SlideShare a Scribd company logo
.conf  2011 Keynote Outline August 15, 2011 Web Analytics  Throwdown  with NPR and Intuit Sondra Russell and Tim Suh
24/7
Why Splunk? I started using Splunk because I could… I fell in love because I could…. Crunch raw logs Make pretty reports Still go back into the raw data Easily group scattered log lines into single transactions Slice and dice in new ways Actually use data to inform decisions
Audio and Video Tracking: The Basic Setup MP3 Downloads On Demand Flash Live Streams ProgramID (?P<ProgramID>[^\/]*)(?=\/) UserAgent (?P<UserAgent>[^\&quot;]*)(?=\&quot; ) AppVersion “ *(? =\/) ” Ingest  Raw Data Extract Fields Define Transactions >   sourcetype = download  AND status < 300  AND Method=Get | transaction IPAddress UserAgent maxspan=120… Create Summary Indexes 08/08/2011=>31800 08/09/2011=>29655 08/10/2011=>29903 08/11/2011=>53443 08/12/2011=>32593 08/13/2011=>88654 08/14/2011=>11231 1 2 3 4
>   index=“summary” search_name=“ si_download_programID ”   ProgramName= “ All Songs Considered ”   “ How has my podcast been doing?” pulls from the summary index maps ProgramID to lookup table
>  *  | eval Platform = mvfilter(match(eventtype,&quot;plat*&quot;)) | timechart span=1w count by Platform  “ What platforms are people using to access our show?” Filters for eventtypes that include “plat”  plat_iphone_browser UserAgent=&quot;*iPhone*&quot; AND UserAgent!=&quot;*NPRRadio*&quot; AND UserAgent!=&quot;*iPod*“ AND sc!=18
>  *  | rex field=_raw &quot;Darwin\/(?<Version>[0-9\.]*)\&quot;“ | top Version “ What percentage of our users have upgraded?” Uses regex to extract element from raw log &quot;NPRMusic/2.7 CFNetwork/459 Darwin/10.0.0d3&quot;
>   index=“twitter” | stats count by story_url “ Which stories are getting Tweeted the most?” timestamp =&quot;2011-07-18T15:40:34Z&quot;,  author =&quot;drpdtapp (Dr. P. D Tapp)&quot;,  tweet =&quot;Tinnitus: Why Won't My Ears Stop Ringing?”,  story_url =&quot;http://www.npr.org/2011/07/18/138163304/tinnitus-why-wont-my-ears-stop-ringing?sc=tw&quot;, Creates reports from a custom log
.conf  2011 Keynote Outline August 15, 2011 Questions? Sondra Russell and Tim Suh

More Related Content

PPTX
Spark for Recommender Systems
PPTX
Connecting R to the Sensor Web
PPSX
Product and Service Roadmap
PPTX
Splunk Fundamentals: Investigations with Core Splunk - Splunk Tech Day
PDF
Splunk | Reporting Use Cases
PDF
Splunk conf2014 - Detecting Fraud and Suspicious Events Using Risk Scoring
PPT
Splunk .conf2011: Real Time Alerting and Monitoring
PPTX
SplunkLive! Splunk for Insider Threats and Fraud Detection
Spark for Recommender Systems
Connecting R to the Sensor Web
Product and Service Roadmap
Splunk Fundamentals: Investigations with Core Splunk - Splunk Tech Day
Splunk | Reporting Use Cases
Splunk conf2014 - Detecting Fraud and Suspicious Events Using Risk Scoring
Splunk .conf2011: Real Time Alerting and Monitoring
SplunkLive! Splunk for Insider Threats and Fraud Detection

Viewers also liked (8)

PPTX
Visualizing the Insider Threat: Challenges and tools for identifying maliciou...
PDF
Threat Hunting
PDF
Rapidly Improving Security Posture - CanDeal
PPTX
Data Mining with Splunk
PPTX
Insider Threat Kill Chain: Detecting Human Indicators of Compromise
PPTX
Insider threat event presentation
PPTX
Delivering business value from operational insights at ING Bank
PDF
Detecting-Preventing-Insider-Threat
Visualizing the Insider Threat: Challenges and tools for identifying maliciou...
Threat Hunting
Rapidly Improving Security Posture - CanDeal
Data Mining with Splunk
Insider Threat Kill Chain: Detecting Human Indicators of Compromise
Insider threat event presentation
Delivering business value from operational insights at ING Bank
Detecting-Preventing-Insider-Threat
Ad

Similar to .conf2011: Web Analytics Throwdown: with NPR and Intuit (20)

PPTX
Splunk at opa
PDF
VMworld 2013: Deep Dive into vSphere Log Management with vCenter Log Insight
PPTX
Getting Started Getting Started With Splunk Enterprise
PPTX
Getting Started with Splunk Enterprise
PPTX
SplunkLive! London 2016 Getting started with Splunk
PPTX
Getting Started with Splunk Enterprise Hands-On
PPTX
Getting Started with Splunk Enterprise Hands-On
PPTX
Splunk Ninjas Breakout Session
PPTX
dlux - Splunk Technical Overview
PPTX
PPTX
dlux splunk>live! 2012 Beginners Session
PPTX
SplunkLive! Dallas Nov 2012 - Metro PCS
PPTX
Splunk Ninjas: New Features and Search Dojo
PPTX
SplunkLive! London: Splunk ninjas- new features and search dojo
PPTX
SplunkLive 2011 Beginners Session
PDF
Caso de Sucesso Vodafone e Splunk
PPTX
Integrerad verksamhetsstyrning på Saint Gobain Ecophon - IBM Smarter Business...
PDF
Xldb2011 tue 1055_tom_fastner
KEY
Datacamp @ Transparency Camp 2010
PPTX
Splunk Dynamic lookup
Splunk at opa
VMworld 2013: Deep Dive into vSphere Log Management with vCenter Log Insight
Getting Started Getting Started With Splunk Enterprise
Getting Started with Splunk Enterprise
SplunkLive! London 2016 Getting started with Splunk
Getting Started with Splunk Enterprise Hands-On
Getting Started with Splunk Enterprise Hands-On
Splunk Ninjas Breakout Session
dlux - Splunk Technical Overview
dlux splunk>live! 2012 Beginners Session
SplunkLive! Dallas Nov 2012 - Metro PCS
Splunk Ninjas: New Features and Search Dojo
SplunkLive! London: Splunk ninjas- new features and search dojo
SplunkLive 2011 Beginners Session
Caso de Sucesso Vodafone e Splunk
Integrerad verksamhetsstyrning på Saint Gobain Ecophon - IBM Smarter Business...
Xldb2011 tue 1055_tom_fastner
Datacamp @ Transparency Camp 2010
Splunk Dynamic lookup
Ad

Recently uploaded (20)

PDF
Reach Out and Touch Someone: Haptics and Empathic Computing
PDF
Mobile App Security Testing_ A Comprehensive Guide.pdf
PDF
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
PDF
Spectral efficient network and resource selection model in 5G networks
PPTX
MYSQL Presentation for SQL database connectivity
PPTX
Effective Security Operations Center (SOC) A Modern, Strategic, and Threat-In...
PPTX
Cloud computing and distributed systems.
PDF
MIND Revenue Release Quarter 2 2025 Press Release
PPTX
Digital-Transformation-Roadmap-for-Companies.pptx
PDF
Machine learning based COVID-19 study performance prediction
PPTX
20250228 LYD VKU AI Blended-Learning.pptx
PPTX
sap open course for s4hana steps from ECC to s4
PDF
Electronic commerce courselecture one. Pdf
PDF
Encapsulation_ Review paper, used for researhc scholars
PDF
Chapter 3 Spatial Domain Image Processing.pdf
PDF
cuic standard and advanced reporting.pdf
PDF
Diabetes mellitus diagnosis method based random forest with bat algorithm
PPTX
Understanding_Digital_Forensics_Presentation.pptx
PDF
Dropbox Q2 2025 Financial Results & Investor Presentation
PDF
Network Security Unit 5.pdf for BCA BBA.
Reach Out and Touch Someone: Haptics and Empathic Computing
Mobile App Security Testing_ A Comprehensive Guide.pdf
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
Spectral efficient network and resource selection model in 5G networks
MYSQL Presentation for SQL database connectivity
Effective Security Operations Center (SOC) A Modern, Strategic, and Threat-In...
Cloud computing and distributed systems.
MIND Revenue Release Quarter 2 2025 Press Release
Digital-Transformation-Roadmap-for-Companies.pptx
Machine learning based COVID-19 study performance prediction
20250228 LYD VKU AI Blended-Learning.pptx
sap open course for s4hana steps from ECC to s4
Electronic commerce courselecture one. Pdf
Encapsulation_ Review paper, used for researhc scholars
Chapter 3 Spatial Domain Image Processing.pdf
cuic standard and advanced reporting.pdf
Diabetes mellitus diagnosis method based random forest with bat algorithm
Understanding_Digital_Forensics_Presentation.pptx
Dropbox Q2 2025 Financial Results & Investor Presentation
Network Security Unit 5.pdf for BCA BBA.

.conf2011: Web Analytics Throwdown: with NPR and Intuit

  • 1. .conf 2011 Keynote Outline August 15, 2011 Web Analytics Throwdown with NPR and Intuit Sondra Russell and Tim Suh
  • 3. Why Splunk? I started using Splunk because I could… I fell in love because I could…. Crunch raw logs Make pretty reports Still go back into the raw data Easily group scattered log lines into single transactions Slice and dice in new ways Actually use data to inform decisions
  • 4. Audio and Video Tracking: The Basic Setup MP3 Downloads On Demand Flash Live Streams ProgramID (?P<ProgramID>[^\/]*)(?=\/) UserAgent (?P<UserAgent>[^\&quot;]*)(?=\&quot; ) AppVersion “ *(? =\/) ” Ingest Raw Data Extract Fields Define Transactions > sourcetype = download AND status < 300 AND Method=Get | transaction IPAddress UserAgent maxspan=120… Create Summary Indexes 08/08/2011=>31800 08/09/2011=>29655 08/10/2011=>29903 08/11/2011=>53443 08/12/2011=>32593 08/13/2011=>88654 08/14/2011=>11231 1 2 3 4
  • 5. > index=“summary” search_name=“ si_download_programID ” ProgramName= “ All Songs Considered ” “ How has my podcast been doing?” pulls from the summary index maps ProgramID to lookup table
  • 6. > * | eval Platform = mvfilter(match(eventtype,&quot;plat*&quot;)) | timechart span=1w count by Platform “ What platforms are people using to access our show?” Filters for eventtypes that include “plat” plat_iphone_browser UserAgent=&quot;*iPhone*&quot; AND UserAgent!=&quot;*NPRRadio*&quot; AND UserAgent!=&quot;*iPod*“ AND sc!=18
  • 7. > * | rex field=_raw &quot;Darwin\/(?<Version>[0-9\.]*)\&quot;“ | top Version “ What percentage of our users have upgraded?” Uses regex to extract element from raw log &quot;NPRMusic/2.7 CFNetwork/459 Darwin/10.0.0d3&quot;
  • 8. > index=“twitter” | stats count by story_url “ Which stories are getting Tweeted the most?” timestamp =&quot;2011-07-18T15:40:34Z&quot;, author =&quot;drpdtapp (Dr. P. D Tapp)&quot;, tweet =&quot;Tinnitus: Why Won't My Ears Stop Ringing?”, story_url =&quot;http://www.npr.org/2011/07/18/138163304/tinnitus-why-wont-my-ears-stop-ringing?sc=tw&quot;, Creates reports from a custom log
  • 9. .conf 2011 Keynote Outline August 15, 2011 Questions? Sondra Russell and Tim Suh