Session Tracks
View Breakout Sessions by Date and Time
Deploying Splunk
Targeted primarily at Splunk admins, this track covers everything you need to know about architecting and deploying Splunk and driving adoption within your organization.
Architecting and Sizing Your Splunk Deployments
Simeon Yep, Customer Success Manager, SplunkTrack: Deploying Splunk
Skill Level: Beginner/ Intermediate
Breakout Session: 1: Tues, Aug 16, 11:30 AM - 12:30 PM
Sure Splunk is a flexible product that can be deployed to meet almost any scale and redundancy requirement. But like any other high-performance application you need to define your goals and requirements then plan your architecture carefully. Number of users? Daily index? Hot, warm, cold storage? High availability? This session will walk through a checklist of items to consider before choosing hardware and deploying Splunk in a manner that best meets your goals.
Best Practices for Deploying Splunk--Physical, Virtual or Cloud
Simeon Yep, Customer Success Manager, SplunkTrack: Deploying Splunk
Skill Level: Beginner/ Intermediate
Breakout Session: 2: Tues, Aug 16, 1:45 PM - 2:45 PM
Assess your IT search requirements, design a Splunk topology, perform capacity planning and decide on indexing, security, and data management strategies that best fit your environment and deployment goals. Splunk's professional services team has seen it all in the field and they're bringing that knowledge to the conference to help make your Splunk deployment be all that it can be.
Enterprise Deployments: Architecting and Managing Scalable Solutions with Splunk
Mackenzie Kosutt, Senior Systems Engineer, ViacomMatthew Settipane, Solutions Architect, Splunk
Track: Deploying Splunk
Skill Level: Beginner/ Intermediate
Breakout Session: 3: Tues, Aug 16, 3:00 PM - 4:00 PM
Viacom recently rolled out 4,500 forwarders indexing to 12 R510s with mounted bundles, using search head pooling (built on VMs ready to scale by adding more at any time), deployment servers, and a farm of syslog servers for handling numerous networking and infosec devices. We'll re-cap the best practices we uncovered along the way, including:
- Deployment server, Puppet, and SCCM working together in harmony
- Scaling your search farm
- Search head pooling and mounted bundles
- Props.conf
- Naming conventions
- Examples of how quickly Splunk solved issues from asset tracking to cyber security
With Splunk one size does not fit all, so the goal of this session is to share best practices and seed ideas for tackling your own implementation.
Using Puppet To Manage Splunk
Carl Schwenk, Citrix OnlineTrack: Deploying Splunk
Solution Area: Operations
Skill Level: Intermediate
Breakout Session: 4: Tues, Aug 16, 4:15 PM - 5:30 PM
Between indexers, search heads, and forwarders there's a lot of configuration to manage in an Enterprise Splunk installation. In this session we'll cover how to leverage Puppet to manage these configurations easily and efficiently. We'll also touch on using Foreman to gain greater visibility into your deployment.
Indexing Everything: Adding New Data Sources
Brian Wooden, Client Architect, SplunkTrack: Deploying Splunk
Skill Level: Beginner/ Intermediate
Breakout Session: 5: Weds, Aug 17, 9:00 AM - 10:00 AM
In this session, we'll review best practices for organizing data as it comes into Splunk: ensuring host, timestamps, timezone offsets, sourcetypes, event breaking, etc. are correct. We'll help you understand how investing a bit of time on the front end, and testing in the sandbox environment, can prevent the need for cleaning event data or clearing forwarder fishbuckets later. We'll also review apps available on Splunkbase which help with field extraction in a way that supports extensibility, reporting, and security.
Supporting Enterprise System Rollouts with Splunk
Clint Sharp, Cricket CommunicationsTrack: Deploying Splunk
Solution Area: Security + OI
Breakout Session: 6: Weds, Aug 17, 11:00 AM - 12:00 PM
At Cricket Communications, Splunk started as a way to correlate all of our data into one view to help our operations team keep processes humming. Then we gave secured access to our developers--and they're addicted. In fact, Splunk is critical in helping us to speed deployment of new systems (like our recent multi-million dollar billing system implementation). Learn how we use Splunk to displaying key metrics for the business, track overall system health, track transactions, optimize license usage and support capacity planning.
Authentication and Authorization
David Marquardt, Software Engineer, SplunkTrack: Deploying Splunk
Solution Area: Security
Skill Level: Beginner/ Intermediate
Breakout Session: 7: Weds, Aug 17, 11:40 AM - 12:40 PM
Learn how to integrate Splunk into Active Directory and LDAP for SSO and role-based access leveraging your existing infrastructure. Then we'll walk through configuring Splunk to use trusted certificates issued by your internal CA. Sure, Splunk can use its own self-signed certificate for https, but by using trusted certs issued by your company's certificate authority, you get a better degree of trust, and none of those pesky certificate warnings. Finally, we'll configure some Active Directory based reporting, like changes to AD groups or Group Policy.
How to Boost Splunk's Cred in Your Organization
John Folkers, UGI UtilitiesPete Ehlke, Client Architect, Splunk
Track: Deploying Splunk
Breakout Session: 8: Weds, Aug 17, 1:45 PM - 2:45 PM
How do you promote Splunk internally to expand usage? Who is your audience? What do they need to know? Which messages work for them? What hasn't worked? We'll walk through different approaches one can take to tackle the, "How do I get approval to buy/expand Splunk?" question. This is a brainstorming session and open discussion, and Splunk will provide materials geared to help you drive Splunk usage across your organization.
High Availability and Disaster Recovery
Rithy Sim ieng, Senior Consultant, SplunkTrack: Deploying Splunk
Skill Level: Beginner/ Intermediate
Breakout Session: 9: Weds, Aug 17, 3:00 PM - 4:00 PM
As Splunk becomes more critical to people and to business functions, it becomes more important to maximize the uptime of the service. We'll talk about general principles of HA and DR with Splunk, about the various mechanisms for providing them, and the levels of availability, relative advantages, and costs of each of them.
SplunkIt--The Splunk Performance Test Kit
Peter Zadrozny, SplunkTrack: Deploying Splunk
Skill Level: Beginner/ Intermediate
Breakout Session: 9: Weds, Aug 17, 3:00 PM - 4:00 PM
Introducing SplunkIt the new Splunk Performance Test Kit--available for download for all users after the conference. The presentation describes the performance kit, how it works and how to use it. The kit allows for users to run with a standardized set of data and provide performance numbers from the end user perspective. The kit will produce a set of uniform results that can easily be shared so that all Splunkers can anticipate performance results moving forward.
Forwarding and Receiving
Jeff Blake, Senior Solutions Architect, SplunkTrack: Deploying Splunk
Skill Level: Beginner/ Intermediate
Breakout Session: 10: Weds, Aug 17, 4:15 PM - 5:15 PM
Splunk's forwarding and receiving capability makes possible all sorts of interesting Splunk topologies to handle functions like data consolidation, load balancing, and data routing. We'll detail how using Splunk forwarders versus other methods can help with tagging of metadata, compression and SSL security. We'll review how to configure forwarding, create deployment topologies, and deploying universal, heavy and light forwarders and search across indexers.
Using Splunk
Deep dive into searching, alerting, reporting, conducting statistical analysis and building dashboards with Splunk. This track appeals to all types of Splunk users.
FISMA and the Path to Continuous Monitoring
Monzy Merza, Solutions Architect, SplunkTrack: Using Splunk
Solution Area: Security, Compliance
Breakout Session: 1: Tues, Aug 16, 11:30 AM - 12:30 PM
Join us in a discussion around the challenges Federal agencies are facing on the path to continuous monitoring, situational awareness and FISMA compliance. We'll look to address the ways Federal Agencies can: Enable continuous Monitoring and drive operational efficiency; Address the machine data challenge and provide continuous monitoring; Provide dynamic situational awareness with real-time visibility; Scale "on the fly" and securely share relevant data across organizations; Bridge the gap between Operations and Security.
Search Language-Beginner
Dan Plaza, Senior Instructor, SplunkTrack: Using Splunk
Skill Level: Beginner/ Intermediate
Breakout Session: 1: Tues, Aug 16, 11:30 AM - 12:30 PM
Did you know you can do crazy useful things with Splunk's search language? Sort, use fields, apply wildcards - but even better, it allows you to drill-down into the results using Splunk's Search interface timeline. This session will show some concrete examples of how to use Splunk with web access and other types of commonly used data so you can craft simple but powerful searches based on what's interesting in your data. Learn the basics of the Splunk search language in this beginner class, then move on to the Intermediate and Advanced classes to become a real pro.
Reporting Across Large Datasets with Summary Indexing
Gerald Kanapathy, Manager, Professional Services, SplunkTrack: Using Splunk
Skill Level: Beginner/ Intermediate
Breakout Session: 1: Tues, Aug 16, 11:30 AM - 12:30 PM
Summary indexing in Splunk is the best way to report efficiently on large volumes of data. Rather than searching across your entire dataset, you can create a summary index related only to your most critical data or reports. Join us for this session to define the types of data you'll want to include on your summary index and how to craft the searches that derive the insight most interesting and critical to your business.
New Splunk Product Offering--Unleashed!
Ledio Ago, Engineering Manager, Cloud, SplunkDeclan Shanaghy, Sr. Software Engineer, Cloud, Splunk
Greg Albrecht, Software Engineer, Cloud, Splunk
Track: Using Splunk
Skill Level: Intermediate
Breakout Session: 2: Tues, Aug 16, 1:45 PM - 2:45 PM
If you're a developer or have used any cloud services like Amazon Web Services, Rackspace, Heroku, EngineYard, Azure; this session will be of interest to you. Join this session to learn about a new product beta from Splunk.
Search Language-Intermediate
Karen Hodges, SplunkTrack: Using Splunk
Skill Level: Intermediate
Breakout Session: 2: Tues, Aug 16, 1:45 PM - 2:45 PM
Breakout Session: 10: Weds, Aug 17, 4:15 PM - 5:15 PM
Finding that needle in the haystack has never been easier. You ratcheted up your search language knowledge in the beginner session, now join us for the intermediate session to learn more about reporting commands, transactions, and adding knowledge to your events.
Splunking for Forensic Analysis in the Cloud
Vincent Uria, Sandia National LabsTrack: Using Splunk
Solution Area: Security
Breakout Session: 3: Tues, Aug 16, 3:00 PM - 4:00 PM
As we split our IT environments across public and private cloud, hosted and physical facilities, forensic analysis becomes more and more challenging. The ephemeral nature of the cloud can leave an incomplete view of our data, making it difficult to paint an accurate picture of a given point in time. This session will show how Splunk has become our platform for Situational Awareness, providing visibility across our infrastructure to assist with forensic investigations for operations, security and forensics, and application teams.
Web Analytics Throwdown: with NPR and Intuit
Sondra Russell, NPRTim Suh, Intuit
Track: Using Splunk
Solution Area: Web Intelligence
Skill Level: Intermediate
Breakout Session: 3: Tues, Aug 16, 3:00 PM - 4:00 PM
Splunk for Web Intelligence? Why not! This session is a plain-english tour of how NPR is using Splunk to track audio and video traffic across our web sites and digital apps (Android, iPhone, etc.). Intuit will share how they capture greater insight into visitor sessions and answer questions traditional web analytics tools can't provide. We'll cover a variety of use cases, taking each from the raw data through the Splunk under-the-hood to the strategic questions and answers.
Using Splunk to Provide Business Value Outside of IT
James Wilson Realestate.com.auSplunk
Track: Using Splunk
Breakout Session: 3: Tues, Aug 16, 3:00 PM - 4:00 PM
We know Splunk helps us solve problems at the IT operations level. But more and more Splunk helps us to make IT data relevant for non-technical business users. With Splunk you can ask any question at any time, without planning questions or structures in advance. And once you've built initial dashboards, you can empower business users to access them so they can get instant, accurate data on their own. Join us for this session where we'll review how to build custom dashboards that provide both up-to-the-minute and long-term trending analysis that business users need to make the decisions that impact revenue.
Enabling DevOps at LinkedIn with Splunk
Stephan Apitz, Sr. Director Operations, LinkedInTrack: Using Splunk
Solution Area: App Management / Ops
Breakout Session: 4: Tues, Aug 16, 4:15 PM - 5:15 PM
Bridging the gap between Dev and Ops is crucial to deliver software faster and better. The world¹s largest and most reliable professional networking site, LinkedIn, shares its journey to building a successful DevOps culture. Building cooperation between developer and operations teams at LinkedIn required tools that would provide end-to-end operational visibility to help DevOps teams closely monitor KPIs for the services they manage. This session covers the enabling technologies used by LinkedIn to assemble a thriving DevOps team, helping it secure top ranking among PCMagazine¹s best performing social networking sites.
Splunk for Fraud and Forensics at Intuit
Jaime Rodriguez, Senior Fraud Analyst, IntuitMark Seward, Director, Product Marketing, Security, Splunk
Track: Using Splunk
Solution Area: Security
Skill Level: Intermediate
Breakout Session: 4: Tues, Aug 16, 4:15 PM - 5:30 PM
This session will examine how Intuit is using Splunk to prevent fraud and conduct forensic analysis. Splunk helps Intuit monitor for known fraudsters and fraudulent patterns and then speeds forensic investigations to understand which systems may have been compromised.
Supporting the Salesforce.com Cloud
Denise Glaser, Salesforce.comTrack: Using Splunk
Solution Area: App Management / Ops
Breakout Session: 4: Tues, Aug 16, 4:15 PM - 5:30 PM
To keep our edge as the leading Software as a Service (SaaS) provider, we need real-time intelligence across our business. Splunk delivers the insight we need to more than 400 users enterprise-wide. Splunk helps us to stay on top of our systems, not only to ensure uptime, but for capacity planning and understanding user trends to develop and deliver new features and services. We'll walk through our implementation and share some of the successes we've seen using Splunk to improve our business operations.
Search Language-Advanced aka: Optimizing Search
Steve Zhang, SplunkTrack: Using Splunk
Skill Level: Advanced
Breakout Session: 5: Weds, Aug 17, 9:00 AM - 10:00 AM
We'll take a walk through common "approaches" our customers take to boost search performance, which can actually slow the presentation of your results. Join this session to learn 5 ways to really power up search performance--then how you can save these searches to build alerts and dashboards to truly boost the performance of your organization.
How to do Event Correlation and Normalization with Splunk
Jack Coates, SplunkTrack: Using Splunk
Skill Level: Beginner/ Intermediate
Breakout Session: 5: Weds, Aug 17, 9:00 AM - 10:00 AM
While traditionally used in a security context, event correlation can help to speed MTTR across your operations--fraud detection, user behaviors, root cause analysis and more. Universal indexing and search time extraction position Splunk as a natural for event correlation. We'll review several techniques for correlating events in Splunk and offer a number of examples to help you determine what method makes the most sense for your particular needs.
Using Splunk's Pattern-based Capabilities to Reduce MTTR
Mika Borner, SwisscomTrack: Using Splunk
Solution Area: Security/ Ops
Skill Level: Beginner
Breakout Session: 6: Weds, Aug 17, 10:30 AM - 11:30 AM
Splunk has empowered Tier 1 support to to significantly reduce MTTR, and provide the reports, dashboards, statistics and trending we need to address service crashes and capacity planning at Swisscom, the leading telco/ISP in Switzerland. A substantial part of running an ISP mail platform, handling more than 40 million emails a day, is fighting abuse and a substantial portion of abuse cases are caused by spammers. This session will investigate how we currently use Splunk's pattern-based capabilities to detect abuse on our platform, and what we do to fight it.
Best Practices for Application Management and Troubleshooting at Tesco.com
Graham Smith, TescoTrack: Using Splunk
Solution Area: App Management / Ops
Breakout Session: 6: Weds, Aug 17, 10:30 AM - 11:30 AM
Tesco.com, a major UK-based online retailer, uses Splunk to provide dev teams with real-time, secure access to its large Java-based application clusters for monitoring and troubleshooting. In this session you will learn how Tesco are using Splunk to monitor its ecommerce platform, Tibco, and other critical applications; Tesco's setup and approach to log monitoring; Alert integration with SCOM; Splunk's use within engineering and non-production environments; and goals for future use of Splunk.
Dashboard Drilldowns and Workflow Actions from Splunk Alerts
Christoph Wiederkehr, PostFinanceTrack: Using Splunk
Skill Level: Beginner/ Intermediate
Breakout Session: 6: Weds, Aug 17, 10:30 AM - 11:30 AM
Long time Splunk user Christoph Wiederkehr and the PostFinance team rely on Splunk's drill down reports to turn "analytical" views into troubleshooting tools. The dashboards and views we've built for our teams to keep tabs on general security and operational health are also critical aids in troubleshooting. Spikes and anomalies are easy to drill into to pinpoint and resolve issues quickly, then create alerts for future occurrences or trigger specific actions to really boost productivity. Sean will walk you challenges and successes they've seen in the PostFinance environment and walk you through specific steps to help you reduce your MTTR and become more proactive too!
Transaction Tracing and Troubleshooting at Staples
Kathy Kysar, StaplesTrack: Using Splunk
Skill Level: Beginner
Breakout Session: 6: Weds, Aug 17, 10:30 AM - 11:30 AM
With Splunk and a userid, transaction code or purchase type, you can securely trace transactions of all varieties (purchases, emails, stock trades) across your network and application stack to ensure completion--or understand where something went off the rails. Once you understand where you may have failures, you can set up conditional alerts so you can avoid failure before it happens. Learn how Staples is tracking transactions across its infrastructure to ensure an optimal customer experience and support revenue generation. We'll review implementation best practices, using Splunk to piece together transactions as they traverse your infrastructure, and dashboards to visualize key metrics for your organization.
Maybe, Maybe Not: Conditional Statements in Splunk
Drew Oetzel, Senior Course Developer, SplunkTrack: Using Splunk
Skill Level: All
Breakout Session: 7: Weds, Aug 17, 11:40 AM - 12:40 PM
Breakout Session: 10: Weds, Aug 17, 4:15 PM - 5:15 PM
Splunk's search language is smart, it can evaluate conditional statements and help you spot patterns across events, across time, and all parts of the space time continuum. Using the eval and where commands you can make your searches and most importantly alerts much smarter. In this session we will dive deep into these powerful commands to help you get the most out of Splunk's powerful search language.
Real-time Alerting and Monitoring
Ledion Bitincka, SplunkTrack: Using Splunk
Skill Level: Beginner/ Intermediate
Breakout Session: 7: Weds, Aug 17, 11:40 AM - 12:40 PM
You know Splunk is great at helping you identify security issues, application errors or network problems. But once you've identified these issues, did you know you could create alerts to proactively address issues before they arise? Join us to learn the basics of saved searches and more complex threshold-based monitoring for predictive alerting.
Using Splunk From Windows PowerShell
Brandon Shell, CTO Shell ConsultingTrack: Using Splunk
Solution Area: App Management
Skill Level: Advanced
Breakout Session: 8: Weds, Aug 17, 1:45 PM - 2:45 PM
We'll begin with a basic introduction into the object oriented nature of PowerShell. Next, we'll showcase our shiny new PowerShell Resource kit. Finally a demo of searching Splunk via PowerShell will demonstrate the power of piping objects from Splunk into the PowerShell ecosystem.
How Splunk Uses Splunk
Doug Harr,CIO, SplunkTrack: Using Splunk
Skill Level: Beginner/ Intermediate
Breakout Session: 9: Weds, Aug 17, 3:00 PM - 4:00 PM
At Splunk, we drink our own champagne. So we'll share how we're implementing Splunk and gathering business insight from across our organization.
Field Extractions in Splunk - Making RegEx Your Buddy
Michael Wilde,Splunk Ninja, SplunkTrack: Using Splunk
Skill Level: Beginner/ Intermediate
Breakout Session: 9: Weds, Aug 17, 3:00 PM - 4:00 PM
In this technical session, the Splunk Ninja will cover a basic overview of regular expression (RegEx) syntax, define how RegEx is used within Splunk for field extractions, filtering, finding and processing events, using the search language, and more. We'll provide an overview of how best to use RegEx to cleverly solve problems in Splunk. Join the Splunk Ninja to learn tips and tricks for "thinking in RegEx", desktop tools to help you, and the best ways and appropriate times to use RegEx in Splunk.
Extending Splunk
Mashups, partner and community developed apps, lookups--there are many ways to get more value from your data both inside and outside of Splunk. This track is primarily geared to those intending to extend Splunk's native functionality or modify Splunk using XML.
Web Intelligence in Splunk
Jake Flomenberg, SplunkArchana Ganapathi, Splunk
Track: Extending Splunk
Solution Area: Web Intelligence
Skill Level: Beginner/ Intermediate
Breakout Session: 1: Tues, Aug 16, 11:30 AM - 12:30 PM
You know Splunk is great at helping you identify security issues, application errors or network problems. But once you've identified these issues, did you know you could create alerts to proactively address issues before they arise? Join us to learn the basics of saved searches and more complex threshold-based monitoring for predictive alerting.
Splunk's Role in the Big Data Ecosystem
Jake Flomenberg, Product Manager, SplunkTrack: Extending Splunk
Solution Area: Big Data
Skill Level: Beginner
Breakout Session: 2: Tues, Aug 16, 1:45 PM - 2:45 PM
Today, open source technologies are increasingly used to harness what is being termed 'big data'. It's data so vast, complex and non-standard that it becomes awkward to work with using traditional tools. As the insight derived from this data becomes increasingly mission-critical, the sheer time, complexity and effort involved in deploying open source-based solutions present real challenges. We'll discuss how Splunk is being used in big data environments and compare and contrast the differences between Splunk and open source big data technologies, and learn more about Splunk apps that interface with some of these technologies.
Increase Your Security Visibility with the Splunk App for Enterprise Security
Jim Hansen, Director, Product Management, Security and Compliance Solutions, SplunkTrack: Extending Splunk
Solution Area: Security
Skill Level: All
Breakout Session: 2: Tues, Aug 16, 1:45 PM - 2:45 PM
Maintaining a secure infrastructure without sacrificing the confidentiality, availability, or integrity of key information systems is an ongoing struggle that every security team faces. Security threats evolve quickly--the right tools to monitor for threats, breach, or inappropriate behavior are essential for mitigation and reducing risk. Many organizations have looked to Security Information Event Management (SIEM) solutions to help, but have found them to be difficult to use, customize, and ineffective. It's time for a new approach. A Splunk approach. Come to this session to see how Splunk can help provide an effective monitoring solution and keep your company name out of the headlines. We will provide a sneak peak at the latest version of the Splunk App for Enterprise Security (formerly "Enterprise Security Suite") and show how this app can help your security team proactively find patterns of activity in your data and increase your overall security posture.
Achieving Enterprise Level Security Visibility Using Splunk
Paul Johnson, General ElectricTrack: Extending Splunk
Solution Area: Security
Breakout Session: 3: Tues, Aug 16, 3:00 PM - 4:00 PM
This session will cover our experience/journey using Splunk as a global SIEM solution, including best practices we have implemented (such as the common information model) and some of our real world use cases.
From Point Solution to Platform
Tim Hartmann, Senior Network Services Engineer, Large Private UniversityJames Donn, Senior Network Management Systems Engineer, Large Private University
Track: Extending Splunk
Solution Area: All
Breakout Session: 4: Tues, Aug 16, 4:15 PM - 5:15 PM
We first brought Splunk in as one tool that could help us on both the network management and security front. But everyone who touched Splunk wanted more. This session will review how we've standardized on "Splunk as our platform" - how that term was born and why it stuck. We'll cover the technical bits of how we are able to provide Splunk as a service for other teams, and ways we help to drive adoption.
Introducing Splunk Apps for Application Management
Dan Goldburt, Product Manager, Application Management SplunkTrack: Extending Splunk
Solution Area: Application Management
Skill Level: All
Breakout Session: 5: Weds, Aug 17, 9:00 AM - 10:00 AM
This session introduces two new apps that accelerate getting end-to-end visibility across all tiers of applications as well as facilitate monitoring of individual components of applications. This session will include an introduction and technical deep dive into the new Splunk App for Transaction Profiling that makes it easier to trace and monitor transactions across distributed application infrastructures. This app can be used across a broad set of industries and a variety of transaction types from mobile phone activations to stock trade executions. This session will also include an overview of the upcoming revisions to the Splunk App for WebSphere Application Server that will make it easier to install and deploy in large scale Websphere environments. Attend this session to learn how these Apps are applicable in your environment.
Presenting your Data Effectively: Building Charts with Splunk
Johnvey Hwang, UI Development Manager, SplunkTrack: Extending Splunk
Skill Level: Beginner/ Intermediate
Breakout Session: 5: Weds, Aug 17, 9:00 AM - 10:00 AM
You can use Splunk to visualize the information you uncover through your searches to create compelling charts and reports. Just a few clicks and Voila, you've got your choice of 7 types of charts based on the best format for showcasing your data. Next we'll learn how to customize your charts based on everything from the axis labels to the chart colors. We'll discuss a few common customizations in both the simplified and advanced XML, and outline the complete list of all chart formatting options. You'll walk away knowing how to create basic charts, save them to dashboards and reports, and examples of interesting charts other customers are using today.
Enhancing Operational Security Processes with the Splunk App for Enterprise Security
Daniel Frye, Cedar CrestoneMarquis Montgomery, Cedar Crestone
Track: Extending Splunk
Solution Area: Security
Breakout Session: 6: Weds, Aug 17, 11:00 AM - 12:00 PM
For 15+ years, SIEM vendors have delivered a single approach. Their method is to collect and normalize data from traditional security sources, provide canned reports then correlate a subset of the "security-relevant" data based on 'rules' that drive dashboards and alerts. This session will cover the challenges and limitations Cedar Crestone has encountered using the traditional SIEM approach and how they have gained new visibility and enhanced their operational security processes using the flexibility of the Splunk App for Enterprise Security.
Visibility Inside Your Virtual Environments
Leena Joshi, Director of Solutions Marketing, SplunkWill Hayes, Director, Solutions Architecture, Splunk
Curt Collins, Director, Product Management Splunk
Track: Extending Splunk
Solution Area: Operations
Breakout Session: 7: Weds, Aug 17, 11:40 AM - 12:40 PM
Virtualized environments are complex, yet becoming increasingly widespread in datacenters. Come to this session to learn: The benefits of using Splunk with virtualization software; How to deploy Splunk in virtualized environments; How to use data in Splunk to troubleshoot common scenarios you may encounter; Proactive use of saved searches/ reports for virtualized environments; Correlation of data across various layers in virtualized environments
Dynamic Lookups
Nimish Doshi, Solutions Architect, SplunkTrack: Extending Splunk
Skill Level: Beginner
Breakout Session: 7: Weds, Aug 17, 11:40 AM - 12:40 PM
Did you know you can augment the data in your Splunk index with external data? This session will first cover the elementary way to use static lookups to enrich your data.. We'll then cover how dynamic lookups can enrich your data at search time with more fields. This session will cover three examples: accessing a relational database, using an in-memory database, and accessing a remote web site to enrich your data via dynamic lookups. All dynamic lookup examples will be made available to attendees for download. The session will also discuss best practices when performing dynamic lookups.
Transitioning from Google App Engine to Amazon Web Services and Splunk
Dan Siroker, CEO, OptimizelyTrack: Extending Splunk
Solution Area: Application Management, Ops, Operational Intelligence
Skill Level: All
Breakout Session: 8: Weds, Aug 17, 1:45 PM - 2:45 PM
This session will review how A/B testing platform Optimizely scaled to processing billions of requests in real-time by using on Amazon Web Services and Splunk. We'll understand why Optimizely chose AWS + Splunk over Google App Engine, and best practices for building a scalable business in the cloud.
Extending Splunk's Query and Analysis Capabilities to Build Cybersecurity Apps
Nate McKervey, Harris CorporationTrack: Extending Splunk
Solution Area: Security
Skill Level: Intermediate
Breakout Session: 8: Weds, Aug 17, 1:45 PM - 2:45 PM
Using Splunk's correlation, query and analysis commands, we have prototyped products that quickly and accurately identify people. For cybersecurity, our prototype matches persons on the no-fly list with passenger manifests (and more). We've applied the same theory to other industries to correlate multiple files on the same person from different organizations into a single searchable data repository. This session will showcase these prototypes and review how Splunk's correlation, querying and analysis commands drove the creation of these prototypes.
Introducing: Splunk App for Microsoft Exchange
Ben Brauer, Director of Product Marketing, SplunkAdrian Hall, Senior Solutions Architect, Splunk
Track: Extending Splunk
Solution Area: Security / Microsoft
Skill Level: Beginner
Breakout Session: 9: Weds, Aug 17, 3:30 PM - 4:30 PM
You want to Splunk Microsoft Exchange? We've got an app for that. We'll demo the freshly-baked app and show how it supports message tracking, client management, general IT operations and capacity planning. This session will give you a detailed preview of the app with a technical explanation of features from the developer himself, Adrian Hall.
Splunking Outside the Box
Nimish Doshi, Principal Systems Engineer, SplunkMaverick Garner, Sales Manager, Splunk
Track: Extending Splunk
Skill Level: Intermediate
Breakout Session: 9: Weds, Aug 17, 3:30 PM - 4:30 PM
From the beginning, Splunk was designed to universally index data from a variety of sources; meaning Splunk can index data that is not necessarily meant for consumption by IT staff and has more of a business focus. Add Splunk's statistical analysis, aggregate reporting, and alerts, and you're adding real business value beyond IT's typical purview. In fact, more and more customers now use Splunk to gain better insight into their customer's web site experience, habits, preferences, or mapping call detail records (CDRs) for telecomms and law enforcement, or getting bad weather alerts in real time, or viewing the latest TV news. You can even use Splunk to pick your lottery numbers. This session will look at different types of data you can feed into Splunk, and how to think about and create more advanced searches to draw out the patterns and trends that can bring new enlightenment and truly add value as well as new opportunity to your business. So join us, expand your mind now, and start Splunking outside the box.
Inside Splunk
Ever wondered how Splunk works? Our dev team walks you through how Splunk processes data so quickly and makes searches fast to get you the data you need. Sessions may include:
How splunkd Works
Amrit Bath, SplunkJagaannath Kerai, Splunk
Track: Inside Splunk
Skill Level: Intermediate/ Advanced
Breakout Session: 5: Weds, Aug 17, 9:00 AM - 10:00 AM
Join this session to learn about the building blocks of splunkd. We'll review how pipeline, processors and queues work to build a scalable system in splunkd, and highlight how Splunk can eat data form variety of input sources. We will detail File, Network, Scripted inputs, and walk through a scenario where data in file is read by splunkd and makes its way through different components of splunkd before getting indexed or forwarded. Finally we'll review how to debug issues based on metrics.log information.
How Splunk Works: Indexing and Search Architecture
Vishal Patel, SplunkSteve Zhang, Splunk
Track: Inside Splunk
Skill Level: Intermediate/ Advanced
Breakout Session: 7: Weds, Aug 17, 11:40 AM - 12:40 PM
Indexing: Buckets, tsidx files, rawdata, metadata
Developing on Splunk
Learn more about leveraging Splunk's existing APIs and SDKs--as well as our API roadmap--to build apps and grow your business on top of Splunk.
Building a Solutions Business on Splunk
Bill Gaylord, Vice President, Business Development, SplunkTrack: Developing on Splunk
Skill Level: All
Breakout Session: 1: Tues, Aug 16, 11:15 AM - 12:15 PM
Splunk's partner ecosystem is already buzzing with apps aimed at extending Splunk's functionality for various use cases, verticals or other IT products. Join this panel of several companies--Aplura, Centrify, SPP, Sideview, M5 and more--all of whom have built a services business by building apps on Splunk. The panel shares challenges and benefits to developing on Splunk, as well as their goals for future platform development.
Best Practices for Building Apps on Splunk
Will Hayes, Director, Solutions Architecture, SplunkDavid Hazekamp, Solutions Architect, Splunk
Track: Developing on Splunk
Skill Level: Intermediate/ Advanced
Breakout Session: 2: Tues, Aug 16, 1:30 PM - 2:30 PM
Ready to try your hand at building an app on Splunk? Join this session where we'll walk through best practices for defining your app, mapping out your UI and supporting roles, incorporating configurations and knowledge objects, and extending Splunk's API to build a stable, useful app to share with your organization or on Splunkbase.
Building Custom REST Endpoints
Amrit Bath, Senior Software Engineer, SplunkEric Woo, Software Engineer, Splunk
Track: Developing on Splunk
Skill Level: Intermediate/ Advanced
Breakout Session: 3: Tues, Aug 16, 2:45 PM - 3:45 PM
Another way to extend Splunk's functionality is via REST endpoints. Splunk ships with over 55, but you can build your own to: build and configure features on top of Splunk; go beyond SplunkWeb Manager's capabilities to create a customized configuration, or augment search results with outside data. Join this session to understand when it makes sense to build a custom REST endpoint and how you, too, can use Splunk's RESTful API to extend Splunk's capabilities.
What's New in Splunk APIs and SDKs
Paul Sanford, Director Product Management - Developer Platform, SplunkTrack: Developing on Splunk
Skill Level: Intermediate/ Advanced
Breakout Session: 4: Tues, Aug 16, 4:15 PM - 5:30 PM
You may have heard about Splunk for application logging and monitoring scenarios, but there is so much more that you can do with Splunk as a developer. We are building out a developer platform with the goal of making it easier for you to harness the power of Splunk. At this session, you will hear about our conceptual approach to the developer platform, see our roadmap and get a first look at the Python SDK and demos.
Developing on Splunk: Unplugged
Brad Lovering, Vice President, Developer Platform SplunkPaul Sanford, Director Product Management - Developer Platform, Splunk
Track: Developing on Splunk
Skill Level: Intermediate/ Advanced
Bonus Session: Tues, Aug 16, 5:30 PM - 6:30 PM
This is an unscripted, no slides format for you to ask questions and provide feedback on roadmap, our approach and anything else.
Delivering Operational Intelligence Across a Telecom Organization
Johnny Lin, SystexTrack: Extending Splunk
Solution Area: All
Skill Level: All
Breakout Session: 6: Weds, Aug 17, 10:30 AM - 11:30 AM
Splunk's ability to ingest and correlate all kinds of data is particularly useful in telecom companies. This session will detail how Splunk is replacing traditional business intelligence tools at this large Asian mobile operator. The telecom is using Splunk to gain new business insight, optimize revenue and improve customer satisfaction. We'll review the dashboards and forms they've built to deliver insight in various departments across the organization.
Web Traffic Visibility End-to-end
Eddie Satterly, ExpediaTrack: Using Splunk / Developing on Splunk
Skill Level: Intermediate
Breakout Session: 8: Weds, Aug 17, 1:45 PM - 2:45 PM
Expedia uses the data from an external CDN and internal application data to produce a view of traffic to our multiple web properties. This data helps us to drive capacity calculations and to avoid risks to the site from certain malicious traffic and sources that are not trusted. Beyond ensuring site uptime, we have visibility into the benefits of third party advertising agreements and top referral sites driving our business.
The Mechanics of Semantic Logging
Rob Das, Co-Founder, Chief Architect, SplunkTrack: Developing on Splunk
Skill Level: Advanced
Breakout Session: 8: Weds, Aug 17, 1:45 PM - 2:45 PM
Most events are written by developers to help them debug server side functionality. Semantic events are written explicitly for building analytics. Splunk allows developers to create sophisticated analytics for their system without resorting to the typical RDBMS and data cube. Chief Architect Rob Das describes what semantic events are and the best practices for creating them, and follows with a demonstration of how Splunk is used on this type of data.