Copyright © 2015 Splunk Inc.
Splunk Enterprise & Cloud
Version 6.3
Rosie Sennett
Staff Sales Engineer
2
3
Advanced Analysis &
Visualization
VISABILITY
Anomaly Detection
Super Powered Geospatial
Mapping
Amped Up Single Value Display
Breakthrough
Performance & Scale
PLATFORM
Search Parallelization
Index Parallelization
Intelligent Job Scheduling
Management and
Administration
Continued Distributed Environment
Awareness
Distributed Management Console
Expansion
GUI Assist for Custom Alerts w 3rd
Party Endpoints
Expanded Support
for DevOps and IoT
DEVELOPER
HTTP Event Collector
Developer API & SDK
3rd Party Integrations
Cool New Updated Book
ENTERPRISE
Copyright © 2015 Splunk Inc.
In just a moment…
Deep Dives
Please…
5
“Those who wish users to RTFM,
must be diligent at the production
of a better FM.”
- Buddha
6
7
Go get ‘em
conf.splunk.com
8
9
Expanded Support
for DevOps and IOT
DEVELOPER
Management and
Administration
ENTERPRISE
Advanced Analysis &
Visualization
VISABILITY
Breakthrough
Performance & Scale
PLATFORM
10
Vertical Scaling is super Speedy!
Maximizing use of underutilized CPU
Search Performance: 2x Increased Execution Speed
Indexing Speed: 2-4x Data Rate
Official Indexer Volume Per day? 300GB… yep.
11
3 Tier Architecture
12
Good Old Splunk Data Ingestion Pipeline
13
Business as Usual
14
Under Utilized Indexer
15
Multiple Data Ingestion Pipelines
16
Multiple Ingestion Pipelines over Network
17
Search
Execution
Speed
2x
Forwarder
Efficiency
4x
18
Get the rest
from
Buttercup’s
mouth…
19
20
We are Listening to You…
Making The Most Of The New Splunk Scheduler
Speakers
Paul Lucas, Sr. Software Engineer, Splunk
• Performance Improved by 25%
• Simplified and more effective Scheduling
• “Finish By” criteria added creating Scheduling
Windows
• Splunk profiles workloads and controls
scheduling Optimizing Resources
21
Let it Wash Over You…
22
Expanded Support
for DevOps and IOT
DEVELOPER
Management and
Administration
ENTERPRISE
Advanced Analysis &
Visualization
VISABILITY
Breakthrough
Performance & Scale
PLATFORM
23
Pictures Good!
24
25
Single Value
As it Was Then As it Is Now
26
Single Value
Small Space – High Information Density
27
Hard to See
28
Hard to Miss
29
Pre 6.0
Community
Supported
Google Maps
Add-On
Splunk 6.0
Cluster Maps
Splunk Tiles
|geostats
Splunk 6.1
UI Integration
Format Editor
30
Cloropleth Maps
31
Polygons For YOU! (Any .KMZ file works)
32
33
Anomaly Detection
New SPL Command provides histogram-based anomaly detection
• Replaces existing Outlier and
AnomalousValue commands
• Offers zscore, histogram and iqr
options
• Net new Histogram-based approach
offers a more accurate detection
method
3
34
Newest Command…
35
36
Expanded Support
for DevOps and IOT
DEVELOPER
Management and
Administration
ENTERPRISE
Advanced Analysis &
Visualization
VISABILITY
Breakthrough
Performance & Scale
PLATFORM
37
38
39
40
41
42
Alert Action Examples
43
44
HTTP Event Collector
Opens the door (but not too wide) for devs to send logs directly to Splunk
• New token based JSON API for
events
• Send events directly from
anywhere (server, mobile device,
IOT)
• Easy to configure – works out of
the box
• Easy to secure
• Highly performant, scalable and
available
45
46
Expanded Support
for DevOps and IOT
DEVELOPER
Management and
Administration
ENTERPRISE
Advanced Analysis &
Visualization
VISABILITY
Breakthrough
Performance & Scale
PLATFORM
47
HTTP Event Collector
Supports DevOps and IoT Data Analysis Needs at Scale
1. Standard API and Logging Libraries send events directly to Splunk
2. Libraries integrated into popular platforms and services
48
Additions to Logging Libraries
49
50
Expanded Support
for DevOps and IOT
DEVELOPER
Management and
Administration
ENTERPRISE
Advanced Analysis &
Visualization
VISABILITY
Breakthrough
Performance & Scale
PLATFORM
Beautiful FM to R
DOCUMENTATION
51
Documentation
Redesign
52
New Doc For 6.3
Looks good… tastes great
Copyright © 2015 Splunk Inc.
• September 26-29, 2016
• The Disney Swan and Dolphin, Orlando
• 5000+ IT & Business Professionals
• 3 days of technical content
• 165+ sessions
• 3 days of Splunk University
• Sept 24-26, 2016
• Get Splunk Certified for FREE!
• Get CPE credits for CISSP, CAP, SSCP
• Save thousands on Splunk education!
• 80+ Customer Speakers
• 35+ Apps in Splunk Apps Showcase
• 75+ Technology Partners
• 1:1 networking: Ask The Experts and
• Security Experts, Birds of a Feather and Chalk Talks
• NEW hands-on labs!
• Expanded show floor, Dashboards Control Room &
Clinic, and MORE!
.conf2016: The 7th Annual
Splunk Worldwide Users’ Conference
54
We Want to Hear your Feedback!
After the Breakout Sessions conclude
Text Splunk to 20691
And be entered for a chance to win a $100 AMEX gift card!
Thank You

What's New in Splunk 6.3

Editor's Notes

  • #2 This is a huge release… So many innovations and so many inroads made on this fantastic journey. Enterprise Splunk Version 6.3 was made available just recently at our World Wide User Conference in Las Vegas September 2015 We have a lot of material to cover…
  • #3 So I’m going to give you the 40,000 foot view.
  • #4 There are four major areas of improvement
  • #5 And you’ll get more info in the deep dives
  • #7 So we produced a better FM to guide you
  • #8 But you can get the sessions that go deeper yourself
  • #9 Specifically this one… which will point you to all the other ones.
  • #10 Let’s get started.
  • #11 Faster stronger…
  • #54 We’re headed to the East Coast! 2 inspired Keynotes – General Session and Security Keynote + Super Sessions with Splunk Leadership in Cloud, IT Ops, Security and Business Analytics! 165+ Breakout sessions addressing all areas and levels of Operational Intelligence – IT, Business Analytics, Mobile, Cloud, IoT, Security…and MORE! 30+ hours of invaluable networking time with industry thought leaders, technologists, and other Splunk Ninjas and Champions waiting to share their business wins with you! Join the 50%+ of Fortune 100 companies who attended .conf2015 to get hands on with Splunk. You’ll be surrounded by thousands of other like-minded individuals who are ready to share exciting and cutting edge use cases and best practices. You can also deep dive on all things Splunk products together with your favorite Splunkers. Head back to your company with both practical and inspired new uses for Splunk, ready to unlock the unimaginable power of your data! Arrive in Orlando a Splunk user, leave Orlando a Splunk Ninja! REGISTRATION OPENS IN MARCH 2016 – STAY TUNED FOR NEWS ON OUR BEST REGISTRATION RATES – COMING SOON!