  1. 1. Copyright © 2015 Splunk Inc. Splunk at Yodlee Akshay Sethi Performance and Service Architecture, Director
  2. 2. 2 About Yodlee •  Leading technology and applicaFons plaGorm powering digital financial services •  950 companies, including 12 of the largest US banks subscribe to the Yodlee plaGorm •  Yodlee soluFons transform financial innovaFon, improve digital customer experiences, and deepen customer engagement •  HQ in Redwood City, CA –  Global offices London and Bangalore
  3. 3. 3 About Me •  Akshay Sethi - Director of Performance and Service Architecture •  Manage the performance team, product tesFng, and performance tesFng •  Assist in service architecture design, requirements, and vendor assessment for all operaFons iniFaFves
  4. 4. 4 Before Splunk Expansion •  Every outage required searching through 20+ server logs to correlate events •  Event correlaFon took hours or longer •  Needed to enable the site reliability team responsible for producFon, upFme, and resiliency Needed to decrease MTTR
  5. 5. 5 Geng started with Splunk •  Started with a 50-100 gig license in ~2010 •  Teams began to realize the value of Splunk and was leveraged across teams •  Found value in log aggregaFon and search capabiliFes •  Started with troubleshooFng use cases “Teams realized the value of Splunk and started using it for projects!”
  6. 6. 6 Splunk Expansion "   Needed to expand Splunk usage to include all producFon server logs "   Data OperaFons team using splunk for troubleshooFng and data aggregaFons –  Comfortable and familiar with Splunk capabiliFes "   IdenFfied an opportunity to expand Splunk usage
  7. 7. The Splunk Advantage •  Tried a small POC with the ELK stack •  Retrieving, indexing, and structuring the data took a lot of effort •  Splunk out of the box was easy to get up and running •  Didn’t want 10 people implemenFng one soluFon •  Leveraged Splunk online tool for sizing number of disks and indexers needed for a given number of GB per day / retenFon period “When you include all the man hours of implemenFng a new soluFon, It made more sense to go with Splunk.”
  8. 8. Splunk at Yodlee •  Using Splunk for over 5 years •  Currently 700 Gig License •  Two teams using Splunk •  Data operaFons team •  Account AggregaFon team •  Data sources include Oracle DB Connector App, linux server and custom add logs •  Queries every minute, live dashboard and alerFng •  Currently monitoring 4-5 databases •  Currently monitoring 20 servers 8
  9. 9. Splunk as the core of the Yodlee PlaGorm •  No more manual grepping through logs aner applicaFon failures •  Planning to add JBOSS logs from producFon environment including access logs, server logs, and custom logs •  Plan to start to Splunking addiFonal DB connectors, and network logs •  Plan to monitor 150+ servers
  11. 11. Splunk as the core of the Yodlee PlaGorm “It doesn’t maper if it’s running across one server or 20 servers. As long as we have an idenFfier, Splunk can pull up all the logs related to that Fme relaFvely quickly.”
  12. 12. 12 ExecuFve Level ReporFng "   SLA reports, run access logs through Splunk to get execuFve summary "   Measure server response Fme "   Able to directly correlate informaFon with customer acFvity
  13. 13. 13 Splunk Enterprise Security "   Splunk Enterprise Security (ES) cluster separate from main cluster "   License of around 100 gigs "   Splunk use expanded to the security team "   Using ES for incident invesFgaFon and response, IPS ideas, and monitoring firewalls
  15. 15. 15 Key Take Aways ①  Splunk can be leveraged across mulFple teams ②  Started with the troubleshooFng use case and expanded into security, and monitoring producFon environments ③  Geng started with Splunk is easy!
  16. 16. 16 Best PracFces "   Learn from other users –  Splunk Lives –  .Conf –  Online EducaFon "   You don’t need a large team, but you need a plan –  Consider total cost of ownership of new tools
  17. 17. 17 What’s Next "   Currently seng up a new Splunk cluster with 7 indexers "   This cluster will process up to 800GB of data a day "   Need to add all the addiFonal data sources from all producFon servers and network devices "   Seng a separate and smaller Enterprise Security cluster for security monitoring
