+ All Categories
Home > Technology > SplunkLive! Warsaw 2016 - Splunk IT Service Intellience

SplunkLive! Warsaw 2016 - Splunk IT Service Intellience

Date post: 06-Jan-2017
Category:
Upload: splunk
View: 115 times
Download: 2 times
Share this document with a friend
46
Copyright © 2016 Splunk Inc. Splunk IT Service Intelligence Hans-Henning Gehrts
Transcript
Page 1: SplunkLive! Warsaw 2016 - Splunk IT Service Intellience

Copyright©2016SplunkInc.

SplunkITServiceIntelligenceHans-HenningGehrts

Page 2: SplunkLive! Warsaw 2016 - Splunk IT Service Intellience

WhatWeHearFromOurCustomers!

“MyCIOisdemandingwelookatITfromabusinessserviceperspective.”

“Splunkisgreatforbreak-fix,butIneedtoshowwe’remeetingSLAs.”

“Ineedeveryonetobeabletoseethesamethingatthesametime.”

“IjustwanttothrowdataatSplunkandhaveitfindproblemsforme.”

“Showmewhatmydatacandoforme!”

Page 3: SplunkLive! Warsaw 2016 - Splunk IT Service Intellience

RethinkingandImprovingHowITOperates

3

TraditionalIT Data-DrivenIT

• Structureddata• Brittletoolsandintegrations• Obsessionwith“faults”and“traps”• Focusoncomponentsparts• Searchoriented

• Structuredandunstructureddata• Robustdataintegrations• Real-timeinsightsfrombigdata• Focusonthewholeservice• Machinelearning-drivenanalytics

Page 4: SplunkLive! Warsaw 2016 - Splunk IT Service Intellience

4

WhatIsServiceIntelligence?

Enablingabusiness-awareITMeasuringandreportingonindicatorsthatmatter

UnlockingoperationalefficienciesCollaboratingacrosssilostoimproveserviceoperations

Data-baseddecisionmakingSolvingproblemsandanticipatingpitfallswithsophisticatedanalyticsandpowerfulinsights

Page 5: SplunkLive! Warsaw 2016 - Splunk IT Service Intellience

Machinelearning-poweredanalyticsforreal-timeserviceinsights,simplifiedoperationsandroot-causeisolation

Page 6: SplunkLive! Warsaw 2016 - Splunk IT Service Intellience

WhyAnotherSplunkSolution?

6

Adata-centricapproachisneeded

ServicecontextmaximizesSplunkvalue

Anintegratedsolutionacceleratescustomersuccess

Page 7: SplunkLive! Warsaw 2016 - Splunk IT Service Intellience

Splunk ITServiceIntelligenceMachineLearning-Powered,Analytics-DrivenITOperations

Simplifyserviceoperations

Prioritizeincidentswithcontext RedefinetheroleofIT

Combineevents&metricsacrosssiloswithease,flexibility&scaleindays

Unifysiloed monitoringLeveragemachinelearningtodetectanomalies&highlight

eventsthatmatter

Deliverbusiness&servicecontexttoprioritizeincidentinvestigation&action

Supportdecisions&communicateresultswithpowerfulservice-levelinsights

Page 8: SplunkLive! Warsaw 2016 - Splunk IT Service Intellience

KeyConcepts

Page 9: SplunkLive! Warsaw 2016 - Splunk IT Service Intellience

TerminologyMatters

9

Logicalgroupingofoperations

Onlinebanking,authentication,virtualization

EXAMPLES

SERVICES

Setofactionsperformedwith

specificbusinessgoals

Sellproducts,fulfillorders,processpayroll

EXAMPLES

BUSINESSPROCESSES

Componentrequiredtodeliveraservice

Hosts,users,

OSprocesses

EXAMPLES

ENTITIES

Metricsusedtoevaluatesuccess

Servicehealth,orderrevenue,

latency

EXAMPLES

KEYPERFORMANCEINDICATORS

Page 10: SplunkLive! Warsaw 2016 - Splunk IT Service Intellience

SplunkITServiceIntelligence– CoreConcepts

Service RequestsResponses

Web

TechnicalServices Services

RequestsResponses

MobileAPI/Middleware

RequestsResponses

DNSSupportDesk Requests

Responses

CustomerTransactions

RequestsResponses

BusinessServices

Page 11: SplunkLive! Warsaw 2016 - Splunk IT Service Intellience

PacketNetwork

HypervisorandHosts

RDBMSs

StorageTier

APIServices

WebServices InSplunkITSI,aservice isalogicalgroupoftechnologycomponentsthatauser

deemsneedtobemonitoredtogether

ITServiceIntelligence– CoreConcepts

Service RequestsResponses

Web

TechnicalServices Services

CustomerTransactions

Web

CustomerTransactions

RequestsResponses

BusinessServices

Mobile

API/Middlew

are

SupportDesk

DNS

Page 12: SplunkLive! Warsaw 2016 - Splunk IT Service Intellience

ITServiceIntelligence– CoreConcepts

Service RequestsResponses

Web

TechnicalServices

PacketNetwork

HypervisorandHosts

RDBMSs

StorageTier

APIServices

WebServices

Web

NumberofrequestsErrorrateAverageresponsetimeServicerCPUloadServernetworkI/Ferrors

KPIs

KPIsandhealthscoresconstitutethemeansbywhichservicesare

monitored

HealthScore

Page 13: SplunkLive! Warsaw 2016 - Splunk IT Service Intellience

DefininganEntity

13

Anentity isanoptionalsub-elementofaKPI.

AKPIcanbefilteredbyentitiesandviewedonaper-entitybasisorasanaggregate.

TheKPIWebRequestsmightusewebserversasentities;UserLogins coulduseaccounts.

SplunkITSIcanimportentitiesfromCMDBs&othersources.

Page 14: SplunkLive! Warsaw 2016 - Splunk IT Service Intellience

ServiceHealthScores

14

Ahealthscoreisrankedfrom0-100(0=criticaland100=normal)thathelpsdeterminethehealthofaservice.

Itiscalculatedbasedonimportanceandstatus(e.g.,green,orange,red)ofallKPIs,onceeveryminute.

Page 15: SplunkLive! Warsaw 2016 - Splunk IT Service Intellience

SplunkITSIDemo

Page 16: SplunkLive! Warsaw 2016 - Splunk IT Service Intellience

PersonalizedVisualizationsofYourServices

• Visualizecontextualinter-relationshipsacrossservicedeliverycomponents

• Illustratebusinessandserviceactivityusingindicatorsalignedwithstrategicgoals

• Drivedecisionsbymonitoringservicehealthagainstperformanceindicators

• Createsophisticateddashboardsinminutes

16

Page 17: SplunkLive! Warsaw 2016 - Splunk IT Service Intellience

OrganizedViewofPerformanceIndicators

17

• OrganizeandcorrelateKPIstospeedupinvestigationsanddiagnosis

• Compareperformanceovertimeandinrealtimetounderstandtrendsandidentifysystemicissues

• Enablebroadanddeepinvestigationwithcontextualdrill-downs

Page 18: SplunkLive! Warsaw 2016 - Splunk IT Service Intellience

Real-TimeViewofServiceandKPIHealthScores

• GetearlywarningofemergingincidentswithaheatmapofservicehealthandKPIscores,metrics,sparklines andalerts

• Drilldownintoserviceandentitydetailsforin-depthtriage

18

Page 19: SplunkLive! Warsaw 2016 - Splunk IT Service Intellience

InsightsIntotheOriginofServiceDisruptions

19

Profileanentitytotroubleshootoutagesandservicedegradations

IdentifycontributingservicesandentitiesoftheworstperformingKPIs

Page 20: SplunkLive! Warsaw 2016 - Splunk IT Service Intellience

CorrelationRulesGenerateMeaningfulEvents

20

Runpredefinedcorrelationsearchesagainstlearnedindicatorstogeneratenotableeventsbasedonstatusandcompositescores

Page 21: SplunkLive! Warsaw 2016 - Splunk IT Service Intellience

SophisticatedEventAnalytics

21

• Reduceeventclutterandfalsepositiveswithmultivariateanomalydetection

• Automaticallyconcealduplicateeventstofocusonrelevantevents

• Easilysiftthroughvastamountsofeventsbyfiltering,taggingandsorting

• Enrichandaddcontexttoeventstomakeitinformativeandactionable

Page 22: SplunkLive! Warsaw 2016 - Splunk IT Service Intellience

IntegrateWithExistingIncidentWorkflows

22

Automaticallyinitiatedefinedincidentandremediationresponses

IntegratewithServiceNowtocreateticketsandacceleratetriage

Page 23: SplunkLive! Warsaw 2016 - Splunk IT Service Intellience

DeepService-OrientedInsightsIntoTechnologyDomains

● Extendout-of-the-boxfunctionalitybyeasilyintegratingwithopensourceand3rd-partytechnologiesandtools

23

• Fast-trackdatacollectionwithoutcostlyadd-ons,customizationsandmanualconfigurations

• Gaindeepservice-orientedinsightswithbuilt-indashboards

• Simplifycreationanddeploymentofthird-partyandcustommodules

Page 24: SplunkLive! Warsaw 2016 - Splunk IT Service Intellience

LearnWhat’sNormalandAbnormal

24

Baselinenormaloperationsandalertonanomalousconditions

IdentifyabnormaltrendsandpatternsinKPIdata

Page 25: SplunkLive! Warsaw 2016 - Splunk IT Service Intellience

BaselineTrendstoAdaptThresholds

25

UsestatisticstodynamicallyadaptKPIthresholdsbytime

MaintainandpreservelearnedthresholdstomonitorKPIandservicebehavior

Page 26: SplunkLive! Warsaw 2016 - Splunk IT Service Intellience

ReducetheAdministrativeHurdle

26

Enablemasschangestothresholdsandsearcheswithtemplates,reducingthenumberofsearchesandimprovingperformance

Setservicesandentitiesinto“maintenance”tosuppressalertsandaccuratelyreflecthealthscores

CreatehighlyavailableSplunkITSIenvironments,revertconfigurationstopreviousversionsandensurecontinuousdelivery

ManagepermissionsandauthorizeaccesstovariousviewswithinSplunkITSI

FASTSEARCHPERFORMANCE

MAINTENANCEWINDOWS

BACKUPANDRESTORE

ROLE-BASEDACCESSCONTROLS

Page 27: SplunkLive! Warsaw 2016 - Splunk IT Service Intellience

WhatMakesSplunkITSIDifferent

27

Search-BasedKPIs• Easytowrite,manageandchangebothservicesandKPIs

• Reflects businessandtechnologypriorities

• Benefit:RapidlygenerateandchangeKPIstoalignservicehealthwithbusiness

• Fiserv – 1000sinjustweeks

FullFidelityServiceHealth

• Adaptableandflexibledefinitionsofservicehealth

• Onesolutiontogoseamlesslyfromservicereportstorootcause, includingrawdata

• Remainsadaptableandyetstillmaintainscompletehistoricalcontext

UniversalDataPlatform

• Datadriven:AllITdataincludingevents,metricsandlogs

• Schemaon-the-Fly• Askanyquestionofthedata

• Fasttime-to-value

• Datafidelity

Page 28: SplunkLive! Warsaw 2016 - Splunk IT Service Intellience

CaseStudies

Page 29: SplunkLive! Warsaw 2016 - Splunk IT Service Intellience

Real-TimeCarAuctionsDeliveredWithIntelligence

29

Reducedtime-to-investigateandresolutionwithreal-timeinsights

Reducedincidentsacrossglobal

auctionsby90%

Improvedend-userexperienceandservicereliability

“WithSplunkITSI,wehaveproactiveinfrastructuremonitoringtoensureaconsistentlevelofcustomerserviceforinterestedbuyerstobidoncars.”

– KenGavranovic,VPTechnologyApplicationDevelopment&Operations,CoxAutomotive

Scalingtheimplementationwith

SplunkCloud

Page 30: SplunkLive! Warsaw 2016 - Splunk IT Service Intellience

SplunkITServiceIntelligenceat

30

Replacedhome-growntools

Providedreal-timeserviceinsights toLOBs

Reducedtime-to-resolution

Page 31: SplunkLive! Warsaw 2016 - Splunk IT Service Intellience

ImprovedSatelliteOperationsWithReal-TimeInfrastructureVisibility

31

“UsingSplunkITSIhashelpedustounderstandourITnetworkinawayweweren’tabletopreviously.Thishasdirectlyledtoimprovementsinareassuchastroubleshootingandsecurityawareness.”

– DanielNye,CTO,SurreySatellite

Improvedserviceaccessibility,reliabilityandsecurity

Enhancedabilitytotroubleshootpersistentserviceproblems

Gainedend-to-endvisibilityintooverallITperformance

Page 32: SplunkLive! Warsaw 2016 - Splunk IT Service Intellience

ModernizingEnterpriseMonitoringattheInternationalWorldDevelopmentBank

● Enhancedservicereliabilityandincidentresponse

● Easeandflexibilityincreatingbusinessleveldashboardsadhocandon-the-fly

● IntegrationswithBMCRemedytosimplifyincidentresponseandaction

● Tracingbusinesstransactionsendtoend

32

Page 33: SplunkLive! Warsaw 2016 - Splunk IT Service Intellience

Supporting,MonitoringandSecuringServices24/7

33

REDUCETIME-TO-RESOLUTION

ConsolidatedservicesviewacrossentireITinfrastructure

IDENTIFYANOMALOUSACTIVITYANDENSURE

GOVERNANCE

Adaptivethresholdsandalertsimprovesecurityposture

PROACTIVELYIMPROVECUSTOMEREXPERIENCE

Comprehensiveanalyticstoreduceservicedisruption

Page 34: SplunkLive! Warsaw 2016 - Splunk IT Service Intellience

34

Unifiedinsights:dataintegrationsfromothertools

11,000to100s

Reducedincidenttickets

AlertingonserviceKPI’sinsteadof

serverperformance

Usagebaselinestoidentifyanomalies

SplunkITServiceIntelligenceat

Page 35: SplunkLive! Warsaw 2016 - Splunk IT Service Intellience

35

Server-basedtoservices-basedmonitoring

Top-downanddeep-diveservice

insights

200+servicesand1,500+KPIsmonitored

FlexiblecreationandmodificationofservicesandKPIs

AlertingonserviceKPIsinsteadof

serverperformance

Real-time,holisticandproactive“client”view

Splunk ITServiceIntelligenceat

Page 36: SplunkLive! Warsaw 2016 - Splunk IT Service Intellience

SplunkITServiceIntelligenceData-drivenservicemonitoringandanalytics

36

SPLUNKITSERVICEINTELLIGENCE

Time-SeriesIndex

PlatformforMachineData

DynamicServiceModels

Schema-on-Read DataModel CommonInformationModel

At-a-GlanceProblemAnalysis

EarlyWarningonDeviations EventAnalytics SimplifiedIncident

Workflows

Page 37: SplunkLive! Warsaw 2016 - Splunk IT Service Intellience

Strategic,business-centric

viewofIT

AcceleratedvalueforIT

Data-centricapproachto

servicemapping

SplunkITServiceIntelligence

Page 38: SplunkLive! Warsaw 2016 - Splunk IT Service Intellience

HowDoYouGetSplunkITSI?

38

ONLINESANDBOX TRIAL

7daysofaccesstoafree,personalenvironmentinthecloud,with

prepopulateddata

Engageinaproof-of-concepttoindexyourdataandexperience

Splunk ITSI

Page 39: SplunkLive! Warsaw 2016 - Splunk IT Service Intellience

Splunk-SponsoredGuidedWorkshop

39

Definemethodsfor:

• Proactiveservicemonitoring

• Reducedriskandfailures

• Fasterissueresolution

• Increasedbusiness

performance

Whatisit?

• 1-dayon-siteworkshop

• Tightlylinkedwithvalue

• Collaborativeapproach

• BuildyourownSplunkITSI

GlassTable

Page 40: SplunkLive! Warsaw 2016 - Splunk IT Service Intellience

ThankYou

Page 41: SplunkLive! Warsaw 2016 - Splunk IT Service Intellience

Backup

Page 42: SplunkLive! Warsaw 2016 - Splunk IT Service Intellience

AugmentConventionalMonitoring

SplunkITServiceIntelligence

APM NPM Operations&InfraMgmt. DomainTools

DeliverInsightsBasedonIntegratedData,NotIntegratedProducts

Page 43: SplunkLive! Warsaw 2016 - Splunk IT Service Intellience

43

SplunkITServiceIntelligence

Getdata Defineservices,entitiesandKPIs

Monitorandtroubleshoot

Analyzeanddetect

Data-Defined,Data-DrivenServiceInsights

Page 44: SplunkLive! Warsaw 2016 - Splunk IT Service Intellience

Pricing

Page 45: SplunkLive! Warsaw 2016 - Splunk IT Service Intellience

Splunk Enterpriseor Splunk Cloud

SplunkITSI

Splunk ITSI

45

Page 46: SplunkLive! Warsaw 2016 - Splunk IT Service Intellience

VolumeDiscountsBuiltIn

46

DailyPeakIndexingVolume (GB)

SplunkITServiceIntelligence

$/GB Built-inVolumeDiscount

1 $5,000 $5000

2 $7,500 $3750 25%

5 $12,500 $2500 50%

10 $18,000 $1800 64%

20 $27,000 $1350 73%

50 $47,500 $950 81%

100 $60,000 $600 88%

200 $90,000 $450 91%

500 $162,500 $325 93.5%

1000 $300,000 $300 94%


Recommended