SlideShare una empresa de Scribd logo
1 de 38
Robert Novak, Cisco Big Data Partner CSE
March 2016
Splunk in the Cisco UCS Ecosystem
How Cisco and its customers deploy,
use, and scale Splunk environments
with the Cisco Unified Computing System
Who am I and why am I here?
Today: Consulting Systems Engineer
for Cisco’s Americas Partner Organization
Focused on big data and analytics
UNIX Sysadmin for ~20 years (retired)
Full stack: servers, storage, network, coffee
149 to 149k person companies
Sun, Nortel, 3PAR, Ebay, Trulia, Disney, etc
“Big Data” herder since 2003
Hadoop admin (certifiable) since 2009
Cisco UCS C-Series admin since 2011 (early adopter!)
Charter Cisco Champion, VMware vExpert since 2013
Blogger at rsts11.com and Cisco Blogs
Tweeter at @gallifreyan and @rsts11
Agenda
• Hardware still matters!
• How Cisco uses Splunk internally
• How some of our customers use Splunk on UCS
• Cisco integrations with Splunk
• The Unified Computing System advantage
• Learn More
Hardware Still Matters
A quick glance at infrastructure for Splunk
Why does hardware still matter?
5
• Splunk will run on almost anything (even my laptop)
• Standalone servers have lower admin overhead
• Build up your clusters and you have to keep them consistent
• Grow your data sources (and uses) and you have to add
servers
• Cluster constipation is bad, mmmkay?
Why does hardware still matter?
6
• Cisco customer big data pools tend to grow 2-3x/year
• Cisco customer IT staff doesn’t grow as fast
• The Cisco Unified Computing System (UCS) provides
scalable, repeatable, predictable, and manageable
deployments across dozens to thousands of servers for any
application deployment
• Pallet to production in hours, not days or weeks
• Deep engineering integration between Cisco and Splunk with
tested and proven configurations
More on this later…
How Cisco Uses Splunk
Part 1
Operational Analytics at Enterprise Scale
within Cisco IT
Big Data at a Big Customer: Cisco
8
• 10s of thousands of employees, contractors, devices
• 100s of offices, business apps, audiences
• Lots of data in lots of places
• No one tool (not even Splunk) can do everything for
everyone all the time
• High volume, low value, low shelf life
• Lancope, Hadoop feed into Splunk
• Low to moderate volume, high value, (any) shelf life
• Splunk on its own, sometimes with fronting dashboards
• Additional visualizations with Platfora, Tableau, etc
A closer look at Splunk within Cisco
9
• Customer for 7+ years, strategic partner for 3+ years
• Geographically disparate data collection and analysis
• Over 70 business applications/use cases across the company
• Around 20 teams using Splunk including Cisco IT and CSIRT
• Nearly 10x growth in search volume from 2014-2016
10 Indexers
16 Search Heads
thanks to search head
clustering in Splunk 6.3
47 Search Heads
20 Indexers
Daily Indexing
~ 2TB
2014
2014
2015
2015
2015
Cisco’s IT Operations Evolving with Splunk
Daily Indexing
300G
2010
Splunk Searches – Daily Average
1. Interactive Searches = 55K+ 2. Scheduled Searches = 45K+
3. Total Searches = 100K+ 4. Number of Users = 180+
How Cisco Uses Splunk
Part 2
Security Analytics at Enterprise Scale:
Cisco’s Computer Security Incident Response
Team (CSIRT)
About CSIRT
• Cisco Computer Security Incident Response Team (CSIRT)
• CSIRT = Security Monitoring and Incident Response
• Architecture, Engineering, Research, and Investigations
• Enterprise global threat and 24x7 incident response
CSIRT Environments Recent Snapshot
 300 locations in 90 countries
 400 buildings
 1500+ labs
 100,000+ employees on network
 50-300 malware-related cases opened in a typical week
 650,000+ ip devices on network
 130,000 windows hosts
 50,000 Linux hosts
 40,000 routers
 2-3 million highly tuned ids events per day
 10+ billion netflow records per day
Deploying Splunk as SIEM
• SIEM: Security Information and Event Management platform
– Easy to index any type of machine data from any source
– Over 60 users doing investigations, correlations, reporting, advanced threat detection
– All the data + flexible searches and reporting = empowered and effective team
– 2TB/day and searches take less than a minute. 7 global data centers with 350TB stored data
– Flashback Malware contained to a fraction of the environment
– Replaced older pre-big-data SIEM
 Previous solution didn’t scale effectively
 Queries in the minutes (or worse) rather than seconds with Splunk
 Diverse functionality across the same aggregate data
Looking at our customers
Successful deployments
with Cisco UCS and Splunk
Threat Management at Govt Agency
19
• Agency wanted to manage and monitor all relevant alert data
• Needed visibility across multiple security platforms
• Centralized on scalable appliance model through a partner
• Splunk Enterprise with Enterprise Security[1] premium app
• By deploying on Cisco UCS with proven Cisco Validated
Design, partner was able to deliver easily upgraded and
expanded deployment with predictable results
[1] Splunk won Best SIEM Solution (Enterprise Security) and Best Fraud Prevention Solution
(Splunk Enterprise) awards from SC Magazine this month (Splunk press release)
Fraud prevention for Online School
20
• Leading online university needed to track student activity
• Federal agencies have stringent requirements for loan
qualifications and fulfillment
• Deployed Splunk on UCS for student activity tracking
• Blocking millions in fraudulent loan claims
• Saving over 75% on auditing and compliance expenses
• Saving over $1M/year on data processing
• Deployed and expanded other analytics (security operations,
IT operations, and application deployment)
• Splunk on UCS grows beyond initial use cases and teams at
most of our customers
21
• Leading worldwide financial services company used Splunk
for IT Operations analytics
• When an electronic payment platform deployment came up,
Splunk was enlisted to support rollout and monitoring in
ridiculously short time frame
• Speed and scalability led to use cases for security and fraud
detection/prevention, marketing optimization, customer
engagement and offers, and more
• Customer continues to grow their Splunk environment (over
10x in first year, and still growing!)
IT Ops & beyond for financial services
22
• Customer needed quick updates, secure services, and high availability
• Deployed Splunk Enterprise on UCS to replace older hardware and
software platforms that didn’t scale well
• Splunk and UCS delivered a more robust security posture with faster
investigation and resolution of security events
• High performance security analytics solution enables hospital to identify
attack patterns and unauthorized actions that would otherwise go
undetected.
• Reduced space/power/cooling by 75%
• Server deployment time reduced from 7 days to 1 day.
See Cisco’s case study at cisco.com
and Splunk’s case study at splunk.com
Secure Healthcare at Union Hospital
Got Cisco?
There’s an app for that…
(or a technology add-on, at least)
CiscoSecuritySuiteApp
Splunk & Cisco Integrations
Security
Identity Services
Engine (pxGrid)
Sourcefire
(including AMP)
ASA/PIX/FWSM
Firewalls
Web Security
Appliance (WSA)
Email Security
Appliance (ESA)
IPS
Cloud Web Security
(CWS)
AnyConnect
OpenDNS, ThreatGrid
(in development)
Data Center/
Insieme
Cisco UCS
Nexus 9K
Application Centric
Infrastructure
(ACI - APIC)
UCS Integrated
Infrastructures Optimized
for Splunk Enterprise
High Performance
High Capacity
Enterprise
Networking
Switching and
Routing
Catalyst Switches
Nexus
(1000V, 2000, 3000, 4000,
5000, 6000, 7000, 9000)
Meraki Wireless
NGN Routers
(CRS, ASR, ISR)
Open SDN Network
Controller
APIC EM
Collaboration
Call Manager
• Inaugural SIEM & Threat Defense Partner
• Inaugural pxGrid partner
• Inaugural member of new Cisco Security
Technical Alliances program
• Inaugural ACI Partner
• Inaugural Data Analytics
Partner
• Cisco Cloud Security for VMDC 1.0 Design Guide (link)
• Cisco UCS Integrated Infrastructure for Splunk Enterprise (Distributed Deployment, High Capacity) (link)
CiscoNetworksApp
Splunk App for Cisco UCS
NEW AND IMPROVED as of May 28, 2016
Aggregates, monitors, trends and analyzes all
relevant data from Cisco UCS Manager
instances
Enables proactive capacity and performance
monitoring/ management, fault trending,
power and cooling, and more
Works with other Splunk add-ons and data
sources (including Enterprise Security and
PCI Compliance add-ons) to aggregate and
correlate data across your enterprise
25
Application
s
Operating Systems
Hypervisors
UCS server, storage,
network
Splunk on Cisco UCS
What is
Cisco’s
Unified
Computing
System
(UCS)?
Unified Management: UCS Manager
uses policy-based configuration to
ensure consistent deployments
Unified Fabric: Integrated 10/40 Gigabit
Ethernet and Storage Networking
(FCoE/iSCSI)
Service Profiles: Maintain consistency
across batches of servers and multiple
applications. Deploy and expand in
record time.
Performance: Built with 10GbE and
40GbE at the core, repeatable
configurations and performance, and
over 100 benchmark records
Why Splunk
on Cisco
UCS?
Time to Deployment: Spin up a
mutually validated, pre-tested
environment in hours rather than days or
weeks
Total Cost of Ownership: Integrated
networking and management reduce
customer cost and effort to migrate,
deploy, and expand
Time to Grow: Expand servers and
network capacity quickly and
consistently
Cisco UCS + Splunk = Better Together
Seamless Scalability Facilitates Rapid Growth
– Scale Splunk from a single server to distributed/clustered deployment
– Grow your clusters efficiently and consistently
– Runs on the same UCS C-Series servers as other big data platforms
Split Second Response Times
– Exceptional performance for “needle-in-a-haystack” searches
– Consistent performance as simultaneous users increase
Simplified Repeatable Deployments
– Four pre-tested UCS Integrated Infrastructures
– Capacity or performance optimization
– NEW! Cisco Validated Design (CVD) with HA and Archiving
250 GB indexed per day
4 months retention
250 GB indexed per day
1 month retention
Single Server
Cisco UCS Reference Architectures
UP to 4TB indexed per day
3 months Retention
Up to 4TB indexed per day
1 year Retention
Clustered Deployment
Retention
optimized
Performance
optimized
Cisco Validated Design (CVD) for Splunk
• Developed by Cisco and Splunk
engineers in Spring 2016
• 250+ page guide to design and
deployment, pallet to production
• Based on UCS C-Series (C220, C240,
C3160) servers and Splunk Enterprise
software
• Includes high availability & data archiving
• Download for free at
cisco.com/go/bigdata_design
Splunk on UCS : Performance Benchmark Test bed Topology
Cisco UCS Benchmark Results
(Splunk Enterprise 6.2 vs 6.3)
Learn more about
Splunk and Cisco UCS
SplunkBase app resources: splunkbase.splunk.com
Cisco’s Big Data Design Hub: cisco.com/go/bigdata_design
features Cisco Validated Designs (CVDs) and other architectural docs
Big Data Applications Hub: cisco.com/go/bigdata
features reference architectures, solution briefs, infrastructure, automation, etc.
Reach Out!
Already using Splunk? Talk to your Splunk team about Cisco UCS!
Already using Cisco UCS? Talk to your Cisco team about Splunk!
Learn More About Splunk on Cisco UCS!
Cisco’s CSIRT engineers
applied their experiences during
the CSIRT deployment to a new
O’Reilly book now available
bitly.com/infosecplaybook
“they wrote the book …”
36
Thank you.
Splunk and Cisco UCS Breakout Session

Más contenido relacionado

La actualidad más candente

バッチ処理にバインド変数はもうやめません? ~|バッチ処理の突発遅延を題材にして考えてみる~
バッチ処理にバインド変数はもうやめません? ~|バッチ処理の突発遅延を題材にして考えてみる~バッチ処理にバインド変数はもうやめません? ~|バッチ処理の突発遅延を題材にして考えてみる~
バッチ処理にバインド変数はもうやめません? ~|バッチ処理の突発遅延を題材にして考えてみる~Ryota Watabe
 
外部キー制約に伴うロックの小話
外部キー制約に伴うロックの小話外部キー制約に伴うロックの小話
外部キー制約に伴うロックの小話ichirin2501
 
ビッグデータ処理データベースの全体像と使い分け - 2017年 Version -
ビッグデータ処理データベースの全体像と使い分け - 2017年 Version - ビッグデータ処理データベースの全体像と使い分け - 2017年 Version -
ビッグデータ処理データベースの全体像と使い分け - 2017年 Version - Tetsutaro Watanabe
 
MySQL 5.7とレプリケーションにおける改良
MySQL 5.7とレプリケーションにおける改良MySQL 5.7とレプリケーションにおける改良
MySQL 5.7とレプリケーションにおける改良Shinya Sugiyama
 
Web App for Containers のデプロイでつまずいた話
Web App for Containers のデプロイでつまずいた話Web App for Containers のデプロイでつまずいた話
Web App for Containers のデプロイでつまずいた話Shigenari Ohnuma
 
【Interop Tokyo 2016】 次世代サービス チェイニング NSH (Network Service Header)
【Interop Tokyo 2016】 次世代サービス チェイニング NSH (Network Service Header)【Interop Tokyo 2016】 次世代サービス チェイニング NSH (Network Service Header)
【Interop Tokyo 2016】 次世代サービス チェイニング NSH (Network Service Header)シスコシステムズ合同会社
 
Creating Single Page Applications with Oracle Apex
Creating Single Page Applications with Oracle ApexCreating Single Page Applications with Oracle Apex
Creating Single Page Applications with Oracle ApexDick Dral
 
PostgreSQLによるデータ分析ことはじめ
PostgreSQLによるデータ分析ことはじめPostgreSQLによるデータ分析ことはじめ
PostgreSQLによるデータ分析ことはじめOhyama Masanori
 
Openconfigを用いたネットワーク機器操作
Openconfigを用いたネットワーク機器操作Openconfigを用いたネットワーク機器操作
Openconfigを用いたネットワーク機器操作Hirofumi Ichihara
 
[db tech showcase Tokyo 2018] #dbts2018 #D34 『サポートのトップエンジニアが語る - ワンランク上のStats...
[db tech showcase Tokyo 2018] #dbts2018 #D34 『サポートのトップエンジニアが語る - ワンランク上のStats...[db tech showcase Tokyo 2018] #dbts2018 #D34 『サポートのトップエンジニアが語る - ワンランク上のStats...
[db tech showcase Tokyo 2018] #dbts2018 #D34 『サポートのトップエンジニアが語る - ワンランク上のStats...Insight Technology, Inc.
 
イマドキのExcelスクショの撮り方
イマドキのExcelスクショの撮り方イマドキのExcelスクショの撮り方
イマドキのExcelスクショの撮り方Yoshitaka Kawashima
 
Oracle常駐接続プーリング(DRCP)を導入した話
Oracle常駐接続プーリング(DRCP)を導入した話Oracle常駐接続プーリング(DRCP)を導入した話
Oracle常駐接続プーリング(DRCP)を導入した話Kentaro Kitagawa
 
NGINX Back to Basics: Ingress Controller (Japanese Webinar)
NGINX Back to Basics: Ingress Controller (Japanese Webinar)NGINX Back to Basics: Ingress Controller (Japanese Webinar)
NGINX Back to Basics: Ingress Controller (Japanese Webinar)NGINX, Inc.
 
Splunk HTTP Event Collector
Splunk HTTP Event CollectorSplunk HTTP Event Collector
Splunk HTTP Event CollectorSplunk
 
SQLアンチパターン~ファントムファイル
SQLアンチパターン~ファントムファイルSQLアンチパターン~ファントムファイル
SQLアンチパターン~ファントムファイルItabashi Masayuki
 
Prometheus入門から運用まで徹底解説
Prometheus入門から運用まで徹底解説Prometheus入門から運用まで徹底解説
Prometheus入門から運用まで徹底解説貴仁 大和屋
 
Do You Really Need to Evolve From Monitoring to Observability?
Do You Really Need to Evolve From Monitoring to Observability?Do You Really Need to Evolve From Monitoring to Observability?
Do You Really Need to Evolve From Monitoring to Observability?Splunk
 
マルチクラウドDWH(Snowflake)のすすめ
マルチクラウドDWH(Snowflake)のすすめマルチクラウドDWH(Snowflake)のすすめ
マルチクラウドDWH(Snowflake)のすすめYuuta Hishinuma
 

La actualidad más candente (20)

バッチ処理にバインド変数はもうやめません? ~|バッチ処理の突発遅延を題材にして考えてみる~
バッチ処理にバインド変数はもうやめません? ~|バッチ処理の突発遅延を題材にして考えてみる~バッチ処理にバインド変数はもうやめません? ~|バッチ処理の突発遅延を題材にして考えてみる~
バッチ処理にバインド変数はもうやめません? ~|バッチ処理の突発遅延を題材にして考えてみる~
 
外部キー制約に伴うロックの小話
外部キー制約に伴うロックの小話外部キー制約に伴うロックの小話
外部キー制約に伴うロックの小話
 
ビッグデータ処理データベースの全体像と使い分け - 2017年 Version -
ビッグデータ処理データベースの全体像と使い分け - 2017年 Version - ビッグデータ処理データベースの全体像と使い分け - 2017年 Version -
ビッグデータ処理データベースの全体像と使い分け - 2017年 Version -
 
MySQL 5.7とレプリケーションにおける改良
MySQL 5.7とレプリケーションにおける改良MySQL 5.7とレプリケーションにおける改良
MySQL 5.7とレプリケーションにおける改良
 
Nmapの真実(続)
Nmapの真実(続)Nmapの真実(続)
Nmapの真実(続)
 
Web App for Containers のデプロイでつまずいた話
Web App for Containers のデプロイでつまずいた話Web App for Containers のデプロイでつまずいた話
Web App for Containers のデプロイでつまずいた話
 
【Interop Tokyo 2016】 次世代サービス チェイニング NSH (Network Service Header)
【Interop Tokyo 2016】 次世代サービス チェイニング NSH (Network Service Header)【Interop Tokyo 2016】 次世代サービス チェイニング NSH (Network Service Header)
【Interop Tokyo 2016】 次世代サービス チェイニング NSH (Network Service Header)
 
Creating Single Page Applications with Oracle Apex
Creating Single Page Applications with Oracle ApexCreating Single Page Applications with Oracle Apex
Creating Single Page Applications with Oracle Apex
 
PostgreSQLによるデータ分析ことはじめ
PostgreSQLによるデータ分析ことはじめPostgreSQLによるデータ分析ことはじめ
PostgreSQLによるデータ分析ことはじめ
 
Openconfigを用いたネットワーク機器操作
Openconfigを用いたネットワーク機器操作Openconfigを用いたネットワーク機器操作
Openconfigを用いたネットワーク機器操作
 
[db tech showcase Tokyo 2018] #dbts2018 #D34 『サポートのトップエンジニアが語る - ワンランク上のStats...
[db tech showcase Tokyo 2018] #dbts2018 #D34 『サポートのトップエンジニアが語る - ワンランク上のStats...[db tech showcase Tokyo 2018] #dbts2018 #D34 『サポートのトップエンジニアが語る - ワンランク上のStats...
[db tech showcase Tokyo 2018] #dbts2018 #D34 『サポートのトップエンジニアが語る - ワンランク上のStats...
 
イマドキのExcelスクショの撮り方
イマドキのExcelスクショの撮り方イマドキのExcelスクショの撮り方
イマドキのExcelスクショの撮り方
 
Oracle常駐接続プーリング(DRCP)を導入した話
Oracle常駐接続プーリング(DRCP)を導入した話Oracle常駐接続プーリング(DRCP)を導入した話
Oracle常駐接続プーリング(DRCP)を導入した話
 
NGINX Back to Basics: Ingress Controller (Japanese Webinar)
NGINX Back to Basics: Ingress Controller (Japanese Webinar)NGINX Back to Basics: Ingress Controller (Japanese Webinar)
NGINX Back to Basics: Ingress Controller (Japanese Webinar)
 
Apache Spark の紹介(前半:Sparkのキホン)
Apache Spark の紹介(前半:Sparkのキホン)Apache Spark の紹介(前半:Sparkのキホン)
Apache Spark の紹介(前半:Sparkのキホン)
 
Splunk HTTP Event Collector
Splunk HTTP Event CollectorSplunk HTTP Event Collector
Splunk HTTP Event Collector
 
SQLアンチパターン~ファントムファイル
SQLアンチパターン~ファントムファイルSQLアンチパターン~ファントムファイル
SQLアンチパターン~ファントムファイル
 
Prometheus入門から運用まで徹底解説
Prometheus入門から運用まで徹底解説Prometheus入門から運用まで徹底解説
Prometheus入門から運用まで徹底解説
 
Do You Really Need to Evolve From Monitoring to Observability?
Do You Really Need to Evolve From Monitoring to Observability?Do You Really Need to Evolve From Monitoring to Observability?
Do You Really Need to Evolve From Monitoring to Observability?
 
マルチクラウドDWH(Snowflake)のすすめ
マルチクラウドDWH(Snowflake)のすすめマルチクラウドDWH(Snowflake)のすすめ
マルチクラウドDWH(Snowflake)のすすめ
 

Destacado

Splunk in the Cisco Unified Computing System (UCS)
Splunk in the Cisco Unified Computing System (UCS) Splunk in the Cisco Unified Computing System (UCS)
Splunk in the Cisco Unified Computing System (UCS) Splunk
 
SplunkLive! Warsaw 2016 - Cisco
SplunkLive! Warsaw 2016 - Cisco SplunkLive! Warsaw 2016 - Cisco
SplunkLive! Warsaw 2016 - Cisco Splunk
 
Cisco and Splunk: Under the Hood of Cisco IT Breakout Session
Cisco and Splunk: Under the Hood of Cisco IT Breakout SessionCisco and Splunk: Under the Hood of Cisco IT Breakout Session
Cisco and Splunk: Under the Hood of Cisco IT Breakout SessionSplunk
 
SplunkLive! Customer Presentation - Cisco Systems, Inc.
SplunkLive! Customer Presentation - Cisco Systems, Inc.SplunkLive! Customer Presentation - Cisco Systems, Inc.
SplunkLive! Customer Presentation - Cisco Systems, Inc.Splunk
 
Cisco UCS - Servidores
Cisco  UCS  - ServidoresCisco  UCS  - Servidores
Cisco UCS - ServidoresBruno Banha
 

Destacado (6)

Splunk in the Cisco Unified Computing System (UCS)
Splunk in the Cisco Unified Computing System (UCS) Splunk in the Cisco Unified Computing System (UCS)
Splunk in the Cisco Unified Computing System (UCS)
 
SplunkLive! Warsaw 2016 - Cisco
SplunkLive! Warsaw 2016 - Cisco SplunkLive! Warsaw 2016 - Cisco
SplunkLive! Warsaw 2016 - Cisco
 
Cisco and Splunk: Under the Hood of Cisco IT Breakout Session
Cisco and Splunk: Under the Hood of Cisco IT Breakout SessionCisco and Splunk: Under the Hood of Cisco IT Breakout Session
Cisco and Splunk: Under the Hood of Cisco IT Breakout Session
 
SplunkLive! Customer Presentation - Cisco Systems, Inc.
SplunkLive! Customer Presentation - Cisco Systems, Inc.SplunkLive! Customer Presentation - Cisco Systems, Inc.
SplunkLive! Customer Presentation - Cisco Systems, Inc.
 
Cisco UCS - Servidores
Cisco  UCS  - ServidoresCisco  UCS  - Servidores
Cisco UCS - Servidores
 
Slideshare ppt
Slideshare pptSlideshare ppt
Slideshare ppt
 

Similar a Splunk and Cisco UCS Breakout Session

Cisco UCS and Splunk Workshop
Cisco UCS and Splunk WorkshopCisco UCS and Splunk Workshop
Cisco UCS and Splunk WorkshopRobb Boyd
 
Inside SecOps at bet365
Inside SecOps at bet365 Inside SecOps at bet365
Inside SecOps at bet365 Splunk
 
SplunkLive! London - Splunk App for Stream & MINT Breakout
SplunkLive! London - Splunk App for Stream & MINT BreakoutSplunkLive! London - Splunk App for Stream & MINT Breakout
SplunkLive! London - Splunk App for Stream & MINT BreakoutSplunk
 
How to accelerate Splunk analytics
How to accelerate Splunk analyticsHow to accelerate Splunk analytics
How to accelerate Splunk analyticsClearSky Data
 
Getting Started with Splunk Enterprise Hands-On
Getting Started with Splunk Enterprise Hands-OnGetting Started with Splunk Enterprise Hands-On
Getting Started with Splunk Enterprise Hands-OnSplunk
 
Webinar: Improve Splunk Analytics and Automate Processes with SnapLogic
Webinar: Improve Splunk Analytics and Automate Processes with SnapLogicWebinar: Improve Splunk Analytics and Automate Processes with SnapLogic
Webinar: Improve Splunk Analytics and Automate Processes with SnapLogicSnapLogic
 
Getting Started with Splunk Breakout Session
Getting Started with Splunk Breakout SessionGetting Started with Splunk Breakout Session
Getting Started with Splunk Breakout SessionSplunk
 
Splunk MINT and Stream Breakout
Splunk MINT and Stream BreakoutSplunk MINT and Stream Breakout
Splunk MINT and Stream BreakoutSplunk
 
Getting Started with Splunk Enterprise
Getting Started with Splunk EnterpriseGetting Started with Splunk Enterprise
Getting Started with Splunk EnterpriseSplunk
 
Getting Started with Splunk Enterprise
Getting Started with Splunk EnterpriseGetting Started with Splunk Enterprise
Getting Started with Splunk EnterpriseShannon Cuthbertson
 
Machine Learning + Analytics in Splunk
Machine Learning + Analytics in Splunk Machine Learning + Analytics in Splunk
Machine Learning + Analytics in Splunk Splunk
 
Getting Started with Splunk Enterprise Hands-On Breakout Session
Getting Started with Splunk Enterprise Hands-On Breakout SessionGetting Started with Splunk Enterprise Hands-On Breakout Session
Getting Started with Splunk Enterprise Hands-On Breakout SessionSplunk
 
SplunkLive! Amsterdam 2015 Breakout - Getting Started with Splunk
SplunkLive! Amsterdam 2015 Breakout - Getting Started with SplunkSplunkLive! Amsterdam 2015 Breakout - Getting Started with Splunk
SplunkLive! Amsterdam 2015 Breakout - Getting Started with SplunkSplunk
 
Splunk for Enterprise Security featuring User Behavior Analytics
Splunk for Enterprise Security featuring User Behavior AnalyticsSplunk for Enterprise Security featuring User Behavior Analytics
Splunk for Enterprise Security featuring User Behavior AnalyticsSplunk
 
SplunkLive! Washington DC May 2013 - Splunk Enterprise 5
SplunkLive! Washington DC May 2013 - Splunk Enterprise 5SplunkLive! Washington DC May 2013 - Splunk Enterprise 5
SplunkLive! Washington DC May 2013 - Splunk Enterprise 5Splunk
 
Splunk Sales Presentation Imagemaker 2014
Splunk Sales Presentation Imagemaker 2014Splunk Sales Presentation Imagemaker 2014
Splunk Sales Presentation Imagemaker 2014Urena Nicolas
 
Best Practices for a CoE
Best Practices for a CoEBest Practices for a CoE
Best Practices for a CoESplunk
 
Taking Splunk to the Next Level - Manager
Taking Splunk to the Next Level - ManagerTaking Splunk to the Next Level - Manager
Taking Splunk to the Next Level - ManagerSplunk
 
Splunk for Enterprise Security featuring UBA Breakout Session
Splunk for Enterprise Security featuring UBA Breakout SessionSplunk for Enterprise Security featuring UBA Breakout Session
Splunk for Enterprise Security featuring UBA Breakout SessionSplunk
 

Similar a Splunk and Cisco UCS Breakout Session (20)

Cisco UCS and Splunk Workshop
Cisco UCS and Splunk WorkshopCisco UCS and Splunk Workshop
Cisco UCS and Splunk Workshop
 
Inside SecOps at bet365
Inside SecOps at bet365 Inside SecOps at bet365
Inside SecOps at bet365
 
SplunkLive! London - Splunk App for Stream & MINT Breakout
SplunkLive! London - Splunk App for Stream & MINT BreakoutSplunkLive! London - Splunk App for Stream & MINT Breakout
SplunkLive! London - Splunk App for Stream & MINT Breakout
 
Splunk
SplunkSplunk
Splunk
 
How to accelerate Splunk analytics
How to accelerate Splunk analyticsHow to accelerate Splunk analytics
How to accelerate Splunk analytics
 
Getting Started with Splunk Enterprise Hands-On
Getting Started with Splunk Enterprise Hands-OnGetting Started with Splunk Enterprise Hands-On
Getting Started with Splunk Enterprise Hands-On
 
Webinar: Improve Splunk Analytics and Automate Processes with SnapLogic
Webinar: Improve Splunk Analytics and Automate Processes with SnapLogicWebinar: Improve Splunk Analytics and Automate Processes with SnapLogic
Webinar: Improve Splunk Analytics and Automate Processes with SnapLogic
 
Getting Started with Splunk Breakout Session
Getting Started with Splunk Breakout SessionGetting Started with Splunk Breakout Session
Getting Started with Splunk Breakout Session
 
Splunk MINT and Stream Breakout
Splunk MINT and Stream BreakoutSplunk MINT and Stream Breakout
Splunk MINT and Stream Breakout
 
Getting Started with Splunk Enterprise
Getting Started with Splunk EnterpriseGetting Started with Splunk Enterprise
Getting Started with Splunk Enterprise
 
Getting Started with Splunk Enterprise
Getting Started with Splunk EnterpriseGetting Started with Splunk Enterprise
Getting Started with Splunk Enterprise
 
Machine Learning + Analytics in Splunk
Machine Learning + Analytics in Splunk Machine Learning + Analytics in Splunk
Machine Learning + Analytics in Splunk
 
Getting Started with Splunk Enterprise Hands-On Breakout Session
Getting Started with Splunk Enterprise Hands-On Breakout SessionGetting Started with Splunk Enterprise Hands-On Breakout Session
Getting Started with Splunk Enterprise Hands-On Breakout Session
 
SplunkLive! Amsterdam 2015 Breakout - Getting Started with Splunk
SplunkLive! Amsterdam 2015 Breakout - Getting Started with SplunkSplunkLive! Amsterdam 2015 Breakout - Getting Started with Splunk
SplunkLive! Amsterdam 2015 Breakout - Getting Started with Splunk
 
Splunk for Enterprise Security featuring User Behavior Analytics
Splunk for Enterprise Security featuring User Behavior AnalyticsSplunk for Enterprise Security featuring User Behavior Analytics
Splunk for Enterprise Security featuring User Behavior Analytics
 
SplunkLive! Washington DC May 2013 - Splunk Enterprise 5
SplunkLive! Washington DC May 2013 - Splunk Enterprise 5SplunkLive! Washington DC May 2013 - Splunk Enterprise 5
SplunkLive! Washington DC May 2013 - Splunk Enterprise 5
 
Splunk Sales Presentation Imagemaker 2014
Splunk Sales Presentation Imagemaker 2014Splunk Sales Presentation Imagemaker 2014
Splunk Sales Presentation Imagemaker 2014
 
Best Practices for a CoE
Best Practices for a CoEBest Practices for a CoE
Best Practices for a CoE
 
Taking Splunk to the Next Level - Manager
Taking Splunk to the Next Level - ManagerTaking Splunk to the Next Level - Manager
Taking Splunk to the Next Level - Manager
 
Splunk for Enterprise Security featuring UBA Breakout Session
Splunk for Enterprise Security featuring UBA Breakout SessionSplunk for Enterprise Security featuring UBA Breakout Session
Splunk for Enterprise Security featuring UBA Breakout Session
 

Más de Splunk

.conf Go 2023 - Data analysis as a routine
.conf Go 2023 - Data analysis as a routine.conf Go 2023 - Data analysis as a routine
.conf Go 2023 - Data analysis as a routineSplunk
 
.conf Go 2023 - How KPN drives Customer Satisfaction on IPTV
.conf Go 2023 - How KPN drives Customer Satisfaction on IPTV.conf Go 2023 - How KPN drives Customer Satisfaction on IPTV
.conf Go 2023 - How KPN drives Customer Satisfaction on IPTVSplunk
 
.conf Go 2023 - Navegando la normativa SOX (Telefónica)
.conf Go 2023 - Navegando la normativa SOX (Telefónica).conf Go 2023 - Navegando la normativa SOX (Telefónica)
.conf Go 2023 - Navegando la normativa SOX (Telefónica)Splunk
 
.conf Go 2023 - Raiffeisen Bank International
.conf Go 2023 - Raiffeisen Bank International.conf Go 2023 - Raiffeisen Bank International
.conf Go 2023 - Raiffeisen Bank InternationalSplunk
 
.conf Go 2023 - På liv og død Om sikkerhetsarbeid i Norsk helsenett
.conf Go 2023 - På liv og død Om sikkerhetsarbeid i Norsk helsenett .conf Go 2023 - På liv og død Om sikkerhetsarbeid i Norsk helsenett
.conf Go 2023 - På liv og død Om sikkerhetsarbeid i Norsk helsenett Splunk
 
.conf Go 2023 - Many roads lead to Rome - this was our journey (Julius Bär)
.conf Go 2023 - Many roads lead to Rome - this was our journey (Julius Bär).conf Go 2023 - Many roads lead to Rome - this was our journey (Julius Bär)
.conf Go 2023 - Many roads lead to Rome - this was our journey (Julius Bär)Splunk
 
.conf Go 2023 - Das passende Rezept für die digitale (Security) Revolution zu...
.conf Go 2023 - Das passende Rezept für die digitale (Security) Revolution zu....conf Go 2023 - Das passende Rezept für die digitale (Security) Revolution zu...
.conf Go 2023 - Das passende Rezept für die digitale (Security) Revolution zu...Splunk
 
.conf go 2023 - Cyber Resilienz – Herausforderungen und Ansatz für Energiever...
.conf go 2023 - Cyber Resilienz – Herausforderungen und Ansatz für Energiever....conf go 2023 - Cyber Resilienz – Herausforderungen und Ansatz für Energiever...
.conf go 2023 - Cyber Resilienz – Herausforderungen und Ansatz für Energiever...Splunk
 
.conf go 2023 - De NOC a CSIRT (Cellnex)
.conf go 2023 - De NOC a CSIRT (Cellnex).conf go 2023 - De NOC a CSIRT (Cellnex)
.conf go 2023 - De NOC a CSIRT (Cellnex)Splunk
 
conf go 2023 - El camino hacia la ciberseguridad (ABANCA)
conf go 2023 - El camino hacia la ciberseguridad (ABANCA)conf go 2023 - El camino hacia la ciberseguridad (ABANCA)
conf go 2023 - El camino hacia la ciberseguridad (ABANCA)Splunk
 
Splunk - BMW connects business and IT with data driven operations SRE and O11y
Splunk - BMW connects business and IT with data driven operations SRE and O11ySplunk - BMW connects business and IT with data driven operations SRE and O11y
Splunk - BMW connects business and IT with data driven operations SRE and O11ySplunk
 
Splunk x Freenet - .conf Go Köln
Splunk x Freenet - .conf Go KölnSplunk x Freenet - .conf Go Köln
Splunk x Freenet - .conf Go KölnSplunk
 
Splunk Security Session - .conf Go Köln
Splunk Security Session - .conf Go KölnSplunk Security Session - .conf Go Köln
Splunk Security Session - .conf Go KölnSplunk
 
Data foundations building success, at city scale – Imperial College London
 Data foundations building success, at city scale – Imperial College London Data foundations building success, at city scale – Imperial College London
Data foundations building success, at city scale – Imperial College LondonSplunk
 
Splunk: How Vodafone established Operational Analytics in a Hybrid Environmen...
Splunk: How Vodafone established Operational Analytics in a Hybrid Environmen...Splunk: How Vodafone established Operational Analytics in a Hybrid Environmen...
Splunk: How Vodafone established Operational Analytics in a Hybrid Environmen...Splunk
 
SOC, Amore Mio! | Security Webinar
SOC, Amore Mio! | Security WebinarSOC, Amore Mio! | Security Webinar
SOC, Amore Mio! | Security WebinarSplunk
 
.conf Go 2022 - Observability Session
.conf Go 2022 - Observability Session.conf Go 2022 - Observability Session
.conf Go 2022 - Observability SessionSplunk
 
.conf Go Zurich 2022 - Keynote
.conf Go Zurich 2022 - Keynote.conf Go Zurich 2022 - Keynote
.conf Go Zurich 2022 - KeynoteSplunk
 
.conf Go Zurich 2022 - Platform Session
.conf Go Zurich 2022 - Platform Session.conf Go Zurich 2022 - Platform Session
.conf Go Zurich 2022 - Platform SessionSplunk
 
.conf Go Zurich 2022 - Security Session
.conf Go Zurich 2022 - Security Session.conf Go Zurich 2022 - Security Session
.conf Go Zurich 2022 - Security SessionSplunk
 

Más de Splunk (20)

.conf Go 2023 - Data analysis as a routine
.conf Go 2023 - Data analysis as a routine.conf Go 2023 - Data analysis as a routine
.conf Go 2023 - Data analysis as a routine
 
.conf Go 2023 - How KPN drives Customer Satisfaction on IPTV
.conf Go 2023 - How KPN drives Customer Satisfaction on IPTV.conf Go 2023 - How KPN drives Customer Satisfaction on IPTV
.conf Go 2023 - How KPN drives Customer Satisfaction on IPTV
 
.conf Go 2023 - Navegando la normativa SOX (Telefónica)
.conf Go 2023 - Navegando la normativa SOX (Telefónica).conf Go 2023 - Navegando la normativa SOX (Telefónica)
.conf Go 2023 - Navegando la normativa SOX (Telefónica)
 
.conf Go 2023 - Raiffeisen Bank International
.conf Go 2023 - Raiffeisen Bank International.conf Go 2023 - Raiffeisen Bank International
.conf Go 2023 - Raiffeisen Bank International
 
.conf Go 2023 - På liv og død Om sikkerhetsarbeid i Norsk helsenett
.conf Go 2023 - På liv og død Om sikkerhetsarbeid i Norsk helsenett .conf Go 2023 - På liv og død Om sikkerhetsarbeid i Norsk helsenett
.conf Go 2023 - På liv og død Om sikkerhetsarbeid i Norsk helsenett
 
.conf Go 2023 - Many roads lead to Rome - this was our journey (Julius Bär)
.conf Go 2023 - Many roads lead to Rome - this was our journey (Julius Bär).conf Go 2023 - Many roads lead to Rome - this was our journey (Julius Bär)
.conf Go 2023 - Many roads lead to Rome - this was our journey (Julius Bär)
 
.conf Go 2023 - Das passende Rezept für die digitale (Security) Revolution zu...
.conf Go 2023 - Das passende Rezept für die digitale (Security) Revolution zu....conf Go 2023 - Das passende Rezept für die digitale (Security) Revolution zu...
.conf Go 2023 - Das passende Rezept für die digitale (Security) Revolution zu...
 
.conf go 2023 - Cyber Resilienz – Herausforderungen und Ansatz für Energiever...
.conf go 2023 - Cyber Resilienz – Herausforderungen und Ansatz für Energiever....conf go 2023 - Cyber Resilienz – Herausforderungen und Ansatz für Energiever...
.conf go 2023 - Cyber Resilienz – Herausforderungen und Ansatz für Energiever...
 
.conf go 2023 - De NOC a CSIRT (Cellnex)
.conf go 2023 - De NOC a CSIRT (Cellnex).conf go 2023 - De NOC a CSIRT (Cellnex)
.conf go 2023 - De NOC a CSIRT (Cellnex)
 
conf go 2023 - El camino hacia la ciberseguridad (ABANCA)
conf go 2023 - El camino hacia la ciberseguridad (ABANCA)conf go 2023 - El camino hacia la ciberseguridad (ABANCA)
conf go 2023 - El camino hacia la ciberseguridad (ABANCA)
 
Splunk - BMW connects business and IT with data driven operations SRE and O11y
Splunk - BMW connects business and IT with data driven operations SRE and O11ySplunk - BMW connects business and IT with data driven operations SRE and O11y
Splunk - BMW connects business and IT with data driven operations SRE and O11y
 
Splunk x Freenet - .conf Go Köln
Splunk x Freenet - .conf Go KölnSplunk x Freenet - .conf Go Köln
Splunk x Freenet - .conf Go Köln
 
Splunk Security Session - .conf Go Köln
Splunk Security Session - .conf Go KölnSplunk Security Session - .conf Go Köln
Splunk Security Session - .conf Go Köln
 
Data foundations building success, at city scale – Imperial College London
 Data foundations building success, at city scale – Imperial College London Data foundations building success, at city scale – Imperial College London
Data foundations building success, at city scale – Imperial College London
 
Splunk: How Vodafone established Operational Analytics in a Hybrid Environmen...
Splunk: How Vodafone established Operational Analytics in a Hybrid Environmen...Splunk: How Vodafone established Operational Analytics in a Hybrid Environmen...
Splunk: How Vodafone established Operational Analytics in a Hybrid Environmen...
 
SOC, Amore Mio! | Security Webinar
SOC, Amore Mio! | Security WebinarSOC, Amore Mio! | Security Webinar
SOC, Amore Mio! | Security Webinar
 
.conf Go 2022 - Observability Session
.conf Go 2022 - Observability Session.conf Go 2022 - Observability Session
.conf Go 2022 - Observability Session
 
.conf Go Zurich 2022 - Keynote
.conf Go Zurich 2022 - Keynote.conf Go Zurich 2022 - Keynote
.conf Go Zurich 2022 - Keynote
 
.conf Go Zurich 2022 - Platform Session
.conf Go Zurich 2022 - Platform Session.conf Go Zurich 2022 - Platform Session
.conf Go Zurich 2022 - Platform Session
 
.conf Go Zurich 2022 - Security Session
.conf Go Zurich 2022 - Security Session.conf Go Zurich 2022 - Security Session
.conf Go Zurich 2022 - Security Session
 

Último

Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...
Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...
Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...Orbitshub
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FMESafe Software
 
Biography Of Angeliki Cooney | Senior Vice President Life Sciences | Albany, ...
Biography Of Angeliki Cooney | Senior Vice President Life Sciences | Albany, ...Biography Of Angeliki Cooney | Senior Vice President Life Sciences | Albany, ...
Biography Of Angeliki Cooney | Senior Vice President Life Sciences | Albany, ...Angeliki Cooney
 
Architecting Cloud Native Applications
Architecting Cloud Native ApplicationsArchitecting Cloud Native Applications
Architecting Cloud Native ApplicationsWSO2
 
[BuildWithAI] Introduction to Gemini.pdf
[BuildWithAI] Introduction to Gemini.pdf[BuildWithAI] Introduction to Gemini.pdf
[BuildWithAI] Introduction to Gemini.pdfSandro Moreira
 
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot TakeoffStrategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoffsammart93
 
Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...apidays
 
Corporate and higher education May webinar.pptx
Corporate and higher education May webinar.pptxCorporate and higher education May webinar.pptx
Corporate and higher education May webinar.pptxRustici Software
 
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...DianaGray10
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FMESafe Software
 
AWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of TerraformAWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of TerraformAndrey Devyatkin
 
Why Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businessWhy Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businesspanagenda
 
Boost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfBoost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfsudhanshuwaghmare1
 
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProduct Anonymous
 
"I see eyes in my soup": How Delivery Hero implemented the safety system for ...
"I see eyes in my soup": How Delivery Hero implemented the safety system for ..."I see eyes in my soup": How Delivery Hero implemented the safety system for ...
"I see eyes in my soup": How Delivery Hero implemented the safety system for ...Zilliz
 
Artificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : UncertaintyArtificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : UncertaintyKhushali Kathiriya
 
Spring Boot vs Quarkus the ultimate battle - DevoxxUK
Spring Boot vs Quarkus the ultimate battle - DevoxxUKSpring Boot vs Quarkus the ultimate battle - DevoxxUK
Spring Boot vs Quarkus the ultimate battle - DevoxxUKJago de Vreede
 
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...apidays
 
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWEREMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWERMadyBayot
 
Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...
Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...
Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...Zilliz
 

Último (20)

Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...
Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...
Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
 
Biography Of Angeliki Cooney | Senior Vice President Life Sciences | Albany, ...
Biography Of Angeliki Cooney | Senior Vice President Life Sciences | Albany, ...Biography Of Angeliki Cooney | Senior Vice President Life Sciences | Albany, ...
Biography Of Angeliki Cooney | Senior Vice President Life Sciences | Albany, ...
 
Architecting Cloud Native Applications
Architecting Cloud Native ApplicationsArchitecting Cloud Native Applications
Architecting Cloud Native Applications
 
[BuildWithAI] Introduction to Gemini.pdf
[BuildWithAI] Introduction to Gemini.pdf[BuildWithAI] Introduction to Gemini.pdf
[BuildWithAI] Introduction to Gemini.pdf
 
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot TakeoffStrategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
 
Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...
 
Corporate and higher education May webinar.pptx
Corporate and higher education May webinar.pptxCorporate and higher education May webinar.pptx
Corporate and higher education May webinar.pptx
 
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
 
AWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of TerraformAWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of Terraform
 
Why Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businessWhy Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire business
 
Boost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfBoost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdf
 
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
 
"I see eyes in my soup": How Delivery Hero implemented the safety system for ...
"I see eyes in my soup": How Delivery Hero implemented the safety system for ..."I see eyes in my soup": How Delivery Hero implemented the safety system for ...
"I see eyes in my soup": How Delivery Hero implemented the safety system for ...
 
Artificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : UncertaintyArtificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : Uncertainty
 
Spring Boot vs Quarkus the ultimate battle - DevoxxUK
Spring Boot vs Quarkus the ultimate battle - DevoxxUKSpring Boot vs Quarkus the ultimate battle - DevoxxUK
Spring Boot vs Quarkus the ultimate battle - DevoxxUK
 
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
 
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWEREMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
 
Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...
Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...
Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...
 

Splunk and Cisco UCS Breakout Session

  • 1. Robert Novak, Cisco Big Data Partner CSE March 2016 Splunk in the Cisco UCS Ecosystem How Cisco and its customers deploy, use, and scale Splunk environments with the Cisco Unified Computing System
  • 2. Who am I and why am I here? Today: Consulting Systems Engineer for Cisco’s Americas Partner Organization Focused on big data and analytics UNIX Sysadmin for ~20 years (retired) Full stack: servers, storage, network, coffee 149 to 149k person companies Sun, Nortel, 3PAR, Ebay, Trulia, Disney, etc “Big Data” herder since 2003 Hadoop admin (certifiable) since 2009 Cisco UCS C-Series admin since 2011 (early adopter!) Charter Cisco Champion, VMware vExpert since 2013 Blogger at rsts11.com and Cisco Blogs Tweeter at @gallifreyan and @rsts11
  • 3. Agenda • Hardware still matters! • How Cisco uses Splunk internally • How some of our customers use Splunk on UCS • Cisco integrations with Splunk • The Unified Computing System advantage • Learn More
  • 4. Hardware Still Matters A quick glance at infrastructure for Splunk
  • 5. Why does hardware still matter? 5 • Splunk will run on almost anything (even my laptop) • Standalone servers have lower admin overhead • Build up your clusters and you have to keep them consistent • Grow your data sources (and uses) and you have to add servers • Cluster constipation is bad, mmmkay?
  • 6. Why does hardware still matter? 6 • Cisco customer big data pools tend to grow 2-3x/year • Cisco customer IT staff doesn’t grow as fast • The Cisco Unified Computing System (UCS) provides scalable, repeatable, predictable, and manageable deployments across dozens to thousands of servers for any application deployment • Pallet to production in hours, not days or weeks • Deep engineering integration between Cisco and Splunk with tested and proven configurations More on this later…
  • 7. How Cisco Uses Splunk Part 1 Operational Analytics at Enterprise Scale within Cisco IT
  • 8. Big Data at a Big Customer: Cisco 8 • 10s of thousands of employees, contractors, devices • 100s of offices, business apps, audiences • Lots of data in lots of places • No one tool (not even Splunk) can do everything for everyone all the time • High volume, low value, low shelf life • Lancope, Hadoop feed into Splunk • Low to moderate volume, high value, (any) shelf life • Splunk on its own, sometimes with fronting dashboards • Additional visualizations with Platfora, Tableau, etc
  • 9. A closer look at Splunk within Cisco 9 • Customer for 7+ years, strategic partner for 3+ years • Geographically disparate data collection and analysis • Over 70 business applications/use cases across the company • Around 20 teams using Splunk including Cisco IT and CSIRT • Nearly 10x growth in search volume from 2014-2016
  • 10. 10 Indexers 16 Search Heads thanks to search head clustering in Splunk 6.3 47 Search Heads 20 Indexers Daily Indexing ~ 2TB 2014 2014 2015 2015 2015 Cisco’s IT Operations Evolving with Splunk Daily Indexing 300G 2010
  • 11. Splunk Searches – Daily Average 1. Interactive Searches = 55K+ 2. Scheduled Searches = 45K+ 3. Total Searches = 100K+ 4. Number of Users = 180+
  • 12.
  • 13.
  • 14. How Cisco Uses Splunk Part 2 Security Analytics at Enterprise Scale: Cisco’s Computer Security Incident Response Team (CSIRT)
  • 15. About CSIRT • Cisco Computer Security Incident Response Team (CSIRT) • CSIRT = Security Monitoring and Incident Response • Architecture, Engineering, Research, and Investigations • Enterprise global threat and 24x7 incident response
  • 16. CSIRT Environments Recent Snapshot  300 locations in 90 countries  400 buildings  1500+ labs  100,000+ employees on network  50-300 malware-related cases opened in a typical week  650,000+ ip devices on network  130,000 windows hosts  50,000 Linux hosts  40,000 routers  2-3 million highly tuned ids events per day  10+ billion netflow records per day
  • 17. Deploying Splunk as SIEM • SIEM: Security Information and Event Management platform – Easy to index any type of machine data from any source – Over 60 users doing investigations, correlations, reporting, advanced threat detection – All the data + flexible searches and reporting = empowered and effective team – 2TB/day and searches take less than a minute. 7 global data centers with 350TB stored data – Flashback Malware contained to a fraction of the environment – Replaced older pre-big-data SIEM  Previous solution didn’t scale effectively  Queries in the minutes (or worse) rather than seconds with Splunk  Diverse functionality across the same aggregate data
  • 18. Looking at our customers Successful deployments with Cisco UCS and Splunk
  • 19. Threat Management at Govt Agency 19 • Agency wanted to manage and monitor all relevant alert data • Needed visibility across multiple security platforms • Centralized on scalable appliance model through a partner • Splunk Enterprise with Enterprise Security[1] premium app • By deploying on Cisco UCS with proven Cisco Validated Design, partner was able to deliver easily upgraded and expanded deployment with predictable results [1] Splunk won Best SIEM Solution (Enterprise Security) and Best Fraud Prevention Solution (Splunk Enterprise) awards from SC Magazine this month (Splunk press release)
  • 20. Fraud prevention for Online School 20 • Leading online university needed to track student activity • Federal agencies have stringent requirements for loan qualifications and fulfillment • Deployed Splunk on UCS for student activity tracking • Blocking millions in fraudulent loan claims • Saving over 75% on auditing and compliance expenses • Saving over $1M/year on data processing • Deployed and expanded other analytics (security operations, IT operations, and application deployment) • Splunk on UCS grows beyond initial use cases and teams at most of our customers
  • 21. 21 • Leading worldwide financial services company used Splunk for IT Operations analytics • When an electronic payment platform deployment came up, Splunk was enlisted to support rollout and monitoring in ridiculously short time frame • Speed and scalability led to use cases for security and fraud detection/prevention, marketing optimization, customer engagement and offers, and more • Customer continues to grow their Splunk environment (over 10x in first year, and still growing!) IT Ops & beyond for financial services
  • 22. 22 • Customer needed quick updates, secure services, and high availability • Deployed Splunk Enterprise on UCS to replace older hardware and software platforms that didn’t scale well • Splunk and UCS delivered a more robust security posture with faster investigation and resolution of security events • High performance security analytics solution enables hospital to identify attack patterns and unauthorized actions that would otherwise go undetected. • Reduced space/power/cooling by 75% • Server deployment time reduced from 7 days to 1 day. See Cisco’s case study at cisco.com and Splunk’s case study at splunk.com Secure Healthcare at Union Hospital
  • 23. Got Cisco? There’s an app for that… (or a technology add-on, at least)
  • 24. CiscoSecuritySuiteApp Splunk & Cisco Integrations Security Identity Services Engine (pxGrid) Sourcefire (including AMP) ASA/PIX/FWSM Firewalls Web Security Appliance (WSA) Email Security Appliance (ESA) IPS Cloud Web Security (CWS) AnyConnect OpenDNS, ThreatGrid (in development) Data Center/ Insieme Cisco UCS Nexus 9K Application Centric Infrastructure (ACI - APIC) UCS Integrated Infrastructures Optimized for Splunk Enterprise High Performance High Capacity Enterprise Networking Switching and Routing Catalyst Switches Nexus (1000V, 2000, 3000, 4000, 5000, 6000, 7000, 9000) Meraki Wireless NGN Routers (CRS, ASR, ISR) Open SDN Network Controller APIC EM Collaboration Call Manager • Inaugural SIEM & Threat Defense Partner • Inaugural pxGrid partner • Inaugural member of new Cisco Security Technical Alliances program • Inaugural ACI Partner • Inaugural Data Analytics Partner • Cisco Cloud Security for VMDC 1.0 Design Guide (link) • Cisco UCS Integrated Infrastructure for Splunk Enterprise (Distributed Deployment, High Capacity) (link) CiscoNetworksApp
  • 25. Splunk App for Cisco UCS NEW AND IMPROVED as of May 28, 2016 Aggregates, monitors, trends and analyzes all relevant data from Cisco UCS Manager instances Enables proactive capacity and performance monitoring/ management, fault trending, power and cooling, and more Works with other Splunk add-ons and data sources (including Enterprise Security and PCI Compliance add-ons) to aggregate and correlate data across your enterprise 25 Application s Operating Systems Hypervisors UCS server, storage, network
  • 27. What is Cisco’s Unified Computing System (UCS)? Unified Management: UCS Manager uses policy-based configuration to ensure consistent deployments Unified Fabric: Integrated 10/40 Gigabit Ethernet and Storage Networking (FCoE/iSCSI) Service Profiles: Maintain consistency across batches of servers and multiple applications. Deploy and expand in record time. Performance: Built with 10GbE and 40GbE at the core, repeatable configurations and performance, and over 100 benchmark records
  • 28. Why Splunk on Cisco UCS? Time to Deployment: Spin up a mutually validated, pre-tested environment in hours rather than days or weeks Total Cost of Ownership: Integrated networking and management reduce customer cost and effort to migrate, deploy, and expand Time to Grow: Expand servers and network capacity quickly and consistently
  • 29. Cisco UCS + Splunk = Better Together Seamless Scalability Facilitates Rapid Growth – Scale Splunk from a single server to distributed/clustered deployment – Grow your clusters efficiently and consistently – Runs on the same UCS C-Series servers as other big data platforms Split Second Response Times – Exceptional performance for “needle-in-a-haystack” searches – Consistent performance as simultaneous users increase Simplified Repeatable Deployments – Four pre-tested UCS Integrated Infrastructures – Capacity or performance optimization – NEW! Cisco Validated Design (CVD) with HA and Archiving
  • 30. 250 GB indexed per day 4 months retention 250 GB indexed per day 1 month retention Single Server Cisco UCS Reference Architectures UP to 4TB indexed per day 3 months Retention Up to 4TB indexed per day 1 year Retention Clustered Deployment Retention optimized Performance optimized
  • 31. Cisco Validated Design (CVD) for Splunk • Developed by Cisco and Splunk engineers in Spring 2016 • 250+ page guide to design and deployment, pallet to production • Based on UCS C-Series (C220, C240, C3160) servers and Splunk Enterprise software • Includes high availability & data archiving • Download for free at cisco.com/go/bigdata_design
  • 32. Splunk on UCS : Performance Benchmark Test bed Topology
  • 33. Cisco UCS Benchmark Results (Splunk Enterprise 6.2 vs 6.3)
  • 34. Learn more about Splunk and Cisco UCS
  • 35. SplunkBase app resources: splunkbase.splunk.com Cisco’s Big Data Design Hub: cisco.com/go/bigdata_design features Cisco Validated Designs (CVDs) and other architectural docs Big Data Applications Hub: cisco.com/go/bigdata features reference architectures, solution briefs, infrastructure, automation, etc. Reach Out! Already using Splunk? Talk to your Splunk team about Cisco UCS! Already using Cisco UCS? Talk to your Cisco team about Splunk! Learn More About Splunk on Cisco UCS!
  • 36. Cisco’s CSIRT engineers applied their experiences during the CSIRT deployment to a new O’Reilly book now available bitly.com/infosecplaybook “they wrote the book …” 36

Notas del editor

  1. Cisco does servers? – quick answer Cisco does big data? – almost-as-quick answer What’s with Cisco and Splunk? – lead into next segment
  2. Cisco does servers? – quick answer Cisco does big data? – almost-as-quick answer What’s with Cisco and Splunk? – lead into next segment
  3. Cisco does servers? – quick answer Cisco does big data? – almost-as-quick answer What’s with Cisco and Splunk? – lead into next segment
  4. Cisco does servers? – quick answer Cisco does big data? – almost-as-quick answer What’s with Cisco and Splunk? – lead into next segment
  5. 10
  6. Snapshot from earlier this year but could have really been taken anytime. This shows the growth trend mentioned earlier Over 500 unique users per month
  7. A look at our pre 6.2 environment Initially a search head pool was deployed for each client team that was integrated. Which was fine in the beginning. 47 SHs and 12 SHPs Painpoints: An administration nightmare Resource availability – Lots of compute dedicated overall for search heads but not it’s not always available where needed
  8. Current 6.2 based setup was built side by side with the existing pre 6.2 environment SHPs Migrated each client team over one by one If we had kept out heads down and didn’t know of the new features we would have continued down the same path that lead to headaches And with that, back to Robert, TY!
  9. The Computer Security Incident Response Team (CSIRT) reduces the risk of loss as a result of security incidents for Cisco-owned business. CSIRT regularly engages in proactive threat assessment, mitigation planning, incident trending with analysis, security architecture, incident detection and response. CSIRT is our internal protection team within Cisco that protects the integrity of Cisco’s information, resources, ecommerce environment, TAC, etc.
  10. This is the scope of what the Cisco CSIRT team is protecting. We are BIG…and Splunk works well for us because it scales, is flexible and adaptable!!
  11. Easy to index any type of machine data coming in from anywhere 60 users 7x24 around the globe investigating and reporting Massive amounts of data combined with flexible searches empowered the team at Cisco 2TB a day and searches take less than a 1 minute. 25% cost – multi-purpose tool, its not a dedicated niche or point product, Cisco saves money, does SIEM’s + Much more (Swiss Army Knife – does many things). “We moved to Splunk from traditional SIEM as Splunk is designed and engineered for “big data” use cases. Our previous SIEM was not and simply could not scale to the data volumes we have” Former Director, Cisco Computer Security Incident Response Team Cisco’s footprint of security monitoring spans across our 7 global data centers with searches taking less than a minute. A search could be anything from known exploits to uncommon error messages.
  12. Cisco does servers? – quick answer Cisco does big data? – almost-as-quick answer What’s with Cisco and Splunk? – lead into next segment
  13. Cisco does servers? – quick answer Cisco does big data? – almost-as-quick answer What’s with Cisco and Splunk? – lead into next segment
  14. Cisco does servers? – quick answer Cisco does big data? – almost-as-quick answer What’s with Cisco and Splunk? – lead into next segment
  15. Cisco does servers? – quick answer Cisco does big data? – almost-as-quick answer What’s with Cisco and Splunk? – lead into next segment
  16. The key value proposition for Splunk App for Cisco UCS is that it aggregates, monitors, trends and analyzes all data from all UCS managers in one central location. We also explored the importance of correlation. With this app our customers are getting the Cisco UCS data into Splunk where they can analyze it along side other types of data to create various reports, of performance metrics, security, alerts and more Also, UCS has massive scalability and it generates lots of data. Therefore it requires analytics and monitoring solution that can scale to match. And Splunk uniquely fulfills this requirement. Finally our Splunk App for UCS is now certified by Cisco. Few months ago, they passed Cisco’s rigorous Interoperability and Verification Testing and now they can put a stamp UCS validated or Cisco Compatible. What does this mean for you, if you’re a Cisco shop you can now deploy the App without worry of interoperability or doing your own verification testing! Recap: UCS and most management tools generate point in time information. UCS’s massive scalability generates lots of data. Combine that with Converged Infrastructure logs, OS, vSphere, Nexus, etc. and try to correlate. Bottom Line: It requires an analytics and monitoring solution that can scale. Splunk is effectively the “Sherlock Holmes” of data analysis.
  17. Why is UCS so valuable in big data deployments? Most people talk about the hardware capabilities and even though we hold countless benchmark records, its not as important as policy based configurations and management. When you talk big data, you can get started with any hardware. If you have 10-12 machines, who cares what brand they are or if they are white box. If something goes wrong, you deal with it. But what happens when the environment grows? What happens when you have dozens or hundreds of servers? How do you manage the firmware revisions? What about the specific components which cause driver conflicts, or stack interoperability issues? Unified Management: You don’t manage the endpoints, you manage the UCS-M and it manages the endpoints: Chassis, Switches, Blades, Adapters Unified Fabric – FCoE!! Less infrastructure to manage as you don’t have Fibre Channel and Ethernet switches! Just like we combined the Voice and Data network 12+ years ago. Less gear, less expensive and easier to manage! Is there a potential for a use case in your organization where a few servers are needed to access the SAN? For example, backups? Maybe a need for Isilon? Did you plan for this change? Don’t worry. With UCS, use software to turn on the feature and you gain access to all the data on the SAN w/o having to crack open a box or run a cable or install a SAN switch. Do you suddenly need VLAN partitioning for firewalls, security etc? Many customers have a requirement for both an internal and external network on the same system. In the past, it was another cable, another card, and a reconfiguration of the OS. Instead, with Cisco, you just add this in UCS Manager.
  18. Cisco and Splunk provides an infrastructure solution which improves the time to deployment, reduces operations costs, while providing the capability to expand over time. TCO in terms of people supporting the environment, time to deployment, MTTR, etc. One large media company had to rethink their strategy once they realized OPEX was sapping their profitability. They started out with white box and grew to 1400 units. How many engineers do you think it took to support it? Would you believe 40! The next environment was UCS and they grew to 700 servers before that engineer came to work for Cisco. Those 700 servers were managed by 1 engineer!! Do you think your company can afford $4-$6m in people costs per year to manage a large big data infrastructure? You can buy a lot of technology for that! Let’s reiterate or summarize the key benefits of UCS and Splunk together. While the data volume grows tremendously, Splunk maintains control with reliable and repeatable performance.
  19. As mentioned, Splunk can be deployed on a single server to get started, but as organizations realize the value the value they can extract from data they have an insatiable appetite for more insights. They are sifting through massive volumes of data for fraud detection, digging through multiple data sources to identify the extent of a breach. As a result, we have customers indexing a TB of data a day keen to expand their data sources or change retention periods. As Splunk environments grow, infrastructure can easily become a growth inhibitor. - Because Splunk software can address a variety of use cases, you can start from virtually any line of business or department and grow the implementation to fit your needs. Customers that experience the most compelling ROI are the ones that realize that analyzing machine data provides insights for every part of the organization. For example, simply pulling in web data allows your: IT Operations & Applications teams to receive real-time information on how web infrastructure updates are working in production and resolve issues before they impact the customer Marketing team to gain insight into usage trends on your website, allowing them to deliver the most impactful campaigns Security team to identify the fingerprints of fraud and stop fraudulent activity before it impacts your company and customers Business Analysts to identify and understand issues such as shopping cart abandonment Why others (HP/Dell) cant compete against UCS: Central management, integrated networking (UCS 10 Gig built in) designed and documented so you don’t outgrow your network.
  20. Why start from scratch?! Use a Reference Architecture that our two companies have verified are tried, true and rock solid! These are the four reference architecture bundles that are available. For Example: If you’re looking more into transaction history you go with Higher Retention; but if you’re a Card Swiping company looking for fraud, then Performance is more important. Also to note: Customers are clamoring for Cisco Validate Designs (CVD). They are coming soon and the rough ETA is Late Spring 2016. (Over 220 pages!)
  21. We also have 3rd party validation with Cisco UCS – well known for high performance systems. Today, I’d like to share with you an early preview of Cisco’s ongoing benchmark tests. 1 – First off – data indexing results show that with 16 cores you can get 4x the throughput of 6.2 2 – Running searches with 4 cores show that you can get 6x or more the speed of 6.2 3 – A typical indexing + search workload shows that you can get 3x the search performance and twice the data indexing with 6.3 Bottom line –Splunk Enterprise is ready to put your available CPU power to work to get more done, faster Watch for more results and a full report from Cisco on the benchmark tests. System – single 36 core UCS Server. Note that there are 8 concurrent searches for the search results.
  22. Here is Splunk on Cisco Marketplace and the link for the reference architecture. Marketplace Includes: - Big Data/UCS Solutions - Splunk for Cisco Security Environments - Splunk for Cisco Security Suite - Cisco ACI for Splunk Enterprise - Splunk for Cisco Networks Reference Architecture Highlights - Comprehensive Integrated Infrastructure - Real-Time Operational Intelligence - Powerful Search, Analysis, and Visualization - Built on Cisco UCS Advantages - Architectural Scalability Come by the Cisco table to pick up the Reference Architecture Brief and enter yourself to win a Go Pro camera! Appreciate you hanging in there today! Thank you and let me not hold you back for cocktails.
  23. Cisco’s three lead engineers behind the Splunk deployment wrote the book, Crafting the Infosec (information security) Playbook. - Available end of May or early June. http://www.amazon.com/Crafting-InfoSec-Playbook-Security-Monitoring/dp/1491949406 by Jeff Bollinger (Author), Brandon Enright (Author), Matthew Valites (Author) Tim O’Reilly http://en.wikipedia.org/wiki/O%27Reilly_Media