Splunk	
  Live!	
  2015	
  
	
  
Simon	
  O’Brien	
  
Senior	
  Sales	
  Engineer	
  
Splunk	
  Cloud	
  SME	
  -­‐	
  APAC	
  
SPLUNK	
  CLOUD	
  
Agenda	
  
●  Splunk	
  Cloud	
  requirements	
  –	
  through	
  our	
  customers	
  eyes	
  
●  Splunk	
  Cloud	
  Strategy	
  
●  Concepts	
  and	
  components	
  of	
  the	
  plaHorm	
  
●  Customer	
  references	
  
●  Technical	
  overview	
  of	
  the	
  plaHorm	
  
●  Q&A	
  
Cloud	
  and	
  Your	
  Business	
  
3
Apps and data
moving to cloud
Cloud data should
remain in cloud
No data
silos
Desire to consume
Splunk as a service
Opera:onal	
  Intelligence	
  in	
  the	
  cloud	
  
4
Customer	
  requirements:	
  
•  Allow	
  me	
  visibility	
  regardless	
  of	
  workload	
  locaNon	
  
•  Meet	
  my	
  financial	
  requirements	
  –	
  capex	
  vs	
  opex	
  
•  Meet	
  my	
  security	
  requirements	
  –	
  confidenNal	
  and	
  available	
  
•  Incorporate	
  my	
  mobile	
  strategy	
  
•  Facilitate	
  my	
  big	
  data	
  strategy	
  
•  Increase	
  my	
  visibility	
  into	
  my	
  current	
  cloud	
  workloads	
  
	
  
5
Splunk	
  Cloud	
  Strategy	
  
Become	
  the	
  
Standard	
  for	
  
Opera:onal	
  
Intelligence	
  in	
  	
  
the	
  Cloud	
  	
  
Deliver	
  an	
  enterprise-­‐ready	
  	
  
cloud	
  service	
  
Deliver	
  a	
  feature	
  rich	
  
SaaS	
  plaGorm	
  
Deliver	
  low-­‐fric:on	
  customer	
  
experience	
  
Splunk	
  Cloud	
  –	
  Enterprise	
  Ready	
  Service	
  
6
Industry-­‐leading	
  
scalability	
  &	
  
flexibility	
  
Architected	
  for	
  
up:me	
  &	
  
performance	
  	
  
100%	
  Up:me	
  SLA	
  
Isolated	
  environments	
  
Robust	
  
enterprise	
  
security	
  
5GB/day	
  -­‐	
  10TB/day	
  plans	
  
Up	
  to	
  10x	
  data	
  burs:ng	
  
No	
  data	
  co-­‐mingling	
  
SOC	
  2	
  Type	
  2	
  aXesta:on	
  
Splunk	
  Cloud	
  service	
  monitored	
  using	
  Splunk	
  Enterprise	
  
Splunk	
  Cloud	
  –	
  Feature	
  Rich	
  SaaS	
  PlaGorm	
  
7
Full	
  power	
  
of	
  Splunk	
  
Enterprise	
  
Access	
  to	
  
700+	
  apps	
  
Single	
  pane	
  
of	
  glass	
  
visibility	
  
Industry-­‐leading	
  SaaS	
  PlaGorm	
  for	
  Opera:onal	
  Intelligence	
  
8
Splunk	
  Cloud	
  –	
  Built	
  for	
  Low	
  Fric:on	
  
Accelerated	
  
:me-­‐to-­‐value	
  
and	
  faster	
  ROI	
  
AXrac:ve	
  star:ng	
  plans	
  
Splunk	
  Online	
  Sandbox	
  
Immediate	
  Deployment	
  
Opera:onal	
  Capabili:es	
  Delivering	
  100%	
  Up:me	
  
9
Constant	
  Monitoring	
   Automated	
  fail-­‐over	
  
HA	
  across	
  mul:ple	
  
AWS	
  availability	
  zones	
  
Vulnerability	
  scanning	
  
Splunk	
  on	
  Splunk	
   Proac:ve	
  response	
  
Search Head(s)
Indexer(s)
Search Head(s)
Indexer(s)
On Premises Private Cloud Public Cloud On Premises Private Cloud Public Cloud
Hybrid Search
Search Head(s)
Indexer(s)
Search Head(s)
Indexer(s)
On Premises Private Cloud Public Cloud On Premises Private Cloud Public Cloud
Single Pane of Glass Visibility
Forward data
Search
Monitor
Get value fast
What You Do
Hardware setup
Storage
Scaling
Monitoring
What We Do
Who	
  does	
  What	
  
Customer	
  Breadth	
  	
  
14
Financial	
  Services	
  
Public	
  Sector	
  
Healthcare	
  
Consumer	
  Brands	
  
Online	
  Services	
  
Technology	
  	
  
	
  
5GB/day	
  –	
  12TB/day	
  	
  
Startups	
  –	
  Global	
  
Enterprises	
  	
  
Industries	
  /	
  Ver:cals	
   Deployments	
  
Organiza:on	
  Size	
  
What	
  Customers	
  
are	
  Saying	
  
Delivering	
  Security	
  Insights	
  at	
  FINRA	
  
16
" Splunk	
  Cloud	
  used	
  as	
  a	
  Big	
  Data	
  security	
  soluNon	
  	
  
"   Leveraging	
  the	
  Splunk	
  App	
  for	
  AWS	
  
	
  
“Splunk	
  Cloud	
  gives	
  you	
  
applicaNons	
  which	
  let	
  you	
  	
  
get	
  huge	
  amounts	
  of	
  	
  
value	
  from	
  your	
  data.”	
  
Delivering	
  Business	
  Insights	
  at	
  MindTouch	
  
17
Splunk	
  Cloud	
  used	
  across	
  the	
  organizaNon	
  for:	
  	
  
"   Real-­‐Nme	
  monitoring	
  and	
  troubleshooNng	
  	
  
"   Business	
  analyNcs	
  	
  
"   Customer	
  support	
  	
  
“The	
  enNre	
  process	
  to	
  implement	
  
Splunk	
  Cloud	
  	
  
was	
  painless.	
  Splunk	
  Cloud	
  	
  
is	
  now	
  100%	
  visible	
  in	
  the	
  
company,	
  across	
  execuNves,	
  
markeNng	
  and	
  IT.”	
  	
  	
  
Delivering	
  Real-­‐:me	
  Monitoring	
  at	
  Backupify	
  
18
Splunk	
  Cloud	
  used	
  by	
  DevOps	
  for:	
  	
  
"   ProducNon	
  system	
  monitoring	
  	
  
"   ApplicaNon	
  debugging	
  	
  
"   Customer	
  service	
  	
  
“Splunk	
  Cloud	
  saved	
  us	
  months	
  
of	
  development	
  	
  
Nme	
  and	
  we	
  esNmate	
  a	
  	
  
60-­‐70%	
  reducNon	
  	
  
in	
  producNon	
  	
  
troubleshooNng	
  Nme.”	
  
TECHNICAL	
  
DISCUSSION	
  
Dedicated	
  Deployments	
  
Clustered	
  Indexers	
  &	
  
Search	
  Heads	
  
MulNple	
  Data	
  Centers	
  
ProacNve,	
  conNnuous	
  
monitoring	
  
OrchestraNon	
  Layer	
  
MulN-­‐region	
  OperaNons	
  
Processes	
  for	
  data	
  and	
  
customer	
  protecNon	
  
SSL	
  EncrypNon	
  
EncrypNon	
  of	
  data	
  at	
  rest	
  
Splunk	
  Cloud	
  –	
  Technical	
  Overview	
  
Opera:onal	
  	
  
Excellence	
  
Security	
   Support	
  
Enterprise	
  grade	
  support	
  
Same	
  support	
  teams	
  and	
  
processes	
  as	
  Splunk	
  
Enterprise	
  
Architecture	
  
20
How	
  it	
  Works	
  
Splunk	
  Cloud	
  
Datacenter	
  
Private	
  Cloud	
  
Public	
  Cloud	
  
•  Dedicated	
  Deployments	
  in	
  AWS	
  
•  ConNnuously	
  Monitored	
  
•  Forwarders	
  collect	
  all	
  
machine	
  data	
  
•  Compression	
  and	
  
EncrypNon	
  
•  Fault	
  tolerant	
  
persistent	
  queues	
  
21
 
	
  Architecture Diagram
Customer	
  Stack	
  
Opera:onal	
  Monitoring	
  
Users	
  Searching	
  
via	
  HTTPS	
  
Forwarders	
  	
  
over	
  SSL	
  
S3	
  backup	
  
Orchestra:on	
  Layer	
  
•  Chef	
  
•  Ansible	
  
•  Jenkins	
  
Amazon	
  VPC	
  
22
Mul:-­‐AZ,	
  
Clustered	
  Search	
  Heads	
  
Mul:-­‐AZ,	
  Clustered	
  	
  
Indexers	
  
…	
  
Master	
  Nodes	
  
…	
  
Behind-­‐firewall	
  
Forwarder	
  
Management	
  
Splunk	
  Cloud	
  –	
  Data	
  Inputs	
  
Scripted/Modular	
  inputs	
  Syslog/TCP/UDP	
  Local	
  /	
  CIFS	
  files	
  Rest-­‐API	
  
23
Universal	
  or	
  Heavy	
  forwarder	
  
Combine	
  with	
  Any	
  Exis:ng	
  Data	
  Sources	
  
On-­‐Premises	
  Modular	
  Inputs	
  DB	
  Connect	
  Hadoop	
  Connect	
  
24
Any	
  Data	
  Input	
  Correlated	
  with	
  Exis:ng	
  Data	
  Sources	
  	
  
Scripted/Modular	
  inputs	
  TCP/UDP	
  Local	
  files	
  Rest-­‐API	
  
25
Universal	
  or	
  Heavy	
  forwarder	
  
Security	
  &	
  Compliance	
  
"   SOC2	
  type	
  2	
  adested	
  
"   Data	
  confidenNality	
  (data	
  at	
  rest*)	
  
"   Role	
  Based	
  Access	
  Controls	
  
"   Private,	
  dedicated	
  instances	
  
"   IDS	
  Monitoring	
  
"   ConNnuous	
  vulnerability	
  scanning	
  
26
 
	
  Encryption at Rest Diagram
Users	
  Searching	
  
via	
  HTTPS	
  
Forwarders	
  	
  
over	
  SSL	
  
Your	
  VPC	
  
27
Mul:-­‐AZ,	
  
Clustered	
  Search	
  Heads	
  
Mul:-­‐AZ,	
  Clustered	
  	
  
Indexers	
  
…	
  
Master	
  Nodes	
  
…	
  
Behind-­‐firewall	
  
Forwarder	
  
Management	
  
Splunk	
  Cloud	
  VPC	
  
VPC	
  Peering	
  
(OpNonal)	
  
V	
  V	
  
V	
  
V	
  
V	
  
Vormetric	
  	
  
DSM	
  
(OpNonal)	
  
Vormetric	
  	
  
DSM	
  
(OpNonal)	
  
 
	
  
28
Support Coverage
	
  
	
  
Resources	
  :	
  
•  Americas	
  
•  EMEA	
  	
  
•  APAC	
  	
  
•  SLA’s	
  offered	
  are	
  the	
  same	
  as	
  Splunk	
  
Enterprise	
  
•  Splunk	
  support	
  escalates	
  to	
  Splunk	
  
Cloud	
  Ops	
  where	
  required	
  
•  24	
  hour	
  follow	
  the	
  sun	
  model	
  
	
  
	
  
Splunk	
  Cloud	
  –	
  key	
  takeaways	
  
•  Built	
  using	
  best	
  pracNces	
  –	
  maintained	
  by	
  the	
  experts
•  Instantly	
  available	
  
•  Hybrid	
  search	
  capability	
  
•  Following	
  Industry	
  standard	
  SOC2	
  compliance	
  
•  We	
  stand	
  behind	
  our	
  service	
  (100%	
  SLA)	
  
29
QUESTIONS?	
  
	
  
THANKS!	
  
SOBRIEN@SPLUNK.COM	
  

Splunk Cloud

  • 1.
    Splunk  Live!  2015     Simon  O’Brien   Senior  Sales  Engineer   Splunk  Cloud  SME  -­‐  APAC   SPLUNK  CLOUD  
  • 2.
    Agenda   ●  Splunk  Cloud  requirements  –  through  our  customers  eyes   ●  Splunk  Cloud  Strategy   ●  Concepts  and  components  of  the  plaHorm   ●  Customer  references   ●  Technical  overview  of  the  plaHorm   ●  Q&A  
  • 3.
    Cloud  and  Your  Business   3 Apps and data moving to cloud Cloud data should remain in cloud No data silos Desire to consume Splunk as a service
  • 4.
    Opera:onal  Intelligence  in  the  cloud   4 Customer  requirements:   •  Allow  me  visibility  regardless  of  workload  locaNon   •  Meet  my  financial  requirements  –  capex  vs  opex   •  Meet  my  security  requirements  –  confidenNal  and  available   •  Incorporate  my  mobile  strategy   •  Facilitate  my  big  data  strategy   •  Increase  my  visibility  into  my  current  cloud  workloads    
  • 5.
    5 Splunk  Cloud  Strategy   Become  the   Standard  for   Opera:onal   Intelligence  in     the  Cloud     Deliver  an  enterprise-­‐ready     cloud  service   Deliver  a  feature  rich   SaaS  plaGorm   Deliver  low-­‐fric:on  customer   experience  
  • 6.
    Splunk  Cloud  –  Enterprise  Ready  Service   6 Industry-­‐leading   scalability  &   flexibility   Architected  for   up:me  &   performance     100%  Up:me  SLA   Isolated  environments   Robust   enterprise   security   5GB/day  -­‐  10TB/day  plans   Up  to  10x  data  burs:ng   No  data  co-­‐mingling   SOC  2  Type  2  aXesta:on   Splunk  Cloud  service  monitored  using  Splunk  Enterprise  
  • 7.
    Splunk  Cloud  –  Feature  Rich  SaaS  PlaGorm   7 Full  power   of  Splunk   Enterprise   Access  to   700+  apps   Single  pane   of  glass   visibility   Industry-­‐leading  SaaS  PlaGorm  for  Opera:onal  Intelligence  
  • 8.
    8 Splunk  Cloud  –  Built  for  Low  Fric:on   Accelerated   :me-­‐to-­‐value   and  faster  ROI   AXrac:ve  star:ng  plans   Splunk  Online  Sandbox   Immediate  Deployment  
  • 9.
    Opera:onal  Capabili:es  Delivering  100%  Up:me   9 Constant  Monitoring   Automated  fail-­‐over   HA  across  mul:ple   AWS  availability  zones   Vulnerability  scanning   Splunk  on  Splunk   Proac:ve  response  
  • 10.
    Search Head(s) Indexer(s) Search Head(s) Indexer(s) OnPremises Private Cloud Public Cloud On Premises Private Cloud Public Cloud
  • 11.
    Hybrid Search Search Head(s) Indexer(s) SearchHead(s) Indexer(s) On Premises Private Cloud Public Cloud On Premises Private Cloud Public Cloud Single Pane of Glass Visibility
  • 12.
    Forward data Search Monitor Get valuefast What You Do Hardware setup Storage Scaling Monitoring What We Do
  • 13.
  • 14.
    Customer  Breadth     14 Financial  Services   Public  Sector   Healthcare   Consumer  Brands   Online  Services   Technology       5GB/day  –  12TB/day     Startups  –  Global   Enterprises     Industries  /  Ver:cals   Deployments   Organiza:on  Size  
  • 15.
  • 16.
    Delivering  Security  Insights  at  FINRA   16 " Splunk  Cloud  used  as  a  Big  Data  security  soluNon     "   Leveraging  the  Splunk  App  for  AWS     “Splunk  Cloud  gives  you   applicaNons  which  let  you     get  huge  amounts  of     value  from  your  data.”  
  • 17.
    Delivering  Business  Insights  at  MindTouch   17 Splunk  Cloud  used  across  the  organizaNon  for:     "   Real-­‐Nme  monitoring  and  troubleshooNng     "   Business  analyNcs     "   Customer  support     “The  enNre  process  to  implement   Splunk  Cloud     was  painless.  Splunk  Cloud     is  now  100%  visible  in  the   company,  across  execuNves,   markeNng  and  IT.”      
  • 18.
    Delivering  Real-­‐:me  Monitoring  at  Backupify   18 Splunk  Cloud  used  by  DevOps  for:     "   ProducNon  system  monitoring     "   ApplicaNon  debugging     "   Customer  service     “Splunk  Cloud  saved  us  months   of  development     Nme  and  we  esNmate  a     60-­‐70%  reducNon     in  producNon     troubleshooNng  Nme.”  
  • 19.
  • 20.
    Dedicated  Deployments   Clustered  Indexers  &   Search  Heads   MulNple  Data  Centers   ProacNve,  conNnuous   monitoring   OrchestraNon  Layer   MulN-­‐region  OperaNons   Processes  for  data  and   customer  protecNon   SSL  EncrypNon   EncrypNon  of  data  at  rest   Splunk  Cloud  –  Technical  Overview   Opera:onal     Excellence   Security   Support   Enterprise  grade  support   Same  support  teams  and   processes  as  Splunk   Enterprise   Architecture   20
  • 21.
    How  it  Works   Splunk  Cloud   Datacenter   Private  Cloud   Public  Cloud   •  Dedicated  Deployments  in  AWS   •  ConNnuously  Monitored   •  Forwarders  collect  all   machine  data   •  Compression  and   EncrypNon   •  Fault  tolerant   persistent  queues   21
  • 22.
       Architecture Diagram Customer  Stack   Opera:onal  Monitoring   Users  Searching   via  HTTPS   Forwarders     over  SSL   S3  backup   Orchestra:on  Layer   •  Chef   •  Ansible   •  Jenkins   Amazon  VPC   22 Mul:-­‐AZ,   Clustered  Search  Heads   Mul:-­‐AZ,  Clustered     Indexers   …   Master  Nodes   …   Behind-­‐firewall   Forwarder   Management  
  • 23.
    Splunk  Cloud  –  Data  Inputs   Scripted/Modular  inputs  Syslog/TCP/UDP  Local  /  CIFS  files  Rest-­‐API   23 Universal  or  Heavy  forwarder  
  • 24.
    Combine  with  Any  Exis:ng  Data  Sources   On-­‐Premises  Modular  Inputs  DB  Connect  Hadoop  Connect   24
  • 25.
    Any  Data  Input  Correlated  with  Exis:ng  Data  Sources     Scripted/Modular  inputs  TCP/UDP  Local  files  Rest-­‐API   25 Universal  or  Heavy  forwarder  
  • 26.
    Security  &  Compliance   "   SOC2  type  2  adested   "   Data  confidenNality  (data  at  rest*)   "   Role  Based  Access  Controls   "   Private,  dedicated  instances   "   IDS  Monitoring   "   ConNnuous  vulnerability  scanning   26
  • 27.
       Encryption atRest Diagram Users  Searching   via  HTTPS   Forwarders     over  SSL   Your  VPC   27 Mul:-­‐AZ,   Clustered  Search  Heads   Mul:-­‐AZ,  Clustered     Indexers   …   Master  Nodes   …   Behind-­‐firewall   Forwarder   Management   Splunk  Cloud  VPC   VPC  Peering   (OpNonal)   V  V   V   V   V   Vormetric     DSM   (OpNonal)   Vormetric     DSM   (OpNonal)  
  • 28.
        28 Support Coverage     Resources  :   •  Americas   •  EMEA     •  APAC     •  SLA’s  offered  are  the  same  as  Splunk   Enterprise   •  Splunk  support  escalates  to  Splunk   Cloud  Ops  where  required   •  24  hour  follow  the  sun  model      
  • 29.
    Splunk  Cloud  –  key  takeaways   •  Built  using  best  pracNces  –  maintained  by  the  experts •  Instantly  available   •  Hybrid  search  capability   •  Following  Industry  standard  SOC2  compliance   •  We  stand  behind  our  service  (100%  SLA)   29
  • 30.
    QUESTIONS?     THANKS!   SOBRIEN@SPLUNK.COM