Get More From Your Machine
Data With Splunk & AI
March | 2018
Adrien Debosschere | Sales Engineer
SplunkLive! Paris
During the course of this presentation, we may make forward-looking statements regarding future events or
the expected performance of the company. We caution you that such statements reflect our current
expectations and estimates based on factors currently known to us and that actual events or results could
differ materially. For important factors that may cause actual results to differ from those contained in our
forward-looking statements, please review our filings with the SEC.
The forward-looking statements made in this presentation are being made as of the time and date of its live
presentation. If reviewed after its live presentation, this presentation may not contain current or accurate
information. We do not assume any obligation to update any forward looking statements we may make. In
addition, any information about our roadmap outlines our general product direction and is subject to change
at any time without notice. It is for informational purposes only and shall not be incorporated into any contract
or other commitment. Splunk undertakes no obligation either to develop the features or functionality
described or to include any such feature or functionality in a future release.
Splunk, Splunk>, Listen to Your Data, The Engine for Machine Data, Splunk Cloud, Splunk Light and SPL are trademarks and registered trademarks of Splunk Inc. in
the United States and other countries. All other brand names, product names, or trademarks belong to their respective owners. © 2017 Splunk Inc. All rights reserved.
Forward-Looking Statements
Why AI & Machine
Learning?
Humans are good at
learning, but we get lost
in volume and details…
▶ Improve decision-making
▶ Uncover hidden trends or
relationships
▶ Alert on deviations
▶ Forecast or anticipate incidents
All of this requires diverse data
from across many silos. Lots
of unstructured, real-time data.
Why AI & Machine Learning?
Run the Business in Real Time
Data From the Past Real-Time Data Statistical Forecast
T – a few days T + a few days
Security Operations Center
IT Operations Center
Business Operations Center
Predictive
(Models)
Historical Reporting
(BI Tools, Data Lakes) Grey space
What is Machine
Learning?
▶ Face detection: find faces in images
▶ Spam filtering: identify SPAM messages
▶ Shopping recommendations: predict
what customers would like to buy
▶ Fraud detection: identify credit card
transactions
that may be fraudulent in nature
▶ Weather forecast: predict whether or not it
will rain tomorrow; estimate daily max/min
ML is All Around You!
The ML Process
Get and
explore data
Select and fit an
algorithm,
generating a model
Apply and
validate models
Surface model to
consumers to
solve problems
Problem: <Stuff in the world> causes big time and money expense. Value Hypothesis
Solution: Build ML model to forecast <possible incidents>, act pre-emptively and learn
Operationalize
Splunk’s Machine
Learning Tour
Overview of AI Powered by ML at Splunk
CORE PLATFORM
SEARCH
PACKAGED PREMIUM
SOLUTIONS
MACHINE LEARNING
TOOLKIT
Search Includes Machine Learning
Core platform search is a powerful and highly flexible interface built with ML
Splunk IT Service Intelligence
Get Data
Define services,
entities and KPIs
Monitor and
troubleshoot
Analyze
and detect
Data-Defined, Data-Driven Service Insights
Adaptive Thresholds and Anomaly Detection
Anomalous Behavior Risky Users Unknown Threats
Splunk User Behavior Analytics
An out-of-the-box solution that helps organizations find
with the use of machine learning
▶ Assistants: Guided model building, testing
and deployment for common objectives
▶ Showcases: Interactive examples for typical
IT, security, business and IoT use cases
▶ Algorithms: 25+ standard algorithms
included with the Toolkit
▶ ML Commands: New SPL commands to fit,
test and operationalize models
▶ Python for Scientific Computing Library:
Access to 300+ open source algorithms
Splunk Machine Learning Toolkit
Extends Splunk platform functions and provides a guided modeling environment
Build custom analytics for any use case
Custom Machine Learning – Success Formula
Identify use cases
Drive decisions
Set business/ops priorities
SPL
Data prep
Statistics/math background
Algorithm selection
Model building
Splunk ML Toolkit
facilitates and simplifies
via examples and guidance
Operational success
Data
Science
Expertise
Splunk
Expertise
Domain
Expertise
(IT, Security…)
Continuous Data Ingest at Scale
DevelopVisualize PredictAlertSearch
Engineers Data
Analysts
Security
Analysts
Business
Users
Native Inputs
TCP, UDP, Logs, Scripts, Wire, Mobile
Industrial Data
SCADA, AMI, Meter Reads
Modular Inputs
MQTT, AMQP, COAP, REST, JMS
HTTP Event Collector
Token Authenticated Events
Technology Partnerships
Kepware, AWS IoT, Cisco, Palo Alto
Maintenance
Info
Asset
Info
Data
Stores
External
Lookups/EnrichmentOT
Industrial Assets
IT
Consumer and
Mobile Devices Real Time
Search
Third-Party
Applications
Smartphones
and Devices
Tickets
Email
Send an
email
File a
ticket
Send a text
Flash lights
Trigger
process flow
Sense and Respond
Search Can Use
Machine Learning
OT
Industrial Assets
Consumer and
Mobile Devices
Alert
IT
Real Time
Demo
Use Cases and
Customer Stories
© 2018 SPLUNK INC.
▶ Real-time enterprise-wide infrastructure monitoring
▶ Robust solution to tear down IT silos and correlate
events
▶ Dashboards for different audiences, from problem-
solving techs to big-picture managers
Leidos Taps Splunk ITSI for Better
Event Management
“We have so much information at our fingertips thanks to
Splunk… we’re constantly solving business problems in creative
ways.”
– Director of Performance Management, Leidos
TECHNOLOGY – IT OPERATIONS
© 2018 SPLUNK INC.
▶ Using Splunk ES to monitor potential external security
breaches and UBA to detect insider threats
▶ Analyst efficiency to gather data and speed security
investigations has increased by more than 50 percent
▶ Provides deep understanding of data and reusable
correlation rules across all support engineer levels
Nasdaq: Keeping Markets Moving
“Splunk allows us to have a single skill set that is common
across the entire organization. Information security is
writing queries but using the same language as our
operations team.”
– AVP, Nasdaq
FINANCIAL SERVICES – SECURITY
Machine Learning Customer Success
Network Incident Detection
Service Degradation Detection
Security/Fraud Prevention
Machine Learning
Consulting Services
Analytics App Built
on ML Toolkit
Optimizing operations and business results
Predict Gaming Outages
Fraud Prevention
Entertainment
Company
Cell Tower Incident Detection
Optimize Repair Operations
Prioritize Website Issues
and Predict Root Cause
Questions ?
▶Save the Date 2018
October 1-4, 2018
▶ 8,750+ Splunk Enthusiasts
▶ 300+ Sessions
▶ 100+ Customer Speakers
Plus Splunk University:
▶ Three Days: September 29-October 1, 2018
▶ Get Splunk Certified for FREE!
▶ Get CPE credits for CISSP, CAP, SSCP
Walt Disney World Swan and Dolphin Resort in Orlando
conf .splunk.com
SAVE THE DATE!
© 2018 SPLUNK INC.
Thank You!
https://www.surveymonkey.com/r/SLParis2018

SplunkLive! Paris 2018: Splunk And AI 101

  • 1.
    Get More FromYour Machine Data With Splunk & AI March | 2018 Adrien Debosschere | Sales Engineer SplunkLive! Paris
  • 2.
    During the courseof this presentation, we may make forward-looking statements regarding future events or the expected performance of the company. We caution you that such statements reflect our current expectations and estimates based on factors currently known to us and that actual events or results could differ materially. For important factors that may cause actual results to differ from those contained in our forward-looking statements, please review our filings with the SEC. The forward-looking statements made in this presentation are being made as of the time and date of its live presentation. If reviewed after its live presentation, this presentation may not contain current or accurate information. We do not assume any obligation to update any forward looking statements we may make. In addition, any information about our roadmap outlines our general product direction and is subject to change at any time without notice. It is for informational purposes only and shall not be incorporated into any contract or other commitment. Splunk undertakes no obligation either to develop the features or functionality described or to include any such feature or functionality in a future release. Splunk, Splunk>, Listen to Your Data, The Engine for Machine Data, Splunk Cloud, Splunk Light and SPL are trademarks and registered trademarks of Splunk Inc. in the United States and other countries. All other brand names, product names, or trademarks belong to their respective owners. © 2017 Splunk Inc. All rights reserved. Forward-Looking Statements
  • 3.
    Why AI &Machine Learning?
  • 4.
    Humans are goodat learning, but we get lost in volume and details…
  • 5.
    ▶ Improve decision-making ▶Uncover hidden trends or relationships ▶ Alert on deviations ▶ Forecast or anticipate incidents All of this requires diverse data from across many silos. Lots of unstructured, real-time data. Why AI & Machine Learning?
  • 6.
    Run the Businessin Real Time Data From the Past Real-Time Data Statistical Forecast T – a few days T + a few days Security Operations Center IT Operations Center Business Operations Center Predictive (Models) Historical Reporting (BI Tools, Data Lakes) Grey space
  • 7.
  • 8.
    ▶ Face detection:find faces in images ▶ Spam filtering: identify SPAM messages ▶ Shopping recommendations: predict what customers would like to buy ▶ Fraud detection: identify credit card transactions that may be fraudulent in nature ▶ Weather forecast: predict whether or not it will rain tomorrow; estimate daily max/min ML is All Around You!
  • 9.
    The ML Process Getand explore data Select and fit an algorithm, generating a model Apply and validate models Surface model to consumers to solve problems Problem: <Stuff in the world> causes big time and money expense. Value Hypothesis Solution: Build ML model to forecast <possible incidents>, act pre-emptively and learn Operationalize
  • 10.
  • 11.
    Overview of AIPowered by ML at Splunk CORE PLATFORM SEARCH PACKAGED PREMIUM SOLUTIONS MACHINE LEARNING TOOLKIT
  • 12.
    Search Includes MachineLearning Core platform search is a powerful and highly flexible interface built with ML
  • 13.
    Splunk IT ServiceIntelligence Get Data Define services, entities and KPIs Monitor and troubleshoot Analyze and detect Data-Defined, Data-Driven Service Insights Adaptive Thresholds and Anomaly Detection
  • 14.
    Anomalous Behavior RiskyUsers Unknown Threats Splunk User Behavior Analytics An out-of-the-box solution that helps organizations find with the use of machine learning
  • 15.
    ▶ Assistants: Guidedmodel building, testing and deployment for common objectives ▶ Showcases: Interactive examples for typical IT, security, business and IoT use cases ▶ Algorithms: 25+ standard algorithms included with the Toolkit ▶ ML Commands: New SPL commands to fit, test and operationalize models ▶ Python for Scientific Computing Library: Access to 300+ open source algorithms Splunk Machine Learning Toolkit Extends Splunk platform functions and provides a guided modeling environment Build custom analytics for any use case
  • 16.
    Custom Machine Learning– Success Formula Identify use cases Drive decisions Set business/ops priorities SPL Data prep Statistics/math background Algorithm selection Model building Splunk ML Toolkit facilitates and simplifies via examples and guidance Operational success Data Science Expertise Splunk Expertise Domain Expertise (IT, Security…)
  • 17.
    Continuous Data Ingestat Scale DevelopVisualize PredictAlertSearch Engineers Data Analysts Security Analysts Business Users Native Inputs TCP, UDP, Logs, Scripts, Wire, Mobile Industrial Data SCADA, AMI, Meter Reads Modular Inputs MQTT, AMQP, COAP, REST, JMS HTTP Event Collector Token Authenticated Events Technology Partnerships Kepware, AWS IoT, Cisco, Palo Alto Maintenance Info Asset Info Data Stores External Lookups/EnrichmentOT Industrial Assets IT Consumer and Mobile Devices Real Time
  • 18.
    Search Third-Party Applications Smartphones and Devices Tickets Email Send an email Filea ticket Send a text Flash lights Trigger process flow Sense and Respond Search Can Use Machine Learning OT Industrial Assets Consumer and Mobile Devices Alert IT Real Time
  • 19.
  • 20.
  • 21.
    © 2018 SPLUNKINC. ▶ Real-time enterprise-wide infrastructure monitoring ▶ Robust solution to tear down IT silos and correlate events ▶ Dashboards for different audiences, from problem- solving techs to big-picture managers Leidos Taps Splunk ITSI for Better Event Management “We have so much information at our fingertips thanks to Splunk… we’re constantly solving business problems in creative ways.” – Director of Performance Management, Leidos TECHNOLOGY – IT OPERATIONS
  • 22.
    © 2018 SPLUNKINC. ▶ Using Splunk ES to monitor potential external security breaches and UBA to detect insider threats ▶ Analyst efficiency to gather data and speed security investigations has increased by more than 50 percent ▶ Provides deep understanding of data and reusable correlation rules across all support engineer levels Nasdaq: Keeping Markets Moving “Splunk allows us to have a single skill set that is common across the entire organization. Information security is writing queries but using the same language as our operations team.” – AVP, Nasdaq FINANCIAL SERVICES – SECURITY
  • 23.
    Machine Learning CustomerSuccess Network Incident Detection Service Degradation Detection Security/Fraud Prevention Machine Learning Consulting Services Analytics App Built on ML Toolkit Optimizing operations and business results Predict Gaming Outages Fraud Prevention Entertainment Company Cell Tower Incident Detection Optimize Repair Operations Prioritize Website Issues and Predict Root Cause
  • 24.
  • 25.
    ▶Save the Date2018 October 1-4, 2018 ▶ 8,750+ Splunk Enthusiasts ▶ 300+ Sessions ▶ 100+ Customer Speakers Plus Splunk University: ▶ Three Days: September 29-October 1, 2018 ▶ Get Splunk Certified for FREE! ▶ Get CPE credits for CISSP, CAP, SSCP Walt Disney World Swan and Dolphin Resort in Orlando conf .splunk.com SAVE THE DATE!
  • 26.
    © 2018 SPLUNKINC. Thank You! https://www.surveymonkey.com/r/SLParis2018