SlideShare ist ein Scribd-Unternehmen logo
1 von 9
.conf  2011 Keynote Outline August 15, 2011 Web Analytics  Throwdown  with NPR and Intuit Sondra Russell and Tim Suh
24/7
Why Splunk? I started using Splunk because I could… I fell in love because I could…. ,[object Object],[object Object],[object Object],[object Object],[object Object],[object Object]
Audio and Video Tracking: The Basic Setup MP3 Downloads On Demand Flash Live Streams ProgramID (?P<ProgramID>[^]*)(?=) UserAgent (?P<UserAgent>[^amp;quot;]*)(?=amp;quot; ) AppVersion “ *(? =) ” Ingest  Raw Data Extract Fields Define Transactions >   sourcetype = download  AND status < 300  AND Method=Get | transaction IPAddress UserAgent maxspan=120… Create Summary Indexes 08/08/2011=>31800 08/09/2011=>29655 08/10/2011=>29903 08/11/2011=>53443 08/12/2011=>32593 08/13/2011=>88654 08/14/2011=>11231 1 2 3 4
>   index=“summary” search_name=“ si_download_programID ”   ProgramName= “ All Songs Considered ”   “ How has my podcast been doing?” pulls from the summary index maps ProgramID to lookup table
>  *  | eval Platform = mvfilter(match(eventtype,&quot;plat*&quot;)) | timechart span=1w count by Platform  “ What platforms are people using to access our show?” Filters for eventtypes that include “plat”  plat_iphone_browser UserAgent=&quot;*iPhone*&quot; AND UserAgent!=&quot;*NPRRadio*&quot; AND UserAgent!=&quot;*iPod*“ AND sc!=18
>  *  | rex field=_raw &quot;Darwin(?<Version>[0-9]*)amp;quot;“ | top Version “ What percentage of our users have upgraded?” Uses regex to extract element from raw log &quot;NPRMusic/2.7 CFNetwork/459 Darwin/10.0.0d3&quot;
>   index=“twitter” | stats count by story_url “ Which stories are getting Tweeted the most?” timestamp =&quot;2011-07-18T15:40:34Z&quot;,  author =&quot;drpdtapp (Dr. P. D Tapp)&quot;,  tweet =&quot;Tinnitus: Why Won't My Ears Stop Ringing?”,  story_url =&quot;http://www.npr.org/2011/07/18/138163304/tinnitus-why-wont-my-ears-stop-ringing?sc=tw&quot;, Creates reports from a custom log
.conf  2011 Keynote Outline August 15, 2011 Questions? Sondra Russell and Tim Suh

Weitere ähnliche Inhalte

Andere mochten auch

Data Mining with Splunk
Data Mining with SplunkData Mining with Splunk
Data Mining with Splunk
David Carasso
 
Detecting-Preventing-Insider-Threat
Detecting-Preventing-Insider-ThreatDetecting-Preventing-Insider-Threat
Detecting-Preventing-Insider-Threat
Mike Saunders
 

Andere mochten auch (8)

Visualizing the Insider Threat: Challenges and tools for identifying maliciou...
Visualizing the Insider Threat: Challenges and tools for identifying maliciou...Visualizing the Insider Threat: Challenges and tools for identifying maliciou...
Visualizing the Insider Threat: Challenges and tools for identifying maliciou...
 
Threat Hunting
Threat HuntingThreat Hunting
Threat Hunting
 
Rapidly Improving Security Posture - CanDeal
Rapidly Improving Security Posture - CanDealRapidly Improving Security Posture - CanDeal
Rapidly Improving Security Posture - CanDeal
 
Data Mining with Splunk
Data Mining with SplunkData Mining with Splunk
Data Mining with Splunk
 
Insider Threat Kill Chain: Detecting Human Indicators of Compromise
Insider Threat Kill Chain: Detecting Human Indicators of CompromiseInsider Threat Kill Chain: Detecting Human Indicators of Compromise
Insider Threat Kill Chain: Detecting Human Indicators of Compromise
 
Insider threat event presentation
Insider threat event presentationInsider threat event presentation
Insider threat event presentation
 
Delivering business value from operational insights at ING Bank
Delivering business value from operational insights at ING BankDelivering business value from operational insights at ING Bank
Delivering business value from operational insights at ING Bank
 
Detecting-Preventing-Insider-Threat
Detecting-Preventing-Insider-ThreatDetecting-Preventing-Insider-Threat
Detecting-Preventing-Insider-Threat
 

Ähnlich wie .conf2011: Web Analytics Throwdown: with NPR and Intuit

What's New with Windows Phone - FoxCon Talk
What's New with Windows Phone - FoxCon TalkWhat's New with Windows Phone - FoxCon Talk
What's New with Windows Phone - FoxCon Talk
Sam Basu
 
Let's Peel Mangos
Let's Peel MangosLet's Peel Mangos
Let's Peel Mangos
Sam Basu
 

Ähnlich wie .conf2011: Web Analytics Throwdown: with NPR and Intuit (20)

What's New with Windows Phone - FoxCon Talk
What's New with Windows Phone - FoxCon TalkWhat's New with Windows Phone - FoxCon Talk
What's New with Windows Phone - FoxCon Talk
 
Let's Peel Mangos
Let's Peel MangosLet's Peel Mangos
Let's Peel Mangos
 
Building real-time collaborative apps with Ajax.org Platform
Building real-time collaborative apps with Ajax.org PlatformBuilding real-time collaborative apps with Ajax.org Platform
Building real-time collaborative apps with Ajax.org Platform
 
Splunk at opa
Splunk at opaSplunk at opa
Splunk at opa
 
IBM Lotus Notes Domino XPages and XPages for Mobile
IBM Lotus Notes Domino XPages and XPages for MobileIBM Lotus Notes Domino XPages and XPages for Mobile
IBM Lotus Notes Domino XPages and XPages for Mobile
 
Consuming open and linked data with open source tools
Consuming open and linked data with open source toolsConsuming open and linked data with open source tools
Consuming open and linked data with open source tools
 
SplunkLive! Munich 2018: Data Onboarding Overview
SplunkLive! Munich 2018: Data Onboarding OverviewSplunkLive! Munich 2018: Data Onboarding Overview
SplunkLive! Munich 2018: Data Onboarding Overview
 
A Deep Dive into Structured Streaming in Apache Spark
A Deep Dive into Structured Streaming in Apache Spark A Deep Dive into Structured Streaming in Apache Spark
A Deep Dive into Structured Streaming in Apache Spark
 
Machine Data Is EVERYWHERE: Use It for Testing
Machine Data Is EVERYWHERE: Use It for TestingMachine Data Is EVERYWHERE: Use It for Testing
Machine Data Is EVERYWHERE: Use It for Testing
 
SplunkLive! Frankfurt 2018 - Data Onboarding Overview
SplunkLive! Frankfurt 2018 - Data Onboarding OverviewSplunkLive! Frankfurt 2018 - Data Onboarding Overview
SplunkLive! Frankfurt 2018 - Data Onboarding Overview
 
Html5 Overview
Html5 OverviewHtml5 Overview
Html5 Overview
 
Jayson lorenzen iptc_rnews_overview
Jayson lorenzen iptc_rnews_overviewJayson lorenzen iptc_rnews_overview
Jayson lorenzen iptc_rnews_overview
 
What is going on - Application diagnostics on Azure - TechDays Finland
What is going on - Application diagnostics on Azure - TechDays FinlandWhat is going on - Application diagnostics on Azure - TechDays Finland
What is going on - Application diagnostics on Azure - TechDays Finland
 
Beyond the Node: Arkestration with Noah
Beyond the Node: Arkestration with NoahBeyond the Node: Arkestration with Noah
Beyond the Node: Arkestration with Noah
 
A Deep Dive into Structured Streaming: Apache Spark Meetup at Bloomberg 2016
A Deep Dive into Structured Streaming:  Apache Spark Meetup at Bloomberg 2016 A Deep Dive into Structured Streaming:  Apache Spark Meetup at Bloomberg 2016
A Deep Dive into Structured Streaming: Apache Spark Meetup at Bloomberg 2016
 
Presentation wpf
Presentation wpfPresentation wpf
Presentation wpf
 
Mashup Y! widget
Mashup Y! widgetMashup Y! widget
Mashup Y! widget
 
Continuous Application with Structured Streaming 2.0
Continuous Application with Structured Streaming 2.0Continuous Application with Structured Streaming 2.0
Continuous Application with Structured Streaming 2.0
 
Odp
OdpOdp
Odp
 
SplunkLive! Munich 2018: Getting Started with Splunk Enterprise
SplunkLive! Munich 2018: Getting Started with Splunk EnterpriseSplunkLive! Munich 2018: Getting Started with Splunk Enterprise
SplunkLive! Munich 2018: Getting Started with Splunk Enterprise
 

Kürzlich hochgeladen

Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Safe Software
 

Kürzlich hochgeladen (20)

CNIC Information System with Pakdata Cf In Pakistan
CNIC Information System with Pakdata Cf In PakistanCNIC Information System with Pakdata Cf In Pakistan
CNIC Information System with Pakdata Cf In Pakistan
 
Exploring Multimodal Embeddings with Milvus
Exploring Multimodal Embeddings with MilvusExploring Multimodal Embeddings with Milvus
Exploring Multimodal Embeddings with Milvus
 
Ransomware_Q4_2023. The report. [EN].pdf
Ransomware_Q4_2023. The report. [EN].pdfRansomware_Q4_2023. The report. [EN].pdf
Ransomware_Q4_2023. The report. [EN].pdf
 
AWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of TerraformAWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of Terraform
 
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
 
presentation ICT roal in 21st century education
presentation ICT roal in 21st century educationpresentation ICT roal in 21st century education
presentation ICT roal in 21st century education
 
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
 
Boost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfBoost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdf
 
Cyberprint. Dark Pink Apt Group [EN].pdf
Cyberprint. Dark Pink Apt Group [EN].pdfCyberprint. Dark Pink Apt Group [EN].pdf
Cyberprint. Dark Pink Apt Group [EN].pdf
 
Rising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdf
Rising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdfRising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdf
Rising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdf
 
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
 
MS Copilot expands with MS Graph connectors
MS Copilot expands with MS Graph connectorsMS Copilot expands with MS Graph connectors
MS Copilot expands with MS Graph connectors
 
FWD Group - Insurer Innovation Award 2024
FWD Group - Insurer Innovation Award 2024FWD Group - Insurer Innovation Award 2024
FWD Group - Insurer Innovation Award 2024
 
Polkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin WoodPolkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin Wood
 
DBX First Quarter 2024 Investor Presentation
DBX First Quarter 2024 Investor PresentationDBX First Quarter 2024 Investor Presentation
DBX First Quarter 2024 Investor Presentation
 
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost SavingRepurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
 
Manulife - Insurer Transformation Award 2024
Manulife - Insurer Transformation Award 2024Manulife - Insurer Transformation Award 2024
Manulife - Insurer Transformation Award 2024
 
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
 
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
 

.conf2011: Web Analytics Throwdown: with NPR and Intuit

  • 1. .conf 2011 Keynote Outline August 15, 2011 Web Analytics Throwdown with NPR and Intuit Sondra Russell and Tim Suh
  • 3.
  • 4. Audio and Video Tracking: The Basic Setup MP3 Downloads On Demand Flash Live Streams ProgramID (?P<ProgramID>[^]*)(?=) UserAgent (?P<UserAgent>[^amp;quot;]*)(?=amp;quot; ) AppVersion “ *(? =) ” Ingest Raw Data Extract Fields Define Transactions > sourcetype = download AND status < 300 AND Method=Get | transaction IPAddress UserAgent maxspan=120… Create Summary Indexes 08/08/2011=>31800 08/09/2011=>29655 08/10/2011=>29903 08/11/2011=>53443 08/12/2011=>32593 08/13/2011=>88654 08/14/2011=>11231 1 2 3 4
  • 5. > index=“summary” search_name=“ si_download_programID ” ProgramName= “ All Songs Considered ” “ How has my podcast been doing?” pulls from the summary index maps ProgramID to lookup table
  • 6. > * | eval Platform = mvfilter(match(eventtype,&quot;plat*&quot;)) | timechart span=1w count by Platform “ What platforms are people using to access our show?” Filters for eventtypes that include “plat” plat_iphone_browser UserAgent=&quot;*iPhone*&quot; AND UserAgent!=&quot;*NPRRadio*&quot; AND UserAgent!=&quot;*iPod*“ AND sc!=18
  • 7. > * | rex field=_raw &quot;Darwin(?<Version>[0-9]*)amp;quot;“ | top Version “ What percentage of our users have upgraded?” Uses regex to extract element from raw log &quot;NPRMusic/2.7 CFNetwork/459 Darwin/10.0.0d3&quot;
  • 8. > index=“twitter” | stats count by story_url “ Which stories are getting Tweeted the most?” timestamp =&quot;2011-07-18T15:40:34Z&quot;, author =&quot;drpdtapp (Dr. P. D Tapp)&quot;, tweet =&quot;Tinnitus: Why Won't My Ears Stop Ringing?”, story_url =&quot;http://www.npr.org/2011/07/18/138163304/tinnitus-why-wont-my-ears-stop-ringing?sc=tw&quot;, Creates reports from a custom log
  • 9. .conf 2011 Keynote Outline August 15, 2011 Questions? Sondra Russell and Tim Suh