Top Banner
Copyright © 2015, Splunk Inc. Splunk for IT Opera>ons and IT Service Intelligence 14. April 2016 Moscow Philipp Drieger Sales Engineer DACH & EE EMEA Central SME IoT & ML
43

Splunk for IT Operations and IT Service Intelligence

Jan 26, 2017

Download

Data & Analytics

CleverDATA
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: Splunk for IT Operations and IT Service Intelligence

Copyright©2015,SplunkInc.

SplunkforITOpera>onsandITServiceIntelligence14.April2016Moscow

PhilippDriegerSalesEngineerDACH&EEEMEACentralSMEIoT&ML

Page 2: Splunk for IT Operations and IT Service Intelligence

Copyright©2015,SplunkInc.

Agenda

•  SplunkOverview•  SplunkforITOpera>ons•  ExtendandAcceleratewithApps•  SplunkITServiceIntelligence(ITSI)•  SplunkforBusinessAnaly>cs

Page 3: Splunk for IT Operations and IT Service Intelligence

Copyright©2015,SplunkInc.

SplunkOverview

Page 4: Splunk for IT Operations and IT Service Intelligence

Copyright©2015,SplunkInc.Copyright©2015SplunkInc.

BigDataComesfromMachinesVolume | Velocity | Variety | Variability

GPS,RFID,

Hypervisor,WebServers,

Email,MessagingClickstreams,Mobile,

Telephony,IVR,Databases,Sensors,TelemaEcs,Storage,

Servers,SecurityDevices,Desktops4

Page 5: Splunk for IT Operations and IT Service Intelligence

Copyright©2015,SplunkInc.Copyright©2015SplunkInc.

TurnMachineDataintoOpera>onalIntelligenceINDEXANYMACHINEDATA:ANYSOURCE,TYPE,VOLUME

OnlineServices Web

Services

ServersSecurity GPS

Loca>on

StorageDesktops

Networks

PackagedApplica>ons

CustomApplica>onsMessaging

TelecomsOnline

ShoppingCart

WebClickstreams

Databases

EnergyMeters

CallDetailRecords

SmartphonesandDevices

RFID

On-Premises

PrivateCloud

PublicCloud

GAINREAL-TIMEVISIBILITY

ApplicaEonDelivery

SecurityandCompliance

InfrastructureMonitoring

BusinessAnalyEcs

InternetofThings

5

Page 6: Splunk for IT Operations and IT Service Intelligence

Copyright©2015,SplunkInc.

SplunkforITOpera>ons

Page 7: Splunk for IT Operations and IT Service Intelligence

Copyright©2015,SplunkInc.

CIOObstacle:Escala>ngITComplexity

SERVERS STORAGE NETWORKING

VIRTUALIZATION

INFRASTRUCTUREAPPLICATIONS

PACKAGEDAPPLICATIONS

CUSTOMAPPLICATIONS

Iden>ty

VPN

IPPhone

HR

Email

Finance

AppSvr

DB

WebSvr SaaS/PaaS

IaaS

Page 8: Splunk for IT Operations and IT Service Intelligence

Copyright©2015,SplunkInc.

CIOObstacle:Escala>ngITComplexity

SERVERS STORAGE NETWORKING

VITUALIZATION

INFRASTRUCTUREAPPLICATIONS

PACKAGEDAPPLICATIONS

CUSTOMAPPLICATIONS

Iden>ty

VPN

IPPhone

HR

Email

Finance

AppSvr

DB

WebSvr SaaS/PaaS

IaaS

Complex,silo-basedtechnologies

Disconnectedandoutdatedpointsolu>ons

Over70%of>mespentonmaintaining,notinnova>ng

Page 9: Splunk for IT Operations and IT Service Intelligence

Copyright©2015,SplunkInc.

Before Splunk

Data Gathering

DBApp NW

Storage

Now What?

….War Room

Outage Occurs

Human latency measured in hours or days

Не удается отобразить рисунок. Возможно, рисунок поврежден или недостаточно памяти для его открытия. Перезагрузите компьютер, а затем снова откройте файл. Если вместо рисунка все еще отображается красный крестик, попробуйте удалить рисунок и вставить его заново.

Page 10: Splunk for IT Operations and IT Service Intelligence

Copyright©2015,SplunkInc.

From Days to Minutes With Splunk

“First Responder”

2012-12-05 07:04:44 Id=Rd910EAJ City=New York [email protected] product_id=product_i BD-

66.57.19.112 ..[05/Dec/2012 07:05:22:152]”GET /card.do?action=addtocart &itemid=K9

[1208/12 02:39:03:209 UTC] 000000c6 ConnectionEve A J2CA00561: ConnectionExeception:[IBM][CLI Driver] SQL1224N

Report and analyze

Custom dashboards

Monitor and alert

Ad hoc search

2012-12-05 07:04:44 Id=Rd910EAJ City=New York [email protected]

product_id=product_i BD-

66.57.19.112 ..[05/Dec/2012 07:05:22:152]”GET /card.do?

action=addtocart &itemid=K9

[1208/12 02:39:03:209 UTC] 000000c6 ConnectionEve A

J2CA00561: ConnectionExeception:

[IBM][CLI Driver] SQL1224N

Outage Occurs

Page 11: Splunk for IT Operations and IT Service Intelligence

Copyright©2015,SplunkInc.

“Splunkreducedourescala>onsby90%andourproblemresolu>on>meby67%.

“EscalaEonsreducedby90%andMTTRdroppedby67%”

SplunkatServiceDesk:Vodafone

PauloCarvalhoDirectorOpera>ons

Theoldway:DisparateITsilosimpactCustomerService• Manuallyintensive,error-proneprocessesresultinconstantescala>onsandlongdelays

•  Expensive,home-growntoolsforlogcollec>onandanalysisdon’tprovidethecompletepicture•  Disconnectedsystemscreatetroubleinmee>ngsecurityandcompliancemandates

Thenewway:Providecomprehensivevisibilityandcontrol✓  AsingleTier1supportpersoncannowperformitera>vesearchesacrossalltheirITdatato

inves>gate,iden>fy,andfixtheproblem–escala>onsreducedby90percent

✓  Splunkconsolidateslogsfromdisparatesystemsintoasingleview,providingvisibilityacrossend-to-endservicedeliveryfromoneplace->metoproblemresolu>ondroppedby67%

✓  Role-basedsecureaccesstologsviaSplunkensuresSOXcompliance

✓  MonitorITdataandfindissuesbeforetheybecomevisibletocustomers

Page 12: Splunk for IT Operations and IT Service Intelligence

Copyright©2015,SplunkInc.

Splunk:TheBeherApproachForIT

12

CustomerFacingData

OutsidetheDatacenter

ApplicaEons  Weblogs  Log4J,JMS,JMX  .NETevents  Codeandscripts

Networking  Configura>ons  syslog  SNMP  nejlow

Databases  Configura>ons  Audit/querylogs  Tables  Schemas

VirtualizaEon&Cloud  Hypervisor  GuestOS,Apps  Cloud

Linux/Unix  Configura>ons  syslog  Filesystemps,iostat,top

Windows  Registry  Eventlogs  Filesystemsysinternals

Logfiles Configs Messages TrapsAlerts

Metrics Scripts TicketsChanges

  Click-streamdata  Shoppingcartdata  Onlinetransac>ondata

  Manufacturing,logis>cs…  CDRs&IPDRs  Powerconsump>on  RFIDdata  GPSdata

Powerful,end-to-end,real->meplajormforMachineData

Page 13: Splunk for IT Operations and IT Service Intelligence

Copyright©2015,SplunkInc.

Splunk:TheBeherApproachForIT

13

CustomerFacingData

OutsidetheDatacenter

ApplicaEons  Weblogs  Log4J,JMS,JMX  .NETevents  Codeandscripts

Networking  Configura>ons  syslog  SNMP  nejlow

Databases  Configura>ons  Audit/querylogs  Tables  Schemas

VirtualizaEon&Cloud  Hypervisor  GuestOS,Apps  Cloud

Linux/Unix  Configura>ons  syslog  Filesystem  ps,iostat,top

Windows  Registry  Eventlogs  Filesystemsysinternals

Logfiles Configs Messages TrapsAlerts

Metrics Scripts TicketsChanges

  Click-streamdata  Shoppingcartdata  Onlinetransac>ondata

  Manufacturing,logis>cs…  CDRs&IPDRs  Powerconsump>on  RFIDdata  GPSdata

Powerful,end-to-end,real->meplajormforMachineData

NoupfrontschemaNocustomconnectorsNoRDBMS

• Anyamount,anyloca>on,anysource.

Page 14: Splunk for IT Operations and IT Service Intelligence

Copyright©2015,SplunkInc.

ExtendandAcceleratewithApps

Page 15: Splunk for IT Operations and IT Service Intelligence

Copyright©2015,SplunkInc.

AppsProvideDeepInsightsByRole

15

Findandresolveproblemsfastinindividualtechnologyareas

ExchangeAdmin

ServiceHealthPerformance

Messagetracking

VMware/Win/LinuxAdmin

InfrastructureHealthPerformance

Anomalies/Outliers

StorageAdmin

InfrastructureHealthPerformance

Anomalies/Outliers

Page 16: Splunk for IT Operations and IT Service Intelligence

Copyright©2015,SplunkInc.

ReduceCosts:Consolidatetools,eliminatesilos,findrootcausefaster!

ExchangeAdmin

Linux/WinAdminNetworkAdmin Applica>ons

AdminLineofBusiness

User

Applica>onSupport

VMware/Linux/WinAdmin

SecurityAdmin StorageAdmin ITManagement

Page 17: Splunk for IT Operations and IT Service Intelligence

Copyright©2015,SplunkInc.

Splunk:PlajormForITOpera>onalIntelligence

17

Plug-Ins,TemplatesandAppsAccelerateValueFromMachineData

Norigidschemas–Addindatafromanyothersource.

APISDKs UI

Server, Storage, Network

Server Virtualization

Operating Systems

Custom Applications

Business Applications

Cloud Services

App Performance Monitoring Ticketing/ and Other

WebIntelligence

Mobile Applications

Stream

Page 18: Splunk for IT Operations and IT Service Intelligence

Copyright©2015,SplunkInc.

SplunkForOpera>ngSystems

Proactive Monitoring

Operational Analytics

End-to-End Visibility

Getinstantinsightintoinfrastructurehealth

OSMetricsforPerformance,Capacity&ResourceAllocaAonAnalyses

ScaleAndCorrelateAcrossAllTiersOfYourTechnologyStack

18

Page 19: Splunk for IT Operations and IT Service Intelligence

Copyright©2015,SplunkInc.

SplunkForVirtualiza>on&Storage

Proactive Monitoring

Operational Analytics

End-to-End Visibility

Real-AmeacAonableinsightsintoproblemspotsandhealthissues

Real-Ame&historicalinsightsintoperformance,security,capacity,forecasAngandchangetracking

ScalableBigDatasoluAonforholisAcvisibilityacrossalltechnologyAers

19

Page 20: Splunk for IT Operations and IT Service Intelligence

Copyright©2015,SplunkInc.

SplunkforITServiceIntelligence

Page 21: Splunk for IT Operations and IT Service Intelligence

Copyright©2015,SplunkInc.

INTRODUCING

Data-drivenserviceinsightsforroot-causeisola>onandimprovedserviceopera>ons

Page 22: Splunk for IT Operations and IT Service Intelligence

Copyright©2015,SplunkInc.Copyright©2015SplunkInc.

CurrentChallenges

22

Can’taccessthedatathatmahers

Mul>pleproductslackdeepintegra>on

Complexandcustomizedtoolsrequiresignificantexper>seand>me

ITorganizaAonsconAnuetostrugglewithaligningoperaAonswithbusiness

FRAGMENTEDINSIGHTS

SLOW&REACTIVE

INEFFICIENT&UNSCALABLE

Page 23: Splunk for IT Operations and IT Service Intelligence

Copyright©2015,SplunkInc.

SplunkITServiceIntelligence

23

DataDriven•  AllITData-events,metrics,andlogs

Service-awareness•  Providesac>onableinsightsintohighvisibilityservices•  Personalcontextualvisualiza>ons•  Mi>gateproblemsbeforetheyimpactcustomers.

PowerfulPlajorm•  Fastcorrela>onacrossservices&KPIs•  DeploysQuickly•  Scalable,flexibleandfast>me-to-value•  ScalableUniversalPlajorm(anypointin>me)

Page 24: Splunk for IT Operations and IT Service Intelligence

Copyright©2015,SplunkInc.

WhatMakesSplunkITSIDifferent!

24

Search-BasedKPIsEasytowrite,manageandchangebothservicesandKPIs

Reflectsbusinessandtechnologypriori>es

Benefit:Rapidlygenerate&changeKPIstoalignservicehealthwithbusiness

Fiserv–1000sinjustweeks

FullFidelityServiceHealth

Adaptableandflexibledefini>onsofservicehealth

Onesolu>ontogoseamlesslyfromservicereportstorootcause,includingrawdata

Remainsadaptableandyets>llmaintainscompletehistoricalcontext

UniversalDataPlajormDatadriven:AllITdataincludingevents,metricsandlogs

Schemaon-the-FlyAskanyques>onofthedata

FastEmetovalue

Datafidelity

Page 25: Splunk for IT Operations and IT Service Intelligence

Copyright©2015,SplunkInc.

SplunkITServiceIntelligenceData-drivenservicemonitoringandanaly>cs

25

SPLUNKITSERVICEINTELLIGENCE

Time-SeriesIndex

PlajormforMachineData

DynamicServiceModels

Schema-on-Read DataModel CommonInformaEonModel

At-a-GlanceProblemAnalysis

EarlyWarningonDevia>ons

SimplifiedIncidentWorkflows

Page 26: Splunk for IT Operations and IT Service Intelligence

Copyright©2015,SplunkInc.

ITSICoreConcepts

Page 27: Splunk for IT Operations and IT Service Intelligence

Copyright©2015,SplunkInc.

ITServiceIntelligence–CoreConcepts

Service RequestsResponses

Web

TechnicalServices Services

RequestsResponses

MobileAPI/Middleware

RequestsResponses

DNS

SupportDeskRequestsResponses

CustomerTransacEons

RequestsResponses

BusinessServices

Page 28: Splunk for IT Operations and IT Service Intelligence

Copyright©2015,SplunkInc.

PacketNetwork

HypervisorandHosts

RDBMSs

StorageTier

APIServices

WebServices InITSI,aServiceisalogicalgroupoftechnology

componentsthatauserdeemsneedtobemonitored

together.

ITServiceIntelligence–CoreConcepts

Service RequestsResponses

Web

TechnicalServices Services

CustomerTransacEons

Web

CustomerTransacEons

RequestsResponses

BusinessServices

MobileAPI/

Middlew

are

SupportDesk

DNS

Page 29: Splunk for IT Operations and IT Service Intelligence

Copyright©2015,SplunkInc.

ITServiceIntelligence–CoreConcepts

Service RequestsResponses

Web

TechnicalServices

PacketNetwork

HypervisorandHosts

RDBMSs

StorageTier

APIServices

WebServices

Web

KPI:NumberofrequestsKPI:ErrorrateKPI:Averageresponse>meKPI:ServicerCPUloadKPI:ServernetworkI/Ferrors

KPIs

KPIsandHealthscorescons>tutethemeansbywhichServicesare

monitored.

HealthScore

Page 30: Splunk for IT Operations and IT Service Intelligence

Copyright©2015,SplunkInc.

ITServiceIntelligence–CoreConcepts

30

AHealthScoreisascoreform0-100(0beingcri>caland100beingnormal)thathelpsdeterminethehealthofaService.ItiscalculatedbasedonallKPIsimportanceanditsstatus(e.g.green,orange,red),onceeveryminute.

AKeyPerformanceIndicator(KPI)isaSplunksavedsearchcreatedwithintheITSIUIthathelpsmonitora

specificfieldlikeCPU,Memory,NumberofErrorsandsoon.KPIsarecontainedwithinServices.

ServiceAnalyzer–Autogeneratedfilterableand>ledviewofServicehealthscoresandKPIs

Page 31: Splunk for IT Operations and IT Service Intelligence

Copyright©2015,SplunkInc.

ITServiceIntelligence–CoreConcepts

31

AGlassTableisacustomizablefreeformdrawingdashboardstoviewHealthscoresand

KPIsofchoicewithvisualtoolstocreatecontextwithlivewidgets

GoDeepertoaDeepDiveView

Page 32: Splunk for IT Operations and IT Service Intelligence

Copyright©2015,SplunkInc.

ITServiceIntelligence–CoreConcepts

32

DeepDives–Swimlaneanalysisdashboardtoshowallthoseindicatorsover>mefor

inves>ga>ons

Page 33: Splunk for IT Operations and IT Service Intelligence

Copyright©2015,SplunkInc.

ITServiceIntelligence–CoreConcepts

33

MulEKPIAlerts–Visualtooltocreatecorrela>onsearchesbasedonKPIs

Page 34: Splunk for IT Operations and IT Service Intelligence

Copyright©2015,SplunkInc.

NotableEvents

34

NotableEventsaregeneratedbycorrela>onsearchesthatindicateservicedegrada>on.TheyarelikeNotableEventsinESbuthaveaslightlydifferent

fieldsetTheCorrela>onsearchesaregeneratedeitherthroughthecorrela>onsearchUIorMul>KPIAlertUI.

Page 35: Splunk for IT Operations and IT Service Intelligence

Copyright©2015,SplunkInc.

SplunkforBusinessAnaly>cs

Page 36: Splunk for IT Operations and IT Service Intelligence

Copyright©2015,SplunkInc.Copyright©2015SplunkInc.

RealTimeClevelGlasstable…

Page 37: Splunk for IT Operations and IT Service Intelligence

Copyright©2015,SplunkInc.Copyright©2015SplunkInc.

..drillsdowntoindividualBPAStakeholdertglasstable….

37

Page 38: Splunk for IT Operations and IT Service Intelligence

Copyright©2015,SplunkInc.Copyright©2015SplunkInc. 38

..drillsdowntotheindividualpa>entjourney

Page 39: Splunk for IT Operations and IT Service Intelligence

Copyright©2015,SplunkInc.

Adap>veThresholding

Page 40: Splunk for IT Operations and IT Service Intelligence

Copyright©2015,SplunkInc.

Page 41: Splunk for IT Operations and IT Service Intelligence

Copyright©2015,SplunkInc.

Page 42: Splunk for IT Operations and IT Service Intelligence

Copyright©2015,SplunkInc.

Page 43: Splunk for IT Operations and IT Service Intelligence

Copyright©2015,SplunkInc.

Thanks–Q&A