Splunking F1: Part Two

Do you remember when your maths teacher told you it’s not the final answer that’s important, it’s your working out that really counts? Well, during this year’s SplunkLive! London event, we had a tie for first place on our F1 racing simulator; two identical lap times to within one thousandth of a second - amazing! Both James and Joe wanted to win the first prize – tickets to the British Grand Prix, so we decided to investigate their driving styles by examining the car telemetry data streamed to Splunk during their respective sessions. Much like an outage or security investigation, with the data in Splunk, we were able to unwind the events to find out how we arrived at the end result. In this case, the result was the fastest lap time. In other scenarios, it could be how security defences were breached, or why a server went down, the process is the same.

One element missing from the F1 data listed in part one of this post, was information concerning the actual driver. To supplement this, we built a simple form in Splunk to capture driver name and demographic data, storing the information in the Splunk KV Store. The final piece; the leaderboard dashboard, correlates the driver information with the telemetry data collected during the race to determine fastest completed lap, of the first 3 laps per contestant.

The table below shows the average throttle, brake and steering application from the driver, ranging from 0 (no application) to 1 (full application).

Session Summary Stats From the above summary table, we can see that James was on the throttle longer and on the brakes less of the time, indicating that he accelerated and braked harder than Joe – key for a fast lap time. James also used less steering angle, indicating a smoother driver, again key for being fast. So how was Joe able to match James’s lap time?

Throttle Application

Brake Application The answer isn’t obvious when looking at the driver inputs alone. However, the speed of the car does give a clear indication. The speed chart from the two drivers reveals that James had a terrible last corner as the pressure of the big prize got to him! Joe kept a clear head and applied the power beautifully through ‘Club Corner’, a very fast right hander which requires the driver to balance the car on the edge of adhesion. This allows him to recover the time that he had lost to James in the earlier part of the lap.

Speed (mph)

For those who missed out on the excitement, the competition is sure to make another appearance at a Splunk event near you! We are also exploring additional features to add to the app, such as the use of the Machine Learning Toolkit to predict behaviours based on player demographic, driving style, and to correlate the data with real-world IOT data sources.

Not and F1 fan? Let us know what other sports you think we could Splunk. Who knows, it could be our next event competition!

SplunkLive London F1 simulator

----------------------------------------------------
Thanks!
Haider Al-Seaidy

Related Articles

Introducing Splunk Operator for Kubernetes 2.0
Platform
2 Minute Read

Introducing Splunk Operator for Kubernetes 2.0

Learn about the newest features in the evolution of our Splunk Operator App Framework.
The Convergence of Security and Observability: Top 5 Platform Principles
Platform
3 Minute Read

The Convergence of Security and Observability: Top 5 Platform Principles

Bringing together security and observability into one holistic platform raises the technical focus of ITOps, DevOps and Security to the broader business concern of managing risk.
Welcome to the Future of Data Search & Exploration
Platform
3 Minute Read

Welcome to the Future of Data Search & Exploration

Introducing the new SPL2 Search Experience for Splunk Cloud, accelerating the data-to-insight workflow, and bringing the power of Splunk to everyone – learn more here.
Splunk 9.0 SmartStore with Microsoft Azure Container Storage
Platform
4 Minute Read

Splunk 9.0 SmartStore with Microsoft Azure Container Storage

With the release of Splunk 9.0 came support for SmartStore in Azure. Previously to achieve this, you’d have to use some form of S3-compliant broker API, but now we can use native Azure APIs.The addition of this capability means that Splunk now offers complete SmartStore support for all three of the big public cloud vendors. This blog will describe a little bit about how it works, and help you set it up yourself.
Machine Learning at Splunk in Just a Few Clicks
Platform
4 Minute Read

Machine Learning at Splunk in Just a Few Clicks

Explore three new beta applications introduced at .conf22 that simplify complex and time consuming tasks while lowering barriers for customers to unlock the power of ML in everyday workflows.
Dashboard Studio: Level-Up Your App with Dashboard Studio
Platform
2 Minute Read

Dashboard Studio: Level-Up Your App with Dashboard Studio

We reimagined the dashboards in the Microsoft 365 App for Splunk using Dashboard Studio, and you can too!
Data Manager Enables Microsoft Azure Data Onboarding!
Platform
2 Minute Read

Data Manager Enables Microsoft Azure Data Onboarding!

We're excited to share that Data Manager now supports the onboarding of Microsoft Azure data sources, allowing you to use the same Data Manager application in your Splunk Cloud Platform to onboard critical Azure data sources to generate actionable insights in Splunk.
Dashboard Studio: More Maps & More Interactivity
Platform
3 Minute Read

Dashboard Studio: More Maps & More Interactivity

Get a closer look at the expanded interactivity capabilities and visualizations for Dashboard Studio, including more drill-down and interactivity options, more maps, more configuration options.
Deep Learning Toolkit 3.7 and 3.8 - What’s New?
Platform
3 Minute Read

Deep Learning Toolkit 3.7 and 3.8 - What’s New?

We are excited to share the latest advances around the Deep Learning Toolkit App for Splunk (DLTK). These include custom certificates, integration with Splunk Observability and a container operations dashboard, just to name a few.