SlideShare a Scribd company logo
Copyright © 2013 Splunk Inc.

Analytics with Splunk
Enterprise – Part 1
Legal Notices
During the course of this presentation, we may make forward-looking statements regarding future events or the
expected performance of the company. We caution you that such statements reflect our current
expectations and estimates based on factors currently known to us and that actual events or results could differ
materially. For important factors that may cause actual results to differ from those contained in our forward-looking
statements, please review our filings with the SEC. The forward-looking statements made in this presentation are
being made as of the time and date of its live presentation. If reviewed after its live presentation, this presentation
may not contain current or accurate information. We do not assume any obligation to update any forward-looking
statements we may make. In addition, any information about our roadmap outlines our general product direction
and is subject to change at any time without notice. It is for informational purposes only and shall not, be
incorporated into any contract or other commitment. Splunk undertakes no obligation either to develop the
features or functionality described or to include any such feature or functionality in a future release.
Splunk, Splunk>, Splunk Storm, Listen to Your Data, SPL and The Engine for Machine Data are trademarks and registered trademarks of
Splunk Inc. in the United States and other countries. All other brand names, product names, or trademarks belong to their respective
owners.

©2013 Splunk Inc. All rights reserved.
Agenda
•

Context

•

Overview

•

Examples

•

Q&A
Context
Search is hard.
Sorkin?
SplunkLive! Analytics with Splunk Enterprise - Part 1
Analytics Big Picture
Pivot

Build complex reports without the
search language

Data
Model

Provides more meaningful representation
of underlying raw machine data

Analytics
Store

Acceleration technology delivers up to
1000x faster analytics over Splunk 5

8
Operational Intelligence Across the Enterprise
[10/11/12

18:57:04
000000b0

UTC]

Raw
Data

IT professional
Create and share data models
Accelerate data models and custom
searches with the analytics store
Create reports with pivot

Analytics
Store

Developer
Leverage data models to
abstract data
Leverage pivot in custom apps

Data
Model

Pivot

Analyst
Create reports using pivot based on
data models created by IT
Pivot is a query builder.
Data Models 101
What is a Data Model?
A data model is a search-time mapping of data onto a hierarchical structure
•

Encapsulate the knowledge
needed to build a search

•

Pivot reports are build on top
of data models

•

Data-independent

Screenshot here
search and filter | munge | report | clean-up

sourcetype=access_combined source = "/home/ssorkin/banner_access.log.2013.6.gz"
| eval unique=(uid + useragent) | stats dc(unique) by os_name
| rename dc(unique) as "Unique Visitors" os_name as "Operating System"
A Data Model Is a Collection of Objects

Screenshot here
Objects Have Constraints and Attributes

Screenshot here
Child Objects Inherit Constraints and Attributes

Screenshot here
Child Objects Inherit Constraints and Attributes
Source
Data set

Source
Source
Success
Sourcetype

Failure
Warning
Source
Business division
Source
Data set
Source
Business division

Source
Technology 1
Common model

Technology 2
Technology 3
Thank You

More Related Content

PPTX
SplunkLive! Analytics with Splunk Enterprise - Part 2
PDF
SplunkLive! Washington DC May 2013 - Search Language Beginner
PPTX
SplunkLive! Dallas Nov 2012 - Metro PCS
PPTX
Power of SPL Breakout Session
PPTX
SplunkLive! Data Models 101
PPTX
Analytics with splunk - Advanced
PPTX
SplunkLive! Beginner Session
PPTX
Splunk overview
SplunkLive! Analytics with Splunk Enterprise - Part 2
SplunkLive! Washington DC May 2013 - Search Language Beginner
SplunkLive! Dallas Nov 2012 - Metro PCS
Power of SPL Breakout Session
SplunkLive! Data Models 101
Analytics with splunk - Advanced
SplunkLive! Beginner Session
Splunk overview

What's hot (20)

PPTX
Splunk Ninjas Breakout Session
PPTX
Splunk live beginner training nyc
PDF
Building a Recommendation Engine Using Diverse Features by Divyanshu Vats
PDF
Jeeves Grows Up: An AI Chatbot for Performance and Quality
PDF
Observability and its application
PPTX
Splunk - Buisness Intelligence tool
PDF
Analytics With PowerBI On Azure
PDF
Why APM Is Not the Same As ML Monitoring
PDF
Webinar: Event Processing & Data Analytics with Lucidworks Fusion
PDF
FrugalML: Using ML APIs More Accurately and Cheaply
PDF
Warehousing Your Hits - The Why and How of Owning Your Data
PDF
Learning to Rank Datasets for Search with Oscar Castaneda
PPTX
Megan Kurka, H2O.ai - AutoDoc with H2O Driverless AI - H2O World 2019 NYC
PPTX
Basic Sentiment Analysis using Hive
PDF
The More the Merrier: Scaling Model Building Infrastructure at Zendesk
PDF
Importance of ML Reproducibility & Applications with MLfLow
PDF
Moving to Solr/Lucene Open Source Search
PPTX
How Lyft Drives Data Discovery
PPTX
Data council sf amundsen presentation
PPTX
How Lyft Drives Data Discovery
Splunk Ninjas Breakout Session
Splunk live beginner training nyc
Building a Recommendation Engine Using Diverse Features by Divyanshu Vats
Jeeves Grows Up: An AI Chatbot for Performance and Quality
Observability and its application
Splunk - Buisness Intelligence tool
Analytics With PowerBI On Azure
Why APM Is Not the Same As ML Monitoring
Webinar: Event Processing & Data Analytics with Lucidworks Fusion
FrugalML: Using ML APIs More Accurately and Cheaply
Warehousing Your Hits - The Why and How of Owning Your Data
Learning to Rank Datasets for Search with Oscar Castaneda
Megan Kurka, H2O.ai - AutoDoc with H2O Driverless AI - H2O World 2019 NYC
Basic Sentiment Analysis using Hive
The More the Merrier: Scaling Model Building Infrastructure at Zendesk
Importance of ML Reproducibility & Applications with MLfLow
Moving to Solr/Lucene Open Source Search
How Lyft Drives Data Discovery
Data council sf amundsen presentation
How Lyft Drives Data Discovery
Ad

Similar to SplunkLive! Analytics with Splunk Enterprise - Part 1 (20)

PDF
Service intelligence hands on workshop
PDF
Service Intelligence hands on workshop
PDF
Service intelligence hands on workshop
PPTX
Getting Started with Splunk Enterprise
PDF
Building an Analytics Enables SOC
PPTX
SplunkLive! Zurich 2018: Legacy SIEM to Splunk, How to Conquer Migration and ...
PPTX
SplunkLive! Frankfurt 2018 - Legacy SIEM to Splunk, How to Conquer Migration ...
PPTX
Getting Started with Splunk Enterprises
PPTX
Accelerate Troubleshooting and Reinvent Monitoring with Interactive Visualiza...
PPTX
SplunkLive! Tampa: Getting Started Session
PPTX
SplunkLive! What's New in Splunk 6 Session
PDF
Splunk in Staples: IT Operations
PPTX
Webinar: Neuigkeiten zu Splunk Enterprise 6.3
PPTX
SplunkLive! Frankfurt 2018 - Predictive, Proactive, and Collaborative ML with...
PDF
SplunkLive! Warsaw 2016 - Machine Learning
PDF
Splunk Discovery: Warsaw 2018 - Legacy SIEM to Splunk, How to Conquer Migrati...
PPTX
SplunkLive! Frankfurt 2018 - Get More From Your Machine Data with Splunk AI
PDF
Splunk Webinar: Mit Splunk SPL Maschinendaten durchsuchen, transformieren und...
PPTX
SplunkLive! Zurich 2018: Get More From Your Machine Data with Splunk & AI
PPTX
Splunk Forum Frankfurt - 15th Nov 2017 - Machine Learning For Event Management
Service intelligence hands on workshop
Service Intelligence hands on workshop
Service intelligence hands on workshop
Getting Started with Splunk Enterprise
Building an Analytics Enables SOC
SplunkLive! Zurich 2018: Legacy SIEM to Splunk, How to Conquer Migration and ...
SplunkLive! Frankfurt 2018 - Legacy SIEM to Splunk, How to Conquer Migration ...
Getting Started with Splunk Enterprises
Accelerate Troubleshooting and Reinvent Monitoring with Interactive Visualiza...
SplunkLive! Tampa: Getting Started Session
SplunkLive! What's New in Splunk 6 Session
Splunk in Staples: IT Operations
Webinar: Neuigkeiten zu Splunk Enterprise 6.3
SplunkLive! Frankfurt 2018 - Predictive, Proactive, and Collaborative ML with...
SplunkLive! Warsaw 2016 - Machine Learning
Splunk Discovery: Warsaw 2018 - Legacy SIEM to Splunk, How to Conquer Migrati...
SplunkLive! Frankfurt 2018 - Get More From Your Machine Data with Splunk AI
Splunk Webinar: Mit Splunk SPL Maschinendaten durchsuchen, transformieren und...
SplunkLive! Zurich 2018: Get More From Your Machine Data with Splunk & AI
Splunk Forum Frankfurt - 15th Nov 2017 - Machine Learning For Event Management
Ad

More from Splunk (20)

PDF
Splunk Leadership Forum Wien - 20.05.2025
PDF
Splunk Security Update | Public Sector Summit Germany 2025
PDF
Building Resilience with Energy Management for the Public Sector
PDF
IT-Lagebild: Observability for Resilience (SVA)
PDF
Nach dem SOC-Aufbau ist vor der Automatisierung (OFD Baden-Württemberg)
PDF
Monitoring einer Sicheren Inter-Netzwerk Architektur (SINA)
PDF
Praktische Erfahrungen mit dem Attack Analyser (gematik)
PDF
Cisco XDR & Splunk SIEM - stronger together (DATAGROUP Cyber Security)
PDF
Security - Mit Sicherheit zum Erfolg (Telekom)
PDF
One Cisco - Splunk Public Sector Summit Germany April 2025
PDF
.conf Go 2023 - Data analysis as a routine
PDF
.conf Go 2023 - How KPN drives Customer Satisfaction on IPTV
PDF
.conf Go 2023 - Navegando la normativa SOX (Telefónica)
PDF
.conf Go 2023 - Raiffeisen Bank International
PDF
.conf Go 2023 - På liv og død Om sikkerhetsarbeid i Norsk helsenett
PDF
.conf Go 2023 - Many roads lead to Rome - this was our journey (Julius Bär)
PDF
.conf Go 2023 - Das passende Rezept für die digitale (Security) Revolution zu...
PDF
.conf go 2023 - Cyber Resilienz – Herausforderungen und Ansatz für Energiever...
PDF
.conf go 2023 - De NOC a CSIRT (Cellnex)
PDF
conf go 2023 - El camino hacia la ciberseguridad (ABANCA)
Splunk Leadership Forum Wien - 20.05.2025
Splunk Security Update | Public Sector Summit Germany 2025
Building Resilience with Energy Management for the Public Sector
IT-Lagebild: Observability for Resilience (SVA)
Nach dem SOC-Aufbau ist vor der Automatisierung (OFD Baden-Württemberg)
Monitoring einer Sicheren Inter-Netzwerk Architektur (SINA)
Praktische Erfahrungen mit dem Attack Analyser (gematik)
Cisco XDR & Splunk SIEM - stronger together (DATAGROUP Cyber Security)
Security - Mit Sicherheit zum Erfolg (Telekom)
One Cisco - Splunk Public Sector Summit Germany April 2025
.conf Go 2023 - Data analysis as a routine
.conf Go 2023 - How KPN drives Customer Satisfaction on IPTV
.conf Go 2023 - Navegando la normativa SOX (Telefónica)
.conf Go 2023 - Raiffeisen Bank International
.conf Go 2023 - På liv og død Om sikkerhetsarbeid i Norsk helsenett
.conf Go 2023 - Many roads lead to Rome - this was our journey (Julius Bär)
.conf Go 2023 - Das passende Rezept für die digitale (Security) Revolution zu...
.conf go 2023 - Cyber Resilienz – Herausforderungen und Ansatz für Energiever...
.conf go 2023 - De NOC a CSIRT (Cellnex)
conf go 2023 - El camino hacia la ciberseguridad (ABANCA)

Recently uploaded (20)

PPTX
MYSQL Presentation for SQL database connectivity
PDF
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
PDF
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
PDF
Advanced methodologies resolving dimensionality complications for autism neur...
PDF
Electronic commerce courselecture one. Pdf
PPTX
Digital-Transformation-Roadmap-for-Companies.pptx
PPT
“AI and Expert System Decision Support & Business Intelligence Systems”
PDF
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
PDF
Architecting across the Boundaries of two Complex Domains - Healthcare & Tech...
PDF
Optimiser vos workloads AI/ML sur Amazon EC2 et AWS Graviton
PDF
MIND Revenue Release Quarter 2 2025 Press Release
PDF
Network Security Unit 5.pdf for BCA BBA.
PDF
Encapsulation theory and applications.pdf
PDF
Review of recent advances in non-invasive hemoglobin estimation
PDF
Machine learning based COVID-19 study performance prediction
PPTX
ACSFv1EN-58255 AWS Academy Cloud Security Foundations.pptx
PDF
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
PPTX
Detection-First SIEM: Rule Types, Dashboards, and Threat-Informed Strategy
PDF
Unlocking AI with Model Context Protocol (MCP)
PPTX
sap open course for s4hana steps from ECC to s4
MYSQL Presentation for SQL database connectivity
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
Advanced methodologies resolving dimensionality complications for autism neur...
Electronic commerce courselecture one. Pdf
Digital-Transformation-Roadmap-for-Companies.pptx
“AI and Expert System Decision Support & Business Intelligence Systems”
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
Architecting across the Boundaries of two Complex Domains - Healthcare & Tech...
Optimiser vos workloads AI/ML sur Amazon EC2 et AWS Graviton
MIND Revenue Release Quarter 2 2025 Press Release
Network Security Unit 5.pdf for BCA BBA.
Encapsulation theory and applications.pdf
Review of recent advances in non-invasive hemoglobin estimation
Machine learning based COVID-19 study performance prediction
ACSFv1EN-58255 AWS Academy Cloud Security Foundations.pptx
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
Detection-First SIEM: Rule Types, Dashboards, and Threat-Informed Strategy
Unlocking AI with Model Context Protocol (MCP)
sap open course for s4hana steps from ECC to s4

SplunkLive! Analytics with Splunk Enterprise - Part 1

  • 1. Copyright © 2013 Splunk Inc. Analytics with Splunk Enterprise – Part 1
  • 2. Legal Notices During the course of this presentation, we may make forward-looking statements regarding future events or the expected performance of the company. We caution you that such statements reflect our current expectations and estimates based on factors currently known to us and that actual events or results could differ materially. For important factors that may cause actual results to differ from those contained in our forward-looking statements, please review our filings with the SEC. The forward-looking statements made in this presentation are being made as of the time and date of its live presentation. If reviewed after its live presentation, this presentation may not contain current or accurate information. We do not assume any obligation to update any forward-looking statements we may make. In addition, any information about our roadmap outlines our general product direction and is subject to change at any time without notice. It is for informational purposes only and shall not, be incorporated into any contract or other commitment. Splunk undertakes no obligation either to develop the features or functionality described or to include any such feature or functionality in a future release. Splunk, Splunk>, Splunk Storm, Listen to Your Data, SPL and The Engine for Machine Data are trademarks and registered trademarks of Splunk Inc. in the United States and other countries. All other brand names, product names, or trademarks belong to their respective owners. ©2013 Splunk Inc. All rights reserved.
  • 8. Analytics Big Picture Pivot Build complex reports without the search language Data Model Provides more meaningful representation of underlying raw machine data Analytics Store Acceleration technology delivers up to 1000x faster analytics over Splunk 5 8
  • 9. Operational Intelligence Across the Enterprise [10/11/12 18:57:04 000000b0 UTC] Raw Data IT professional Create and share data models Accelerate data models and custom searches with the analytics store Create reports with pivot Analytics Store Developer Leverage data models to abstract data Leverage pivot in custom apps Data Model Pivot Analyst Create reports using pivot based on data models created by IT
  • 10. Pivot is a query builder.
  • 12. What is a Data Model? A data model is a search-time mapping of data onto a hierarchical structure • Encapsulate the knowledge needed to build a search • Pivot reports are build on top of data models • Data-independent Screenshot here
  • 13. search and filter | munge | report | clean-up sourcetype=access_combined source = "/home/ssorkin/banner_access.log.2013.6.gz" | eval unique=(uid + useragent) | stats dc(unique) by os_name | rename dc(unique) as "Unique Visitors" os_name as "Operating System"
  • 14. A Data Model Is a Collection of Objects Screenshot here
  • 15. Objects Have Constraints and Attributes Screenshot here
  • 16. Child Objects Inherit Constraints and Attributes Screenshot here
  • 17. Child Objects Inherit Constraints and Attributes

Editor's Notes

  • #4: What is Data Model, and why do I care?Building a Data ModelManagement, Acceleration, and BeyondThe Future!Q&A
  • #9: Splunk 6 takes large-scalemachine data analytics to the next level by introducing three breakthrough innovations:Pivot – opens up the power of Splunk search to non-technical users with an easy-to-use drag and drop interface to explore, manipulate and visualize data Data Model – defines meaningful relationships in underlying machine data and making the data more useful to broader base of non-technical usersAnalytics Store – patent pending technology that accelerates data models by delivering extremely high performance data retrieval for analytical operations, up to 1000x faster than Splunk 5Let’s dig into each of these new features in more detail.
  • #10: How does theAnalytics Store, Data Model and Pivot benefit users across the enterprise?Lets start with the IT Professional – this includes the Splunk Administrator or an advanced Splunk user that is familiar with SPL.Using Splunk 6 they can:Create data modelsShare data models with other users – delivering a consistent view of the dataAccelerate data models using the Analytics StoreCreate reports using Pivot (although being power users, they may prefer using SPL directly!)Next we have the enterprise developer.Using Splunk 6 they can:Leverage data models built by IT, making searches more portable (using common Data Models ensures predictability of results)Leverage the Pivot interface in custom enterprise appsFinally, there are additional users that can now benefit – for example, the business or data analyst. Using Splunk 6 they can:Create reports, dashboards, charts and other visualizations using the Pivot interface and based on data models that provide an abstracted view of the raw data. Splunk 6 is not meant to replace existing BI and Business Analytics tools, but it does provide new visibility, insights and intelligence from operational data that can be used by business analysts to augment these tools. Data from Splunk software can also be leveraged directly using the Splunk API and SDKs and integrated into existing business analytics tools. For example, the recently announced Pentaho Business Analytics for Splunk® Enterprise (http://apps.splunk.com/app/1554), enables business users to utilize Pentaho to rapidly visualize and gain additional insights from Splunk’s machine data platform using existing in-house skills.
  • #15: What are the important “things” in your data?E.g. WebIntelligence might haveHTTPAccessHTTPSuccessUser SessionHow are they related?There’s more than one “right” way to define your objects
  • #16: Constraints filter down to a set of a dataAttributes are the fields and knowledge associated with the objectBoth are inherited!
  • #17: A child object is a type of its parent object: e.g. An HTTP_Success object is a type of HTTP_AccessAdding a child object is essentially a way of adding a filter on the parentsA parent-child relationship makes it easy to do queries like “What percentage of my HTTP_Access events are HTTP_Success events?”