Copyright © 2016 Splunk Inc.
Nationwide
2
John Villacres
Network Automation and Tools
Nationwide
3
Nationwide Overview
• We are on your side
• Network support for 40,000 employees
• 10,000+ agents and employees use VPN remote access daily
• Multiple data centers, lots of devices and applications
4
My Background and Role
• Ohio State University – Go Bucks!
• First career as a pilot – Helicopters, Learjets, flight instructor
• Now Cisco routers and switches. Also FW, LB, Wifi, ACS, ISE, VPN
• Four year Splunk user
• Network Automation and Tools – Splunk, Gigamon, ExtraHop, Sniffers
• My favorite Splunk tag line: ‘I like big data and I cannot lie’
• Fun fact about me: If you attended a Woody Hayes speaking event in
1984, I probably drove him there.
5
How We Got Started
• I demonstrated Splunk to architects and managers in 2012
• Free versions of Splunk in lab (10 x 500MB/day, shift stream every 2 hrs)
• Used on high priority outage calls until it caught on
• We now publish user dashboards for about 12 support teams
• Integrated Splunk with ExtraHop and Savvius
6
Before Splunk
• Data is mostly there, but cumbersome to get, then difficult to interpret
in a timely manner
• Opaque hindsight after major replacements and upgrades to network
• Tools used - Syslogs, router, switch information and packet sniffers to
monitor network data
• Difficult to run/store long-term packet captures, network data
7
New Process Needed
• No access to user’s connection history when they call in for assistance
• Trouble Tickets for connection issues - blocked IP addresses forwarded
to firewall team and wait for response (or start grep-ing)
• Unable to maintain visibility through packet captures/monitoring
sessions without losing wire data:
• 16TB full packet < 100GB ExtraHop select data -> Splunk!
8
Finding Value With Splunk
• All the data you need to solve a user’s VPN issue in 10 seconds
• The data was already there in sylogs in folders, but data was not useable
• Are any one of the 200+ legacy firewalls blocking your app? Self service
via Firewall dashboard (12 seconds instead of a day)
• Agents can write more policies and generate revenue with enhanced
network support
• Support teams have reduced resolution time from days to minutes
9
Timely, Useable Data
• Support teams can resolve firewall issues themselves in minutes
• ExtraHop trigger – 1500 byte packet -> 20 useful bytes of data -> Splunk
time chart -> determine in two seconds through JSESSIONIDs if they’re
balanced properly across JVM’s
• Months of data are now quickly available through custom dashboards
• Humans avoid activities that are difficult and have low resolution probability
Splunk Use Cases
Central Logging
& Visibility
Security
Dashboards
& Reporting
Threat Prevention
& Alerting
Metrics
& Searches
11
How We Use Splunk
• Resolving VPN, firewall, and config change issues with custom
dashboards
• Splunk software serving support operations
• Data sources include wire data, router/switch/firewall syslogs, Cisco
ACS/ISE and others
• Who’s been messin’ with my router?
• Pursuing data the way I want; to make the decisions the way we
want (self service)
12
From this… to this!
grep…arg!
Click…smile 
13
From this… to this!
grep…arg!
Click…smile 
14
15
Growing With Splunk
• Other teams and departments have trained on, and cloned some our
dashboards for their own needs
• Because of Splunk’s efficiency, we have successfully transitioned
employees on to other tasks while continuing with productivity
• Currently reconstituting wire data capability
16
Top Takeaways
• The data may already be there. But now you can access it faster, and
make more sense out of it once you have it.
• “Teach someone how to fish” with Splunk software
• MTTR times go down; sometimes way down
17
Get a Good Night’s Sleep…
“What would normally take me hours or
even days to resolve takes me minutes to an
hour using Splunk.”
– John
Thank You

More Related Content

PPTX
Customer Presentation
PPTX
Customer Presentation
PPTX
How to Design, Build and Map IT and Business Services in Splunk
PPTX
Power of Splunk Search Processing Language (SPL)
PPTX
SplunkLive! Customer Presentation – athenahealth
PDF
Splunk Sales Presentation Imagemaker 2014
PPTX
SplunkLive! Austin Customer Presentation - Dell
PPTX
How to Design, Build and Map IT and Business Services in Splunk
Customer Presentation
Customer Presentation
How to Design, Build and Map IT and Business Services in Splunk
Power of Splunk Search Processing Language (SPL)
SplunkLive! Customer Presentation – athenahealth
Splunk Sales Presentation Imagemaker 2014
SplunkLive! Austin Customer Presentation - Dell
How to Design, Build and Map IT and Business Services in Splunk

What's hot (20)

PDF
Splunk @ Adobe
PDF
SplunkLive! Austin Customer Presentation - Xerox
PPTX
Getting Started with Splunk (Hands-On)
PPTX
Splunk at Aaron's Inc
PPTX
Getting Started with Splunk Enterprise
PPTX
Splunk for IT Operations
PPTX
Cisco UCS and Splunk Workshop
PPT
SplunkLive! Customer Presentation - Penn State Hershey Medical Center
PPTX
SplunkLive! Customer Presentation - Cardinal Health
PPTX
SplunkLive! Customer Presentation - Satcom Direct
PPTX
SplunkLive! Customer Presentation - Staples
PPTX
Cisco and Splunk: Under the Hood of Cisco IT Breakout Session
PDF
Herbalife Customer Presentation
PPTX
Splunk for Developers
PPTX
SplunkLive! - Splunk for IT Operations
PPTX
University of Alberta Customer Presentation
PPTX
SplunkLive! Utrecht 2016 - NXP
PDF
Machine Data 101
PPTX
Data Onboarding Breakout Session
PPTX
Splunk and Cisco UCS Breakout Session
Splunk @ Adobe
SplunkLive! Austin Customer Presentation - Xerox
Getting Started with Splunk (Hands-On)
Splunk at Aaron's Inc
Getting Started with Splunk Enterprise
Splunk for IT Operations
Cisco UCS and Splunk Workshop
SplunkLive! Customer Presentation - Penn State Hershey Medical Center
SplunkLive! Customer Presentation - Cardinal Health
SplunkLive! Customer Presentation - Satcom Direct
SplunkLive! Customer Presentation - Staples
Cisco and Splunk: Under the Hood of Cisco IT Breakout Session
Herbalife Customer Presentation
Splunk for Developers
SplunkLive! - Splunk for IT Operations
University of Alberta Customer Presentation
SplunkLive! Utrecht 2016 - NXP
Machine Data 101
Data Onboarding Breakout Session
Splunk and Cisco UCS Breakout Session
Ad

Viewers also liked (20)

PDF
Getting Started with Splunk Hands-on
PPTX
Why Content Marketing Fails
PDF
The History of SEO
PDF
Digital Strategy 101
PDF
How Google Works
PDF
Understanding FICO Scores - myFICO
PPTX
Getting started with Splunk
PDF
SplunkLive! Washington DC May 2013 - Search Language Beginner
PDF
Using splunk6.2 labs
PPTX
Power of SPL
DOCX
Security Hands-On - Splunklive! Houston
PPTX
SplunkLive! Customer Presentation - Garmin International
PPTX
Best Practices For Sharing Data Across The Enteprrise
PPTX
SplunkLive! Wien 2016 - Use Case TTTech Computertechnik
PDF
Viasat Customer Presentation
PPTX
Splunk for ITOA Breakout Session
PPTX
Get your Service Intelligence off to a Flying Start
PPTX
Daten anonymisieren und pseudonymisieren in Splunk Enterprise
PPTX
AWS Loft London: Finding the signal in the noise - Effective SecOps with Soph...
PDF
Ecetera uses Splunk to facilitate DevOps in forex
Getting Started with Splunk Hands-on
Why Content Marketing Fails
The History of SEO
Digital Strategy 101
How Google Works
Understanding FICO Scores - myFICO
Getting started with Splunk
SplunkLive! Washington DC May 2013 - Search Language Beginner
Using splunk6.2 labs
Power of SPL
Security Hands-On - Splunklive! Houston
SplunkLive! Customer Presentation - Garmin International
Best Practices For Sharing Data Across The Enteprrise
SplunkLive! Wien 2016 - Use Case TTTech Computertechnik
Viasat Customer Presentation
Splunk for ITOA Breakout Session
Get your Service Intelligence off to a Flying Start
Daten anonymisieren und pseudonymisieren in Splunk Enterprise
AWS Loft London: Finding the signal in the noise - Effective SecOps with Soph...
Ecetera uses Splunk to facilitate DevOps in forex
Ad

Similar to Customer Presentation (20)

PPTX
Splunk at Sabre
PDF
Splunk in the Cisco Unified Computing System (UCS)
PDF
Echostar Customer Presentation
PPTX
Getting Started with Splunk Breakout Session
PPTX
SplunkLive! Austin Customer Presentation - Baylor
PPTX
Taking Splunk to the Next Level – Architecture
PDF
Hadoop: The Unintended Benefits
PPTX
Customer Presentation - Telus
PPTX
Webinar: Improve Splunk Analytics and Automate Processes with SnapLogic
PPTX
[DSC Europe 23] Josip Saban - Cloud warehouse monitoring - Snowflake case stu...
PPTX
Getting Started with Splunk Breakout Session
PDF
Rakuten’s Journey with Splunk - Evolution of Splunk as a Service
PPTX
Getting Started with Splunk Breakout Session
PPTX
SplunkLive! Customer Presentation – Covance Inc"
PPTX
Splunk live! Customer Presentation – Wellsfargo
PPTX
Getting Started with Splunk Enterprise Hands-On Breakout Session
PPTX
Getting Started with Splunk Enterprise
PPTX
Getting Started with Splunk Enterprise
PDF
Spotify: Data center & Backend buildout
PPTX
Challenges in Practicing High Frequency Releases in Cloud Environments
Splunk at Sabre
Splunk in the Cisco Unified Computing System (UCS)
Echostar Customer Presentation
Getting Started with Splunk Breakout Session
SplunkLive! Austin Customer Presentation - Baylor
Taking Splunk to the Next Level – Architecture
Hadoop: The Unintended Benefits
Customer Presentation - Telus
Webinar: Improve Splunk Analytics and Automate Processes with SnapLogic
[DSC Europe 23] Josip Saban - Cloud warehouse monitoring - Snowflake case stu...
Getting Started with Splunk Breakout Session
Rakuten’s Journey with Splunk - Evolution of Splunk as a Service
Getting Started with Splunk Breakout Session
SplunkLive! Customer Presentation – Covance Inc"
Splunk live! Customer Presentation – Wellsfargo
Getting Started with Splunk Enterprise Hands-On Breakout Session
Getting Started with Splunk Enterprise
Getting Started with Splunk Enterprise
Spotify: Data center & Backend buildout
Challenges in Practicing High Frequency Releases in Cloud Environments

More from Splunk (20)

PDF
Splunk Leadership Forum Wien - 20.05.2025
PDF
Splunk Security Update | Public Sector Summit Germany 2025
PDF
Building Resilience with Energy Management for the Public Sector
PDF
IT-Lagebild: Observability for Resilience (SVA)
PDF
Nach dem SOC-Aufbau ist vor der Automatisierung (OFD Baden-Württemberg)
PDF
Monitoring einer Sicheren Inter-Netzwerk Architektur (SINA)
PDF
Praktische Erfahrungen mit dem Attack Analyser (gematik)
PDF
Cisco XDR & Splunk SIEM - stronger together (DATAGROUP Cyber Security)
PDF
Security - Mit Sicherheit zum Erfolg (Telekom)
PDF
One Cisco - Splunk Public Sector Summit Germany April 2025
PDF
.conf Go 2023 - Data analysis as a routine
PDF
.conf Go 2023 - How KPN drives Customer Satisfaction on IPTV
PDF
.conf Go 2023 - Navegando la normativa SOX (Telefónica)
PDF
.conf Go 2023 - Raiffeisen Bank International
PDF
.conf Go 2023 - På liv og død Om sikkerhetsarbeid i Norsk helsenett
PDF
.conf Go 2023 - Many roads lead to Rome - this was our journey (Julius Bär)
PDF
.conf Go 2023 - Das passende Rezept für die digitale (Security) Revolution zu...
PDF
.conf go 2023 - Cyber Resilienz – Herausforderungen und Ansatz für Energiever...
PDF
.conf go 2023 - De NOC a CSIRT (Cellnex)
PDF
conf go 2023 - El camino hacia la ciberseguridad (ABANCA)
Splunk Leadership Forum Wien - 20.05.2025
Splunk Security Update | Public Sector Summit Germany 2025
Building Resilience with Energy Management for the Public Sector
IT-Lagebild: Observability for Resilience (SVA)
Nach dem SOC-Aufbau ist vor der Automatisierung (OFD Baden-Württemberg)
Monitoring einer Sicheren Inter-Netzwerk Architektur (SINA)
Praktische Erfahrungen mit dem Attack Analyser (gematik)
Cisco XDR & Splunk SIEM - stronger together (DATAGROUP Cyber Security)
Security - Mit Sicherheit zum Erfolg (Telekom)
One Cisco - Splunk Public Sector Summit Germany April 2025
.conf Go 2023 - Data analysis as a routine
.conf Go 2023 - How KPN drives Customer Satisfaction on IPTV
.conf Go 2023 - Navegando la normativa SOX (Telefónica)
.conf Go 2023 - Raiffeisen Bank International
.conf Go 2023 - På liv og død Om sikkerhetsarbeid i Norsk helsenett
.conf Go 2023 - Many roads lead to Rome - this was our journey (Julius Bär)
.conf Go 2023 - Das passende Rezept für die digitale (Security) Revolution zu...
.conf go 2023 - Cyber Resilienz – Herausforderungen und Ansatz für Energiever...
.conf go 2023 - De NOC a CSIRT (Cellnex)
conf go 2023 - El camino hacia la ciberseguridad (ABANCA)

Recently uploaded (20)

PPTX
Configure Apache Mutual Authentication
PDF
STKI Israel Market Study 2025 version august
PDF
How ambidextrous entrepreneurial leaders react to the artificial intelligence...
PDF
Statistics on Ai - sourced from AIPRM.pdf
PPTX
MicrosoftCybserSecurityReferenceArchitecture-April-2025.pptx
PPT
Geologic Time for studying geology for geologist
PPTX
Build Your First AI Agent with UiPath.pptx
PDF
Architecture types and enterprise applications.pdf
PDF
Five Habits of High-Impact Board Members
PDF
Comparative analysis of machine learning models for fake news detection in so...
PDF
UiPath Agentic Automation session 1: RPA to Agents
PDF
Convolutional neural network based encoder-decoder for efficient real-time ob...
PPTX
Training Program for knowledge in solar cell and solar industry
PDF
The influence of sentiment analysis in enhancing early warning system model f...
PDF
Improvisation in detection of pomegranate leaf disease using transfer learni...
PDF
How IoT Sensor Integration in 2025 is Transforming Industries Worldwide
PDF
Enhancing plagiarism detection using data pre-processing and machine learning...
PDF
NewMind AI Weekly Chronicles – August ’25 Week III
PPT
Module 1.ppt Iot fundamentals and Architecture
PDF
CloudStack 4.21: First Look Webinar slides
Configure Apache Mutual Authentication
STKI Israel Market Study 2025 version august
How ambidextrous entrepreneurial leaders react to the artificial intelligence...
Statistics on Ai - sourced from AIPRM.pdf
MicrosoftCybserSecurityReferenceArchitecture-April-2025.pptx
Geologic Time for studying geology for geologist
Build Your First AI Agent with UiPath.pptx
Architecture types and enterprise applications.pdf
Five Habits of High-Impact Board Members
Comparative analysis of machine learning models for fake news detection in so...
UiPath Agentic Automation session 1: RPA to Agents
Convolutional neural network based encoder-decoder for efficient real-time ob...
Training Program for knowledge in solar cell and solar industry
The influence of sentiment analysis in enhancing early warning system model f...
Improvisation in detection of pomegranate leaf disease using transfer learni...
How IoT Sensor Integration in 2025 is Transforming Industries Worldwide
Enhancing plagiarism detection using data pre-processing and machine learning...
NewMind AI Weekly Chronicles – August ’25 Week III
Module 1.ppt Iot fundamentals and Architecture
CloudStack 4.21: First Look Webinar slides

Customer Presentation

  • 1. Copyright © 2016 Splunk Inc. Nationwide
  • 2. 2 John Villacres Network Automation and Tools Nationwide
  • 3. 3 Nationwide Overview • We are on your side • Network support for 40,000 employees • 10,000+ agents and employees use VPN remote access daily • Multiple data centers, lots of devices and applications
  • 4. 4 My Background and Role • Ohio State University – Go Bucks! • First career as a pilot – Helicopters, Learjets, flight instructor • Now Cisco routers and switches. Also FW, LB, Wifi, ACS, ISE, VPN • Four year Splunk user • Network Automation and Tools – Splunk, Gigamon, ExtraHop, Sniffers • My favorite Splunk tag line: ‘I like big data and I cannot lie’ • Fun fact about me: If you attended a Woody Hayes speaking event in 1984, I probably drove him there.
  • 5. 5 How We Got Started • I demonstrated Splunk to architects and managers in 2012 • Free versions of Splunk in lab (10 x 500MB/day, shift stream every 2 hrs) • Used on high priority outage calls until it caught on • We now publish user dashboards for about 12 support teams • Integrated Splunk with ExtraHop and Savvius
  • 6. 6 Before Splunk • Data is mostly there, but cumbersome to get, then difficult to interpret in a timely manner • Opaque hindsight after major replacements and upgrades to network • Tools used - Syslogs, router, switch information and packet sniffers to monitor network data • Difficult to run/store long-term packet captures, network data
  • 7. 7 New Process Needed • No access to user’s connection history when they call in for assistance • Trouble Tickets for connection issues - blocked IP addresses forwarded to firewall team and wait for response (or start grep-ing) • Unable to maintain visibility through packet captures/monitoring sessions without losing wire data: • 16TB full packet < 100GB ExtraHop select data -> Splunk!
  • 8. 8 Finding Value With Splunk • All the data you need to solve a user’s VPN issue in 10 seconds • The data was already there in sylogs in folders, but data was not useable • Are any one of the 200+ legacy firewalls blocking your app? Self service via Firewall dashboard (12 seconds instead of a day) • Agents can write more policies and generate revenue with enhanced network support • Support teams have reduced resolution time from days to minutes
  • 9. 9 Timely, Useable Data • Support teams can resolve firewall issues themselves in minutes • ExtraHop trigger – 1500 byte packet -> 20 useful bytes of data -> Splunk time chart -> determine in two seconds through JSESSIONIDs if they’re balanced properly across JVM’s • Months of data are now quickly available through custom dashboards • Humans avoid activities that are difficult and have low resolution probability
  • 10. Splunk Use Cases Central Logging & Visibility Security Dashboards & Reporting Threat Prevention & Alerting Metrics & Searches
  • 11. 11 How We Use Splunk • Resolving VPN, firewall, and config change issues with custom dashboards • Splunk software serving support operations • Data sources include wire data, router/switch/firewall syslogs, Cisco ACS/ISE and others • Who’s been messin’ with my router? • Pursuing data the way I want; to make the decisions the way we want (self service)
  • 12. 12 From this… to this! grep…arg! Click…smile 
  • 13. 13 From this… to this! grep…arg! Click…smile 
  • 14. 14
  • 15. 15 Growing With Splunk • Other teams and departments have trained on, and cloned some our dashboards for their own needs • Because of Splunk’s efficiency, we have successfully transitioned employees on to other tasks while continuing with productivity • Currently reconstituting wire data capability
  • 16. 16 Top Takeaways • The data may already be there. But now you can access it faster, and make more sense out of it once you have it. • “Teach someone how to fish” with Splunk software • MTTR times go down; sometimes way down
  • 17. 17 Get a Good Night’s Sleep… “What would normally take me hours or even days to resolve takes me minutes to an hour using Splunk.” – John