statements made in this presentation are being made as of the time and date of its live
presentation. If reviewed after its live presentation, this presentation may not contain current or accurate
information. We do not assume any obligation to update any forward-looking statements we may make. In
addition, any information about our roadmap outlines our general product direction and is subject to change
at any time without notice. It is for informational purposes only and shall not be incorporated into any contract
or other commitment. Splunk undertakes no obligation either to develop the features or functionality
described or to include any such feature or functionality in a future release.
Splunk, Splunk>, Listen to Your Data, The Engine for Machine Data, Splunk Cloud, Splunk Light and SPL are trademarks and registered trademarks of Splunk Inc. in
the United States and other countries. All other brand names, product names, or trademarks belong to their respective owners. © 2019 Splunk Inc. All rights reserved.
Forward-Looking Statements
© 2019 SPLUNK INC.
1. Introduction to the Splunk platform
2. Splunk demo
• Accessing and managing data
• Getting insights
• Taking action
• Intro to Splunk Premium Solutions
• Intro to Splunk A.I. and M.L.
3. Getting started
4. Wrap-up and Q&A
Agenda
© 2019 SPLUNK INC.
This digital evolution is changing everything
There’s an explosion of data beyond anything our world has experienced
3D PRINTING SMART
CITIES
CLOUD
DRONES
MACHINE
LEARNING
SELF-DRIVING EVERYTHING
AUTONOMOUS
EVERYTHING
SMART
PHONES
SMART
APPLIANCES
SMART
BUILDINGS
© 2019 SPLUNK INC.
Machine Data Contains Critical Insights
Order Processing
Twitter
Care IVR
Middleware Error
ORDER, 2019-01-21T14:04:12.484,10098213, 569281734,67.17.10.12,43CD1A7B8322,SA-2100
JAN 21 14:04:12.996 wl-01.acme.com Order 569281734 failed for customer 10098213.
Exception follows: weblogic.jdbc.extensions.ConnectionDeadSQLException:
weblogic.common.resourcepool.ResourceDeadException: Could not create pool connection. The
DBMS driver exception was: [BEA][Oracle JDBC Driver] Error establishing socket to host and port:
ACMEDB-01:1521. Reason: Connection refused
01/21/19 16:33:11.238 [CONNEVENT] Ext 1207130 (0192033): Event 20111, CTI Num:ServID:Type
0:19:9, App 0, ANI T7998#1, DNIS 5555685981, SerID 40489a07-7f6e-4251-801a-
13ae51a6d092, Trunk T451.16
01/21/18 16:33:11:242 [SCREENPOPEVENT] SerID 40489a07-7f6e-4251-801a-13ae51a6d092
CUSTID 10098213
01/21/18 16:37:49.732 [DISCEVENT] SerID 40489a07-7f6e-4251-801a-13ae51a6d092
{actor:{displayName: “Go Cowboys!!”,followersCount:1366,friendsCount:789,link:
http://dallascowboys.com/,location:{displayName:“Dallas, TX”,objectType:“place”},
objectType:“person”,preferredUsername:“Cowb0ysF@n80”,statusesCount:6072},body: “Can’t buy
this device from @ACME. Site doesn’t work! Called, gave up on waiting for them to answer! RT if
you hate @ACME!!”,objectType:“activity”,postedTime:“2019-01-21T16:39:40.647-0600”}
SOURCES
© 2019 SPLUNK INC.
Machine Data Contains Critical Insights
Order Processing
Twitter
Care IVR
Middleware Error
Customer ID Order ID
ORDER, 2019-01-21T14:04:12.484,10098213, 569281734,67.17.10.12,43CD1A7B8322,SA-2100
JAN 21 14:04:12.996 wl-01.acme.com Order 569281734 failed for customer 10098213.
Exception follows: weblogic.jdbc.extensions.ConnectionDeadSQLException:
weblogic.common.resourcepool.ResourceDeadException: Could not create pool connection. The
DBMS driver exception was: [BEA][Oracle JDBC Driver] Error establishing socket to host and port:
ACMEDB-01:1521. Reason: Connection refused
01/21/19 16:33:11.238 [CONNEVENT] Ext 1207130 (0192033): Event 20111, CTI Num:ServID:Type
0:19:9, App 0, ANI T7998#1, DNIS 5555685981, SerID 40489a07-7f6e-4251-801a-
13ae51a6d092, Trunk T451.16
01/21/18 16:33:11:242 [SCREENPOPEVENT] SerID 40489a07-7f6e-4251-801a-13ae51a6d092
CUSTID 10098213
01/21/18 16:37:49.732 [DISCEVENT] SerID 40489a07-7f6e-4251-801a-13ae51a6d092
{actor:{displayName: “Go Cowboys!!”,followersCount:1366,friendsCount:789,link:
http://dallascowboys.com/,location:{displayName:“Dallas, TX”,objectType:“place”},
objectType:“person”,preferredUsername:“Cowb0ysF@n80”,statusesCount:6072},body: “Can’t buy
this device from @ACME. Site doesn’t work! Called, gave up on waiting for them to answer! RT if
you hate @ACME!!”,objectType:“activity”,postedTime:“2019-01-21T16:39:40.647-0600”}
Order ID
Customer’s Twitter ID
Customer ID
Customer ID
Time waiting on hold
Customer’s Tweet
Company’s Twitter ID
Product ID
SOURCES
© 2019 SPLUNK INC.
Machine Data Contains Critical Insights
Order Processing
Twitter
Care IVR
Middleware Error
Customer ID Order ID
ORDER, 2019-01-21T14:04:12.484,10098213, 569281734,67.17.10.12,43CD1A7B8322,SA-2100
JAN 21 14:04:12.996 wl-01.acme.com Order 569281734 failed for customer 10098213.
Exception follows: weblogic.jdbc.extensions.ConnectionDeadSQLException:
weblogic.common.resourcepool.ResourceDeadException: Could not create pool connection. The
DBMS driver exception was: [BEA][Oracle JDBC Driver] Error establishing socket to host and port:
ACMEDB-01:1521. Reason: Connection refused
01/21/19 16:33:11.238 [CONNEVENT] Ext 1207130 (0192033): Event 20111, CTI Num:ServID:Type
0:19:9, App 0, ANI T7998#1, DNIS 5555685981, SerID 40489a07-7f6e-4251-801a-
13ae51a6d092, Trunk T451.16
01/21/18 16:33:11:242 [SCREENPOPEVENT] SerID 40489a07-7f6e-4251-801a-13ae51a6d092
CUSTID 10098213
01/21/18 16:37:49.732 [DISCEVENT] SerID 40489a07-7f6e-4251-801a-13ae51a6d092
{actor:{displayName: “Go Cowboys!!”,followersCount:1366,friendsCount:789,link:
http://dallascowboys.com/,location:{displayName:“Dallas, TX”,objectType:“place”},
objectType:“person”,preferredUsername:“Cowb0ysF@n80”,statusesCount:6072},body: “Can’t buy
this device from @ACME. Site doesn’t work! Called, gave up on waiting for them to answer! RT if
you hate @ACME!!”,objectType:“activity”,postedTime:“2019-01-21T16:39:40.647-0600”}
Order ID
Customer’s Twitter ID
Customer ID
Customer ID
Time waiting on hold
Customer’s Tweet
Company’s Twitter ID
Product ID
SOURCES
© 2019 SPLUNK INC.
Splunk Markets
Developer Platform (REST API, SDKs)
IT
Operations
Application
Delivery
Business
Analytics
Internet of
Things and
Industrial
Data
Security,
Compliance
and Fraud
Platform for Operational Intelligence
© 2019 SPLUNK INC.
Any Question, Any Data, In Real Time.
Open
Ecosystem
Hybrid Artificial
Intelligence
Single
Platform,
Many
Lenses
Performance at
Scale
© 2019 SPLUNK INC.
DEMO: Let’s Dive In
© 2019 SPLUNK INC.
Service
Excellence
Nimble, Tested &
Secure
Maximizes value
from limited
resources
The benefits of Splunk as a service
© 2019 SPLUNK INC.
Splunk Cloud
Service excellence.
Always available
► Splunk Cloud offers a 100% uptime SLA. If we miss it,
you get money back
► Splunk Cloud is fully redundant with three copies of data
in three geographically dispersed locations
Administered by the Splunk experts
► Allow us to relieve your team of the administration and
overhead responsibilities required to run Splunk
Designed to run in an emergency.
► You need your monitoring tools most during cyber incidents. Having
Splunk Cloud running securely outside of your network ensures whatever
might be impacting your systems is not deterring your ability to identify
and implement a solution
© 2019 SPLUNK INC.
Splunk Cloud
Nimble, tested and secure architecture.
Nimble architecture
► Scale up or scale down based on your organization’s evolving
requirements and needs
► Splunk Cloud is architected to facilitate bursts in data volume without any
changes
Eliminates upgrade delays and challenges
► Upgrades and updates are handled for you; you always have the best and
latest Splunk functionality
Secure administration with zero rogue changes
► Splunk Cloud enhancements are made with a continuous integration (CI)
and continuous delivery (CD) process ensuring proper testing and
validation prior to roll-out
► All changes are peer-reviewed and have built-in roll-back
► Out-of-band changes are not permitted
© 2019 SPLUNK INC.
Splunk Cloud
Maximizes value of your limited resources.
Eliminate infrastructure
► Splunk Cloud is a service; no need to provision infrastructure to run it
Fast time-to-value
► Start getting value out of your Splunk purchase on day one. No need to
deal with multiple internal infrastructure and networking teams to get
started
Unlock the value of the full Splunk platform
► Your team can spend more time helping others learn how to turn data into
value
► You never have to worry about a family emergency, vacation, or
unexpected health issue (or sudden burst of wealth) that removes Splunk
expertise from your operations
© 2019 SPLUNK INC.
Get Started
Experience the power of Splunk Cloud
© 2019 SPLUNK INC.
1. Fastest way to get up and running with
Splunk
2. Adopt before you buy: You select the
data; Splunk sets up the service
3. Like what you see? This becomes your
production environment instantly, with
zero lag in set-up
Autobahn
Proof of Value
Program
© 2019 SPLUNK INC.
1. Reach out to the Splunk team today to
explore getting started with Splunk.
2. Action TBD
3. Action TBD
Taking the
next steps
with Splunk
© 2019 SPLUNK INC.
4 Days of Innovation 350 Education Sessions 20 Hours of Networking
“Hands down the most beneficial and attendee focused conference
I have attended!”
– Michael Mills, Senior Consultant, Booz Allen Hamilton
sign up for notifications @ conf.splunk.com
.conf19
October 21-24, 2019
Splunk University
October 19-21, 2019
Las Vegas, NV
The Venetian Sands Expo
© 2019 SPLUNK INC.© 2019 SPLUNK INC.
Thank You.
Don’t forget to rate this
session on the SplunkLIve!
mobile app

Turning Data Into Business Outcomes with the Splunk Platform

  • 1.
    © 2019 SPLUNKINC.© 2019 SPLUNK INC. Getting Started with Splunk Turn Your Data into Answers
  • 2.
    © 2019 SPLUNKINC. During the course of this presentation, we may make forward-looking statements regarding future events or the expected performance of the company. We caution you that such statements reflect our current expectations and estimates based on factors currently known to us and that actual events or results could differ materially. For important factors that may cause actual results to differ from those contained in our forward-looking statements, please review our filings with the SEC. The forward-looking statements made in this presentation are being made as of the time and date of its live presentation. If reviewed after its live presentation, this presentation may not contain current or accurate information. We do not assume any obligation to update any forward-looking statements we may make. In addition, any information about our roadmap outlines our general product direction and is subject to change at any time without notice. It is for informational purposes only and shall not be incorporated into any contract or other commitment. Splunk undertakes no obligation either to develop the features or functionality described or to include any such feature or functionality in a future release. Splunk, Splunk>, Listen to Your Data, The Engine for Machine Data, Splunk Cloud, Splunk Light and SPL are trademarks and registered trademarks of Splunk Inc. in the United States and other countries. All other brand names, product names, or trademarks belong to their respective owners. © 2019 Splunk Inc. All rights reserved. Forward-Looking Statements
  • 3.
    © 2019 SPLUNKINC. 1. Introduction to the Splunk platform 2. Splunk demo • Accessing and managing data • Getting insights • Taking action • Intro to Splunk Premium Solutions • Intro to Splunk A.I. and M.L. 3. Getting started 4. Wrap-up and Q&A Agenda
  • 4.
    © 2019 SPLUNKINC. This digital evolution is changing everything There’s an explosion of data beyond anything our world has experienced 3D PRINTING SMART CITIES CLOUD DRONES MACHINE LEARNING SELF-DRIVING EVERYTHING AUTONOMOUS EVERYTHING SMART PHONES SMART APPLIANCES SMART BUILDINGS
  • 5.
    © 2019 SPLUNKINC. Machine Data Contains Critical Insights Order Processing Twitter Care IVR Middleware Error ORDER, 2019-01-21T14:04:12.484,10098213, 569281734,67.17.10.12,43CD1A7B8322,SA-2100 JAN 21 14:04:12.996 wl-01.acme.com Order 569281734 failed for customer 10098213. Exception follows: weblogic.jdbc.extensions.ConnectionDeadSQLException: weblogic.common.resourcepool.ResourceDeadException: Could not create pool connection. The DBMS driver exception was: [BEA][Oracle JDBC Driver] Error establishing socket to host and port: ACMEDB-01:1521. Reason: Connection refused 01/21/19 16:33:11.238 [CONNEVENT] Ext 1207130 (0192033): Event 20111, CTI Num:ServID:Type 0:19:9, App 0, ANI T7998#1, DNIS 5555685981, SerID 40489a07-7f6e-4251-801a- 13ae51a6d092, Trunk T451.16 01/21/18 16:33:11:242 [SCREENPOPEVENT] SerID 40489a07-7f6e-4251-801a-13ae51a6d092 CUSTID 10098213 01/21/18 16:37:49.732 [DISCEVENT] SerID 40489a07-7f6e-4251-801a-13ae51a6d092 {actor:{displayName: “Go Cowboys!!”,followersCount:1366,friendsCount:789,link: http://dallascowboys.com/,location:{displayName:“Dallas, TX”,objectType:“place”}, objectType:“person”,preferredUsername:“Cowb0ysF@n80”,statusesCount:6072},body: “Can’t buy this device from @ACME. Site doesn’t work! Called, gave up on waiting for them to answer! RT if you hate @ACME!!”,objectType:“activity”,postedTime:“2019-01-21T16:39:40.647-0600”} SOURCES
  • 6.
    © 2019 SPLUNKINC. Machine Data Contains Critical Insights Order Processing Twitter Care IVR Middleware Error Customer ID Order ID ORDER, 2019-01-21T14:04:12.484,10098213, 569281734,67.17.10.12,43CD1A7B8322,SA-2100 JAN 21 14:04:12.996 wl-01.acme.com Order 569281734 failed for customer 10098213. Exception follows: weblogic.jdbc.extensions.ConnectionDeadSQLException: weblogic.common.resourcepool.ResourceDeadException: Could not create pool connection. The DBMS driver exception was: [BEA][Oracle JDBC Driver] Error establishing socket to host and port: ACMEDB-01:1521. Reason: Connection refused 01/21/19 16:33:11.238 [CONNEVENT] Ext 1207130 (0192033): Event 20111, CTI Num:ServID:Type 0:19:9, App 0, ANI T7998#1, DNIS 5555685981, SerID 40489a07-7f6e-4251-801a- 13ae51a6d092, Trunk T451.16 01/21/18 16:33:11:242 [SCREENPOPEVENT] SerID 40489a07-7f6e-4251-801a-13ae51a6d092 CUSTID 10098213 01/21/18 16:37:49.732 [DISCEVENT] SerID 40489a07-7f6e-4251-801a-13ae51a6d092 {actor:{displayName: “Go Cowboys!!”,followersCount:1366,friendsCount:789,link: http://dallascowboys.com/,location:{displayName:“Dallas, TX”,objectType:“place”}, objectType:“person”,preferredUsername:“Cowb0ysF@n80”,statusesCount:6072},body: “Can’t buy this device from @ACME. Site doesn’t work! Called, gave up on waiting for them to answer! RT if you hate @ACME!!”,objectType:“activity”,postedTime:“2019-01-21T16:39:40.647-0600”} Order ID Customer’s Twitter ID Customer ID Customer ID Time waiting on hold Customer’s Tweet Company’s Twitter ID Product ID SOURCES
  • 7.
    © 2019 SPLUNKINC. Machine Data Contains Critical Insights Order Processing Twitter Care IVR Middleware Error Customer ID Order ID ORDER, 2019-01-21T14:04:12.484,10098213, 569281734,67.17.10.12,43CD1A7B8322,SA-2100 JAN 21 14:04:12.996 wl-01.acme.com Order 569281734 failed for customer 10098213. Exception follows: weblogic.jdbc.extensions.ConnectionDeadSQLException: weblogic.common.resourcepool.ResourceDeadException: Could not create pool connection. The DBMS driver exception was: [BEA][Oracle JDBC Driver] Error establishing socket to host and port: ACMEDB-01:1521. Reason: Connection refused 01/21/19 16:33:11.238 [CONNEVENT] Ext 1207130 (0192033): Event 20111, CTI Num:ServID:Type 0:19:9, App 0, ANI T7998#1, DNIS 5555685981, SerID 40489a07-7f6e-4251-801a- 13ae51a6d092, Trunk T451.16 01/21/18 16:33:11:242 [SCREENPOPEVENT] SerID 40489a07-7f6e-4251-801a-13ae51a6d092 CUSTID 10098213 01/21/18 16:37:49.732 [DISCEVENT] SerID 40489a07-7f6e-4251-801a-13ae51a6d092 {actor:{displayName: “Go Cowboys!!”,followersCount:1366,friendsCount:789,link: http://dallascowboys.com/,location:{displayName:“Dallas, TX”,objectType:“place”}, objectType:“person”,preferredUsername:“Cowb0ysF@n80”,statusesCount:6072},body: “Can’t buy this device from @ACME. Site doesn’t work! Called, gave up on waiting for them to answer! RT if you hate @ACME!!”,objectType:“activity”,postedTime:“2019-01-21T16:39:40.647-0600”} Order ID Customer’s Twitter ID Customer ID Customer ID Time waiting on hold Customer’s Tweet Company’s Twitter ID Product ID SOURCES
  • 8.
    © 2019 SPLUNKINC. Splunk Markets Developer Platform (REST API, SDKs) IT Operations Application Delivery Business Analytics Internet of Things and Industrial Data Security, Compliance and Fraud Platform for Operational Intelligence
  • 9.
    © 2019 SPLUNKINC. Any Question, Any Data, In Real Time. Open Ecosystem Hybrid Artificial Intelligence Single Platform, Many Lenses Performance at Scale
  • 10.
    © 2019 SPLUNKINC. DEMO: Let’s Dive In
  • 11.
    © 2019 SPLUNKINC. Service Excellence Nimble, Tested & Secure Maximizes value from limited resources The benefits of Splunk as a service
  • 12.
    © 2019 SPLUNKINC. Splunk Cloud Service excellence. Always available ► Splunk Cloud offers a 100% uptime SLA. If we miss it, you get money back ► Splunk Cloud is fully redundant with three copies of data in three geographically dispersed locations Administered by the Splunk experts ► Allow us to relieve your team of the administration and overhead responsibilities required to run Splunk Designed to run in an emergency. ► You need your monitoring tools most during cyber incidents. Having Splunk Cloud running securely outside of your network ensures whatever might be impacting your systems is not deterring your ability to identify and implement a solution
  • 13.
    © 2019 SPLUNKINC. Splunk Cloud Nimble, tested and secure architecture. Nimble architecture ► Scale up or scale down based on your organization’s evolving requirements and needs ► Splunk Cloud is architected to facilitate bursts in data volume without any changes Eliminates upgrade delays and challenges ► Upgrades and updates are handled for you; you always have the best and latest Splunk functionality Secure administration with zero rogue changes ► Splunk Cloud enhancements are made with a continuous integration (CI) and continuous delivery (CD) process ensuring proper testing and validation prior to roll-out ► All changes are peer-reviewed and have built-in roll-back ► Out-of-band changes are not permitted
  • 14.
    © 2019 SPLUNKINC. Splunk Cloud Maximizes value of your limited resources. Eliminate infrastructure ► Splunk Cloud is a service; no need to provision infrastructure to run it Fast time-to-value ► Start getting value out of your Splunk purchase on day one. No need to deal with multiple internal infrastructure and networking teams to get started Unlock the value of the full Splunk platform ► Your team can spend more time helping others learn how to turn data into value ► You never have to worry about a family emergency, vacation, or unexpected health issue (or sudden burst of wealth) that removes Splunk expertise from your operations
  • 15.
    © 2019 SPLUNKINC. Get Started Experience the power of Splunk Cloud
  • 16.
    © 2019 SPLUNKINC. 1. Fastest way to get up and running with Splunk 2. Adopt before you buy: You select the data; Splunk sets up the service 3. Like what you see? This becomes your production environment instantly, with zero lag in set-up Autobahn Proof of Value Program
  • 17.
    © 2019 SPLUNKINC. 1. Reach out to the Splunk team today to explore getting started with Splunk. 2. Action TBD 3. Action TBD Taking the next steps with Splunk
  • 18.
    © 2019 SPLUNKINC. 4 Days of Innovation 350 Education Sessions 20 Hours of Networking “Hands down the most beneficial and attendee focused conference I have attended!” – Michael Mills, Senior Consultant, Booz Allen Hamilton sign up for notifications @ conf.splunk.com .conf19 October 21-24, 2019 Splunk University October 19-21, 2019 Las Vegas, NV The Venetian Sands Expo
  • 19.
    © 2019 SPLUNKINC.© 2019 SPLUNK INC. Thank You. Don’t forget to rate this session on the SplunkLIve! mobile app