4. 4
Big
Data
Big
data
is
a
term
for
data
sets
that
are
so
large
or
complex
that
tradiQonal
data
processing
applicaQons
are
inadequate.
Manually
or
automaQcally
generated,
not
always
Qme
stamped
events
Term
typically
refers
to
the
use
of
analyQcs
in
order
to
extract
value
from
the
data
set.
6. 6
Machine Data
Time
stamped,
high
volume,
machine
generated
(velocity)
No
single
form
or
format
(variable)
DefiniQve
record
of
events
in
your
organizaQon
7. 7
Machine Data
Defini,ve
record
of
events
in
your
organiza,on
This
is
how
security
engineers
idenQfy
and
interrupt
kill
chains
This
is
user
telemetry
data
that
reveals
soZware
bugs
This
is
how
we
spot
correlaQons
in
customer
behavior
8. 8
The
AcceleraQng
Pace
of
Data
Volume
|
Velocity
|
Variety
|
Variability
GPS,
RFID,
Hypervisor,
Web
Servers,
Email,
Messaging,
Clickstreams,
Mobile,
Telephony,
IVR,
Databases,
Sensors,
TelemaQcs,
Storage,
Servers,
Security
Devices,
Desktops
Machine
data
is
the
fastest
growing,
most
complex,
most
valuable
area
of
big
data
9. 9
Turning
Machine
Data
Into
Business
Value
Index
Untapped
Data:
Any
Source,
Type,
Volume
Online
Services
Web
Services
Servers
Security
GPS
LocaQon
Storage
Desktops
Networks
Packaged
ApplicaQons
Custom
ApplicaQons
Messaging
Telecoms
Online
Shopping
Cart
Web
Clickstreams
Databases
Energy
Meters
Call
Detail
Records
Smartphones
and
Devices
RFID
On-‐
Premises
Private
Cloud
Public
Cloud
Ask
Any
Ques,on
Applica,on
Delivery
Security,
Compliance
and
Fraud
IT
Opera,ons
Business
Analy,cs
Industrial
Data
and
the
Internet
of
Things
10. 10
Industry
Leading
Plaeorm
for
Machine
Data
Index
Untapped
Data:
Any
Source,
Type,
Volume
Online
Services
Web
Services
Servers
Security
GPS
LocaQon
Storage
Desktops
Networks
Packaged
ApplicaQons
Custom
ApplicaQons
Messaging
Telecoms
Online
Shopping
Cart
Web
Clickstreams
Databases
Energy
Meters
Call
Detail
Records
Smartphones
and
Devices
RFID
On-‐
Premises
Private
Cloud
Public
Cloud
Ask
Any
Ques,on
Applica,on
Delivery
Security,
Compliance
and
Fraud
IT
Opera,ons
Business
Analy,cs
Industrial
Data
and
the
Internet
of
Things
Any
amount,
any
locaQon,
any
source
Schema-‐
on-‐the-‐fly
Universal
indexing
No
back-‐end
RDBMS
No
need
to
filter
data
11. 11
Plaeorm
for
OperaQonal
Intelligence
Rich
Ecosystem
of
Apps
&
Add-‐Ons
Splunk
Premium
Solu,ons
Mainframe
Data
RelaQonal
Databases
Mobile
Forwarders
Syslog/TCP
IoT
Devices
Network
Wire
Data
Hadoop
The
Splunk
Poreolio
14. 14
Text
With
Firefox,
Chrome,
or
Safari
–
head
to
hjp://127.0.0.1:8000
.
User=admin
password=changeme
15. 15
SPL
Commands
run
on
tutorial
data
************************
search
basics
************************
buPercupgames
Qme
picker
buPercupgames
400
buPercupgames
400
OR
300
buPercupgames
status=500
OR
status=400
fields>>”status”>>make
selected
field
select
“top
values”
modify
query:
bujercupgames
status=500
OR
status=400|
top
limit=20
status
to
buPercupgames
status=500
OR
status=4*|
top
limit=20
status
bar
and
pie
chart
back
to
raw
search:
buPercupgames
status=500
OR
status=4*
fields>>”status”>>top
values
over
Qme
line
vs
bar
graph..
look
at
raw
search
and
discuss
|
pipe
bujercupgames
status=500
OR
status=4*|
Qmechart
count
by
status
limit=10
buPercupgames
status=*
drill
into
histogram
bar..
fields>>”status”>>top
values
by
Qme
modify
search
to
exclude
200
buPercupgames
status=*
AND
status!=200
|
,mechart
count
by
status
limit=10
is
the
same
as:
buPercupgames
status=*
NOT
status=200
|
,mechart
count
by
status
limit=10
same
event
result
count
change
line
to
column
column
to
stack
save
as
new
dash
board
search
bujon
back
to
home
screen
************************
field
extracQon
************************
buPercupgames
select
an
event
(any
event)
click
>
to
expand
the
fields
of
the
event
and
the
event
opQons
click
“event
opQons>>extract
fields”
select
“regular
expressions”
select
“next”
highlight
the
value
of
the
field
you
want
to
extract..
in
this
case
mozilla
name
the
field
“browser_type”
show
regular
expression..
preview
events
and
browser
type
to
verify
it
looks
good
validate
for
removal
permissions:
all
apps
save
and
search…
fields>>”browser_type”
as
selected
field
“browser_type”
top
values
bar
graph,
pie
graph
add
pie
to
exisQng
dashboard
view
in
search
the
“status
by
day”
original
dashboard
panel:
bujercupgames
status=*
NOT
status=200
|
Qmechart
count
by
status
limit=10
add
new
extracted
field
Qmes
to
break
out
status
by
browser
buPercupgames
status=*
NOT
status=200
browser_type=opera
|
,mechart
count
by
status
limit=10
add
to
dashboard
panel
as
opera
status
buPercupgames
status=*
NOT
status=200
browser_type=mozilla
|
,mechart
count
by
status
limit=10
add
to
dashboard
panel
as
mozilla
status
Dashboard
now
shows
status
codes
by
day,
browser
types,
and
status
codes
by
browser
type
16. 16
SPL
Commands
run
on
tutorial
data
***************
alerts
***************
search..
buPercupgames
Search
for
unsuccessful
events
that
exceed
100
in
quanQty
save
as
alerts,
scheduled
once
a
min
scheduled,
run
on
chron,
early
-‐90d,
latest
now,
cron
expression
“
*/1
*
*
*
*
”
,
trigger
results
>
0,
*********
geostats
*********
buPercupgames
status=*
|
iploca,on
clien,p
fields>>city
fields>>state
buPercupgames
status=*
|
iploca,on
clien,p
|
geostats
count
by
ac,on
Save
to
dashboard
Sweet!