SlideShare a Scribd company logo
Copyright © 2015 Splunk Inc.
Splunk Enterprise 6.3
Was ist neu?
Udo Götzen
CISSP, Senior Sales Engineer
In diesem Raum:
13:30 Splunk Enterprise 6.3
14:15 Splunk for ITOps
Splunk: Platform für
Maschinendaten
3
Industry Leading Platform For Machine Data
Machine Data: Any Location, Type, Volume
Online
Services Web
Services
Servers
Security GPS
Location
Storage
Desktops
Networks
Packaged
Applications
Custom
ApplicationsMessaging
Telecoms
Online
Shopping
Cart
Web
Clickstreams
Databases
Energy
Meters
Call Detail
Records
Smartphones
and Devices
RFID
On-
Premises
Private
Cloud
Public
Cloud
Platform Support (Apps / API / SDKs)
Enterprise Scalability
Universal Indexing
Answer Any Question
Developer
Platform
Report
and
analyze
Custom
dashboards
Monitor
and alert
Ad hoc
search
4
Industry Leading Platform For Machine Data
Machine Data: Any Location, Type, Volume
Online
Services Web
Services
Servers
Security GPS
Location
Storage
Desktops
Networks
Packaged
Applications
Custom
ApplicationsMessaging
Telecoms
Online
Shopping
Cart
Web
Clickstreams
Databases
Energy
Meters
Call Detail
Records
Smartphones
and Devices
RFID
On-
Premises
Private
Cloud
Public
Cloud
Platform Support (Apps / API / SDKs)
Enterprise Scalability
Universal Indexing
Answer Any Question
Developer
Platform
Report
and
analyze
Custom
dashboards
Monitor
and alert
Ad hoc
search
Any amount, any location, any source
Schema-
on-the-fly
Universal
indexing
No
back-end
RDBMS
No need
to filter
data
4
5
Turn Machine Data into Operational Intelligence
INDEX ANY MACHINE DATA: ANY SOURCE, TYPE, VOLUME
Online
Services Web
Services
Servers
Security GPS
Location
Storage
Desktops
Networks
Packaged
Applications
Custom
ApplicationsMessaging
Telecoms
Online
Shopping
Cart
Web
Clickstreams
Databases
Energy
Meters
Call Detail
Records
Smartphones
and Devices
RFID
On-
Premises
Private
Cloud
Public
Cloud
GAIN REAL-TIME VISIBILITY
Application Delivery
Security and
Compliance
Infrastructure
Monitoring
Business Analytics
Internet of Things
5
Setting the Standard for Operational Intelligence
Engine
Platform
1 2 3
2006-2008
Tool
2009-2011 2012-2016
4 4.1 4.2 4.3
5x 6x
“Google for the
datacenter”
“Engine for machine-
generated data”
“Platform for Operational
Intelligence”
6
7
Turning Machine Data Into Operational Intelligence
Reactive
Search
and
Investigate
Proactive
Monitoring
and Alerting
Operational
Visibility
Proactive
Real-time
Business
Insight
Splunk Enterprise 6.3
What’s new?
9
Splunk Enterprise 6.3
Breakthrough
Performance & Scale
Doubles performance
and lowers TCO
• 2x Search & Indexing Speed
• 20-50% Increased Capacity
• 20%+ Reduced TCO
Meeting the needs of the most demanding organizations
Advanced Analysis
& Visualization
High-Volume Event
Collection
Enterprise-Scale
Platform
Supports DevOps and IoT
data analysis at scale
Simplifies analysis of
large datasets
Delivers Enterprise
platform requirements
• Anomaly Detection
• Geospatial Mapping
• Single-Value Display
• HTTP Event Collector
• Developer API & SDKs
• 3rd Party Integrations
• Expanded Management
• Custom Alert Actions
• Data Integrity Control
10
Breakthrough Performance, Scale, TCO
1
Search Performance
Indexing Speed
Intelligent Scheduling
25%+ Capacity Gain
2x Execution Speed
2-4x Data Rate
Vertical scaling maximizes use of CPU power
Total System Capacity
20-50% Increase
Improve speed of searches & reports
Onboard & analyze larger datasets
Optimize resource utilization
Reduce TCO by 20% or more
Comparisons are to Splunk Enterprise 6.2.
Customer performance and TCO will vary according to workload, configuration and available processing capacity.
So What Does Breakthrough Mean?
Critical reports can be available in ¼ the time
It takes 20% less indexing hardware (HW) to expand or deploy
Splunk
New data is ready for analysis in ½ the time
1
Splunk expansion costs have dropped over 50% since 2013
A new customer can deploy Splunk using 1/3 the HW vs. 2013
Splunk deployment is now ½ the cost vs. 2013
Release 6.3
vs.
Release 6.2
Release 6.3
vs.
Release 6.0
12
NEW: HTTP Event Collector
1
• A new token-based JSON API for
events
• Send events directly from anywhere
(servers, mobile devices, IOT)
• Easy to configure / works out of the
box.
• Easy to secure
• Highly performant, scalable and
available
13
HTTP Event Collector
Demo
http://splunk.com/shake
App Spotlights
15
App Spotlight: Custom Visualizations
Copyright © 2015 Splunk Inc.
Vielen Dank! – Q&A

More Related Content

PPTX
SplunkLive! München 2016 - Splunk für IT Operations
PDF
SplunkLive! München 2016 - Getting started with Splunk
PDF
SplunkLive! München 2016 - Splunk für Security
PPTX
Splunk for IT Operations
PPTX
Machine Data 101 Hands-on
PPTX
SplunkLive! Utrecht 2016 - NXP
PDF
Getting Started with IT Service Intelligence
PPTX
Getting Started with Splunk Enterprise
SplunkLive! München 2016 - Splunk für IT Operations
SplunkLive! München 2016 - Getting started with Splunk
SplunkLive! München 2016 - Splunk für Security
Splunk for IT Operations
Machine Data 101 Hands-on
SplunkLive! Utrecht 2016 - NXP
Getting Started with IT Service Intelligence
Getting Started with Splunk Enterprise

What's hot (20)

PPTX
Softcat Splunk Discovery Day Manchester, March 2017
PPTX
Splunk IT Service Intelligence
PDF
Splunk Enterprise for IT Troubleshooting
PPTX
SplunkLive! Splunk for IT Operations
PPTX
Splunk for IT Operations
PPTX
SplunkLive! Splunk Enterprise 6.3 - Data On-boarding
PPTX
SplunkLive! - Splunk for IT Operations
PPTX
Getting Started with Splunk (Hands-On)
PPTX
SplunkLive! - Splunk for IT Operations
PPTX
Splunk for IT Operations Breakout Session
PPTX
Splunk for IT Operations
PPTX
Taking Splunk to the Next Level - Management Breakout Session
PPTX
SplunkLive! Wien 2016 - Use Case TTTech Computertechnik
PPTX
Splunk Enterpise for Information Security Hands-On
PPTX
Splunk for IT Operations
PDF
Доступная безопасность: смесь инструментов с данными. Советы архитектора Oracle
PDF
Splunk Webinar Best Practices für Incident Investigation
PPTX
How to Design, Build and Map IT and Business Services in Splunk
PPTX
How to Design, Build and Map IT and Business Services in Splunk
PDF
SplunkLive! Zürich 2016 - Use Case Swisscom
Softcat Splunk Discovery Day Manchester, March 2017
Splunk IT Service Intelligence
Splunk Enterprise for IT Troubleshooting
SplunkLive! Splunk for IT Operations
Splunk for IT Operations
SplunkLive! Splunk Enterprise 6.3 - Data On-boarding
SplunkLive! - Splunk for IT Operations
Getting Started with Splunk (Hands-On)
SplunkLive! - Splunk for IT Operations
Splunk for IT Operations Breakout Session
Splunk for IT Operations
Taking Splunk to the Next Level - Management Breakout Session
SplunkLive! Wien 2016 - Use Case TTTech Computertechnik
Splunk Enterpise for Information Security Hands-On
Splunk for IT Operations
Доступная безопасность: смесь инструментов с данными. Советы архитектора Oracle
Splunk Webinar Best Practices für Incident Investigation
How to Design, Build and Map IT and Business Services in Splunk
How to Design, Build and Map IT and Business Services in Splunk
SplunkLive! Zürich 2016 - Use Case Swisscom
Ad

Viewers also liked (6)

PDF
SplunkLive! Munich 2015 - Graphmasters
PPTX
Splunk Webinar: Verwandeln Sie Datensilos in Operational Intelligence
PDF
Varnish kann alles
PPTX
SplunkLive! Customer Presentation – Directv
PDF
SplunkLive! München 2016 - Splunk @ Datev
PPTX
SplunkLive! München 2016 - Splunk @ UniCredit
SplunkLive! Munich 2015 - Graphmasters
Splunk Webinar: Verwandeln Sie Datensilos in Operational Intelligence
Varnish kann alles
SplunkLive! Customer Presentation – Directv
SplunkLive! München 2016 - Splunk @ Datev
SplunkLive! München 2016 - Splunk @ UniCredit
Ad

Similar to SplunkLive! München 2016 - Splunk Enterprise 6.3 - Data Onboarding (20)

PPTX
Webinar: Neuigkeiten zu Splunk Enterprise 6.3
PPTX
What's New in 6.3 + Data On-Boarding
PPTX
Splunk Enterprise 6.3 - Splunk Tech Day
PPTX
Splunk - Verwandeln Sie Datensilos in Operational Intelligence
PDF
SplunkLive! Zürich 2016 - Splunk Enterprise 6.4
PDF
SplunkLive! Wien 2016 - Splunk Enterprise 6.4
PDF
Splunk Webinar: Neuigkeiten in Splunk Enterprise 6.4
PPTX
Splunk
PPTX
Getting Started with Splunk Enterprise
PPTX
What's New in Splunk 6.3
PPTX
Splunk Überblick
PPTX
Splunk for ITOps
PPTX
Getting Started with Splunk Enterprise
PPTX
Getting Started with Splunk Enterprise
PPTX
Getting Started with Splunk Enterprise Hands-On
PDF
Getting Started with Splunk Enterprise
PDF
Splunk for big_data
PPTX
Splunk Forum Frankfurt - 15th Nov 2017 - .conf2017 Update
PPTX
SplunkLive! Paris 2016 - Plenary session
PPTX
SplunkLive! Warsaw 2015 Keynote
Webinar: Neuigkeiten zu Splunk Enterprise 6.3
What's New in 6.3 + Data On-Boarding
Splunk Enterprise 6.3 - Splunk Tech Day
Splunk - Verwandeln Sie Datensilos in Operational Intelligence
SplunkLive! Zürich 2016 - Splunk Enterprise 6.4
SplunkLive! Wien 2016 - Splunk Enterprise 6.4
Splunk Webinar: Neuigkeiten in Splunk Enterprise 6.4
Splunk
Getting Started with Splunk Enterprise
What's New in Splunk 6.3
Splunk Überblick
Splunk for ITOps
Getting Started with Splunk Enterprise
Getting Started with Splunk Enterprise
Getting Started with Splunk Enterprise Hands-On
Getting Started with Splunk Enterprise
Splunk for big_data
Splunk Forum Frankfurt - 15th Nov 2017 - .conf2017 Update
SplunkLive! Paris 2016 - Plenary session
SplunkLive! Warsaw 2015 Keynote

More from Splunk (20)

PDF
Splunk Leadership Forum Wien - 20.05.2025
PDF
Splunk Security Update | Public Sector Summit Germany 2025
PDF
Building Resilience with Energy Management for the Public Sector
PDF
IT-Lagebild: Observability for Resilience (SVA)
PDF
Nach dem SOC-Aufbau ist vor der Automatisierung (OFD Baden-Württemberg)
PDF
Monitoring einer Sicheren Inter-Netzwerk Architektur (SINA)
PDF
Praktische Erfahrungen mit dem Attack Analyser (gematik)
PDF
Cisco XDR & Splunk SIEM - stronger together (DATAGROUP Cyber Security)
PDF
Security - Mit Sicherheit zum Erfolg (Telekom)
PDF
One Cisco - Splunk Public Sector Summit Germany April 2025
PDF
.conf Go 2023 - Data analysis as a routine
PDF
.conf Go 2023 - How KPN drives Customer Satisfaction on IPTV
PDF
.conf Go 2023 - Navegando la normativa SOX (Telefónica)
PDF
.conf Go 2023 - Raiffeisen Bank International
PDF
.conf Go 2023 - På liv og død Om sikkerhetsarbeid i Norsk helsenett
PDF
.conf Go 2023 - Many roads lead to Rome - this was our journey (Julius Bär)
PDF
.conf Go 2023 - Das passende Rezept für die digitale (Security) Revolution zu...
PDF
.conf go 2023 - Cyber Resilienz – Herausforderungen und Ansatz für Energiever...
PDF
.conf go 2023 - De NOC a CSIRT (Cellnex)
PDF
conf go 2023 - El camino hacia la ciberseguridad (ABANCA)
Splunk Leadership Forum Wien - 20.05.2025
Splunk Security Update | Public Sector Summit Germany 2025
Building Resilience with Energy Management for the Public Sector
IT-Lagebild: Observability for Resilience (SVA)
Nach dem SOC-Aufbau ist vor der Automatisierung (OFD Baden-Württemberg)
Monitoring einer Sicheren Inter-Netzwerk Architektur (SINA)
Praktische Erfahrungen mit dem Attack Analyser (gematik)
Cisco XDR & Splunk SIEM - stronger together (DATAGROUP Cyber Security)
Security - Mit Sicherheit zum Erfolg (Telekom)
One Cisco - Splunk Public Sector Summit Germany April 2025
.conf Go 2023 - Data analysis as a routine
.conf Go 2023 - How KPN drives Customer Satisfaction on IPTV
.conf Go 2023 - Navegando la normativa SOX (Telefónica)
.conf Go 2023 - Raiffeisen Bank International
.conf Go 2023 - På liv og død Om sikkerhetsarbeid i Norsk helsenett
.conf Go 2023 - Many roads lead to Rome - this was our journey (Julius Bär)
.conf Go 2023 - Das passende Rezept für die digitale (Security) Revolution zu...
.conf go 2023 - Cyber Resilienz – Herausforderungen und Ansatz für Energiever...
.conf go 2023 - De NOC a CSIRT (Cellnex)
conf go 2023 - El camino hacia la ciberseguridad (ABANCA)

Recently uploaded (20)

PDF
Review of recent advances in non-invasive hemoglobin estimation
PDF
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
PDF
NewMind AI Weekly Chronicles - August'25 Week I
PDF
Encapsulation theory and applications.pdf
PDF
Spectral efficient network and resource selection model in 5G networks
PPTX
A Presentation on Artificial Intelligence
PDF
Unlocking AI with Model Context Protocol (MCP)
PPTX
Effective Security Operations Center (SOC) A Modern, Strategic, and Threat-In...
PDF
Building Integrated photovoltaic BIPV_UPV.pdf
PDF
Network Security Unit 5.pdf for BCA BBA.
PPTX
Big Data Technologies - Introduction.pptx
PPTX
MYSQL Presentation for SQL database connectivity
PPT
Teaching material agriculture food technology
PDF
Shreyas Phanse Resume: Experienced Backend Engineer | Java • Spring Boot • Ka...
PDF
Chapter 3 Spatial Domain Image Processing.pdf
PPTX
KOM of Painting work and Equipment Insulation REV00 update 25-dec.pptx
PPTX
VMware vSphere Foundation How to Sell Presentation-Ver1.4-2-14-2024.pptx
DOCX
The AUB Centre for AI in Media Proposal.docx
PDF
Modernizing your data center with Dell and AMD
PPTX
Digital-Transformation-Roadmap-for-Companies.pptx
Review of recent advances in non-invasive hemoglobin estimation
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
NewMind AI Weekly Chronicles - August'25 Week I
Encapsulation theory and applications.pdf
Spectral efficient network and resource selection model in 5G networks
A Presentation on Artificial Intelligence
Unlocking AI with Model Context Protocol (MCP)
Effective Security Operations Center (SOC) A Modern, Strategic, and Threat-In...
Building Integrated photovoltaic BIPV_UPV.pdf
Network Security Unit 5.pdf for BCA BBA.
Big Data Technologies - Introduction.pptx
MYSQL Presentation for SQL database connectivity
Teaching material agriculture food technology
Shreyas Phanse Resume: Experienced Backend Engineer | Java • Spring Boot • Ka...
Chapter 3 Spatial Domain Image Processing.pdf
KOM of Painting work and Equipment Insulation REV00 update 25-dec.pptx
VMware vSphere Foundation How to Sell Presentation-Ver1.4-2-14-2024.pptx
The AUB Centre for AI in Media Proposal.docx
Modernizing your data center with Dell and AMD
Digital-Transformation-Roadmap-for-Companies.pptx

SplunkLive! München 2016 - Splunk Enterprise 6.3 - Data Onboarding

  • 1. Copyright © 2015 Splunk Inc. Splunk Enterprise 6.3 Was ist neu? Udo Götzen CISSP, Senior Sales Engineer In diesem Raum: 13:30 Splunk Enterprise 6.3 14:15 Splunk for ITOps
  • 3. 3 Industry Leading Platform For Machine Data Machine Data: Any Location, Type, Volume Online Services Web Services Servers Security GPS Location Storage Desktops Networks Packaged Applications Custom ApplicationsMessaging Telecoms Online Shopping Cart Web Clickstreams Databases Energy Meters Call Detail Records Smartphones and Devices RFID On- Premises Private Cloud Public Cloud Platform Support (Apps / API / SDKs) Enterprise Scalability Universal Indexing Answer Any Question Developer Platform Report and analyze Custom dashboards Monitor and alert Ad hoc search
  • 4. 4 Industry Leading Platform For Machine Data Machine Data: Any Location, Type, Volume Online Services Web Services Servers Security GPS Location Storage Desktops Networks Packaged Applications Custom ApplicationsMessaging Telecoms Online Shopping Cart Web Clickstreams Databases Energy Meters Call Detail Records Smartphones and Devices RFID On- Premises Private Cloud Public Cloud Platform Support (Apps / API / SDKs) Enterprise Scalability Universal Indexing Answer Any Question Developer Platform Report and analyze Custom dashboards Monitor and alert Ad hoc search Any amount, any location, any source Schema- on-the-fly Universal indexing No back-end RDBMS No need to filter data 4
  • 5. 5 Turn Machine Data into Operational Intelligence INDEX ANY MACHINE DATA: ANY SOURCE, TYPE, VOLUME Online Services Web Services Servers Security GPS Location Storage Desktops Networks Packaged Applications Custom ApplicationsMessaging Telecoms Online Shopping Cart Web Clickstreams Databases Energy Meters Call Detail Records Smartphones and Devices RFID On- Premises Private Cloud Public Cloud GAIN REAL-TIME VISIBILITY Application Delivery Security and Compliance Infrastructure Monitoring Business Analytics Internet of Things 5
  • 6. Setting the Standard for Operational Intelligence Engine Platform 1 2 3 2006-2008 Tool 2009-2011 2012-2016 4 4.1 4.2 4.3 5x 6x “Google for the datacenter” “Engine for machine- generated data” “Platform for Operational Intelligence” 6
  • 7. 7 Turning Machine Data Into Operational Intelligence Reactive Search and Investigate Proactive Monitoring and Alerting Operational Visibility Proactive Real-time Business Insight
  • 9. 9 Splunk Enterprise 6.3 Breakthrough Performance & Scale Doubles performance and lowers TCO • 2x Search & Indexing Speed • 20-50% Increased Capacity • 20%+ Reduced TCO Meeting the needs of the most demanding organizations Advanced Analysis & Visualization High-Volume Event Collection Enterprise-Scale Platform Supports DevOps and IoT data analysis at scale Simplifies analysis of large datasets Delivers Enterprise platform requirements • Anomaly Detection • Geospatial Mapping • Single-Value Display • HTTP Event Collector • Developer API & SDKs • 3rd Party Integrations • Expanded Management • Custom Alert Actions • Data Integrity Control
  • 10. 10 Breakthrough Performance, Scale, TCO 1 Search Performance Indexing Speed Intelligent Scheduling 25%+ Capacity Gain 2x Execution Speed 2-4x Data Rate Vertical scaling maximizes use of CPU power Total System Capacity 20-50% Increase Improve speed of searches & reports Onboard & analyze larger datasets Optimize resource utilization Reduce TCO by 20% or more Comparisons are to Splunk Enterprise 6.2. Customer performance and TCO will vary according to workload, configuration and available processing capacity.
  • 11. So What Does Breakthrough Mean? Critical reports can be available in ¼ the time It takes 20% less indexing hardware (HW) to expand or deploy Splunk New data is ready for analysis in ½ the time 1 Splunk expansion costs have dropped over 50% since 2013 A new customer can deploy Splunk using 1/3 the HW vs. 2013 Splunk deployment is now ½ the cost vs. 2013 Release 6.3 vs. Release 6.2 Release 6.3 vs. Release 6.0
  • 12. 12 NEW: HTTP Event Collector 1 • A new token-based JSON API for events • Send events directly from anywhere (servers, mobile devices, IOT) • Easy to configure / works out of the box. • Easy to secure • Highly performant, scalable and available
  • 15. 15 App Spotlight: Custom Visualizations
  • 16. Copyright © 2015 Splunk Inc. Vielen Dank! – Q&A

Editor's Notes

  • #2: Splunk Enterprise Security
  • #4: One of of the key differentiators of Splunk is the ability to digest all machine data and allow users to quickly analyze it for insight. We call this the universal machine data platform. We’ll look at this in more detail in a bit, but for now, understand that the platform was designed around the premise of being able to consume any machine data even if the format changes; something a relational database cannot do. (Splunk Cloud is only available in the U.S. and Canada.)
  • #5: Splunk software reliably collects and indexes all the streaming data from IT systems, technology devices and the Internet of Things in real-time - tens of thousands of sources in unpredictable formats and types. Splunk software is optimized for real-time, low latency and interactivity. Organizations use Splunk software and their data the following ways: 1. Find and fix problems dramatically faster 2. Automatically monitor to identify issues, problems and attacks 3. Gain end-to-end visibility to track and deliver on IT KPIs and make better-informed IT decisions 4. Gain real-time insight from operational data to make better-informed business decisions This is described as Operational Intelligence: visibility, insights and intelligence from operational data.
  • #6: Our customers typically start with Splunk to solve a specific problem, and then expand from there to address a broad range of use cases, across application troubleshooting, IT infrastructure monitoring, security, business analytics, Internet of things, and many others that are entirely innovated by our customers. Here’s how it works. Splunk software and cloud services reliably collect and index machine data, from a single source to tens of thousands of sources. All in real time. - Once data is in Splunk, you can search, analyze, report-on and derive insights from all your data - across real-time or historical data that may be stored in Hadoop or other NoSQL data sources.
  • #7: Splunk Enterprise is the industry leading software for machine data analytics and has been driving innovation and setting the standard for Operational Intelligence since 2006. In the beginning, we were first to introduce the paradigm of ‘search’ to IT – to troubleshoot IT operations and application management issues much faster than ever before and to find the proverbial “needle in the haystack”. When asking customers, they often referred to it as “google for the datacenter”. As the product evolved, Splunk 4 - the engine for machine data - introduced enterprise-class features – dashboards and apps, real-time search and alerts, universal collection and indexing, enterprise controls and map-reduce for horizontal scalability on commodity servers. And then in 2012 we introduced Splunk 5 – this release represented the evolution of Splunk as an Enterprise Platform for Operational Intelligence. It introduced breakthrough innovations and platform features that included:   A new reporting architecture and transparent summarization technology delivering dramatically faster reports A new high availability architecture delivering enterprise-class scale and resilience, even while scaling on commodity servers and storage A robust developer API and SDKs available in mainstream programming languages to enable enterprise developers to leverage Splunk software Big data ecosystem integrations that included Splunk Hadoop Connect, Splunk DB Connect and the Splunk App for HadoopOps And continuing our strategy of delivering you the Platform for Operational Intelligence we introduce you to Splunk 6 - The most advanced version of Splunk software ever. Splunk 6 delivers new and powerful analytics features designed for broader use: non-technical and technical users alike. Splunk 6 is our most advanced version of Splunk software ever – the industry-leading machine data platform. Powerful Analytics: Splunk Enterprise 6 takes large-scale machine data analytics to the next level by introducing three breakthrough innovations: Pivot – opens up the power of analytics to non-technical users with an easy-to-use drag and drop interface to explore, manipulate and visualize data Data Model – defines meaningful relationships in underlying machine data and makes this data more useful to a broader base of users, in particular non-technical users Analytics Store – patent-pending technology that accelerates data models by delivering extremely high performance data retrieval for analytical processing, up to 1000x faster than Splunk Enterprise 5   The new Pivot interface, combined with Data Models and Analytics Store makes it dramatically easier for non-technical users and technical users alike to analyze and visualize data in Splunk. Now more users than ever are empowered by Splunk software to get insights from their machine data.   Intuitive User Experience: Splunk Enterprise 6 includes powerful productivity features for users with a more intuitive user experience: The new Home Experience – gives users instant access to the data, apps and content they care about The Enhanced Search Experience – brings search and reporting together – so users can author rich – dynamic reports - build visualizations – tables – and custom searches – faster than ever before Simplified Management We’ve made Splunk Enterprise 6 easier to deploy, configure and manage – even as customers expand their Splunk Enterprise deployments to the multi-terabyte scale Simplified Cluster Management – deliver easier management of mission-critical Splunk software deployments providing everything the Splunk admin needs to monitor high availability on a centralized dashboard Forwarder Management – support big data scale with easy configuration and management of thousands of forwarders across multiple geographies   Rich Developer Environment And now Splunk Enterprise 6 provides a more powerful developer environment with the integrated Web Framework. Developers can build custom Splunk Apps, customize dashboards, or add advanced functionality - using standard web technologies, such as JavaScript and Django. Splunk 6 represents a significant milestone in our mission to make machine data accessible, usable and valuable by everyone. Find out more at www.splunk.com/6
  • #8: One of the great things about Splunk is that you don’t have to start big. Many organizations start using Splunk to solve a single problem. From there, they quickly see the value and begin to expand within the organization. Let’s take a look at how customer deployments often mature. The point I want you to see here is that it’s not unusual to start small, but make sure you plan to go big. Let’s start with Search and investigation, which is where many customers start. Using Splunk, organizations identify and resolve issues up to 70% faster and reduce costly escalations by up to 90%. Splunk is one place to find and fix problems, and investigate incidents across all your IT systems and infrastructure. In the Proactive monitoring stage we begin to monitor IT systems in real time to identify issues, problems and attacks before they impact your customers, services and revenue. Splunk keeps watch of specific patterns, trends and thresholds in your machine data so you don't have to. We trigger notifications in real-time via email or RSS, execute a script to take remedial actions. We can also send an SNMP trap to your system management console or generate a service desk ticket. From here we get into Operational visibility. We can now see the whole picture, track performance and make better decisions. We can visualize usage trends to better plan for capacity; spot SLA infractions, track how you are being measured by the business. We do all of this using your existing machine data without spending millions of dollars instrumenting your IT infrastructure. And finally we reach Real-time business insight. We can now make better-informed business decisions by understanding trends, patterns and gaining Operational Intelligence from your machine data. See the success of new online services by channel or demographic, reconcile 3rd-party service provider fees against actual use, find your heaviest users and heaviest abusers, and more. Because machine data captures every behavior, the possibilities are game changing. You'll find the lead times to get to this intelligence dramatically less than other solutions - measured in minutes/hours instead of months.
  • #10: Splunk is the industry-leading platform for Operational Intelligence, delivering both cloud and on-premise solutions tailored to meet the needs of any size organization. Splunk is increasingly being used as a mission-critical, enterprise-wide operational intelligence source, processing 100's of terabytes of data per day. Release 6.3 continues our journey to support the ever-expanding requirements of the most demanding organizations Release 6.3 is especially targeted to meet their needs for scalability and management, extended analysis features, analysis of high-volume data from application and IoT events, and new flexible connectivity options to their business and operational systems. Release 6.3 is a platform release. All 6.3 features are supported on Splunk Enterprise, most on Splunk Cloud, and select features are supported on the Hunk and Splunk Light products
  • #11: Organizations are increasingly standardizing their datacenter operations on economically priced servers supporting 16 or more CPU cores. Splunk Enterprise Release 6.3 now supports vertical scaling capabilities to take better advantage of this available power to:   Improve search and reporting performance (Double the performance of most search and reporting activities) Increase data onboarding capacity (Double the peak data onboarding speed vs Double the data onboarding speed) Reduce operating costs (Reduce operating costs by 20% or more)   Previously, Splunk made use of available CPU cores to execute multiple simultaneous searches while indexing data. Release 6.3 vertical scaling uses allows both individual searches and the data indexing process to execute more efficiently by using multiple CPU cores per task. For systems with available CPU cores, the benefits are broad performance improvements in search processing, report generation, data on-boarding capacity and data forwarding efficiency. Why capacity gain overall? Intelligent scheduling should increase capacity somewhat by optimally scheduling jobs Allowing indexing to use additional cores means that burst data can be handled on the same system, and generally that more data/day overall can be processed. This does not necessarily require totally free CPUs to be permanently available, it can just use additional when needed If there is some available CPU capacity, then running searches faster may mean that more can be done We think most customers are not using their systems to full capacity today. Cores do not have to be otherwise idle in order for gains to be seen The net effect of all of this is a 20%+ gain. 50% for typical security scenarios TCO Influencers Indexer HW reduction System capacity gains – data/searches; job scheduling Standardization of datacenter HW configuration on higher core systems Simpler management: DMC, indexer auto discovery, single-instance indexers and forwarders
  • #12: Report 1H vs 10 mins – assumes 5 or 6 cores are used. (in next release you can control core usage per search) Data ready in half the time – this is moving from 4 to 8 cores for indexing – so a burst takes half 20% capacity reflects our guidance changing from 250 to 300 GB/day 20% indexing HW – same reasoning Tripled since 2013 is our guidance moving from 100 to 300 (6.0 was 100) Expansion drop 50% - reflects 1/3 less indexer HW, but overall TCO is more than that, so downgraded to 50% instead of saying 66% TCO reduction 1/3 less HW – based on 100 to 300 increase New cost 50% lower – same as expansion cost