SlideShare ist ein Scribd-Unternehmen logo
1 von 39
Downloaden Sie, um offline zu lesen
Driving Business Value 
With Continuous Operational 
Intelligence 
1
Today’s Presenters 
Jim Frey 
Vice President of Research, Network 
Management 
Jim has over 25 years of experience in the computing industry 
developing, deploying, managing, and marketing software and 
hardware products, with the last 20 of those years spent in 
network and infrastructure management, straddling both 
enterprise and service provider sectors. 
Erik Giesa 
SVP of Marketing and Business Development, 
ExtraHop Networks 
Erik guides market strategy and execution with a focus on 
helping customers transform their IT operations. Erik offers 
keen insight into the goals and requirements of enterprise IT 
organizations and ensures ExtraHop meets those needs. Erik 
has held executive positions in product management, 
marketing, solutions architecture, and business development 
for companies like F5 Networks, Holistix, WRQ, and hDC 
Express.
Agenda 
• Moving from Ops Monitoring to Continuous Ops Intell 
• ExtraHop Networks: Wire Data Analytics Solutions 
• Three Key Steps to Continuous Operations Intelligence 
• Finding the Right Data Set 
• Turning Data into Operational Intelligence 
• Sharing the Results 
• Wrap-up and Key Takeaways 
• Q&A 
Slide 3 © 2014 Enterprise Management Associates, Inc.
Moving from Operations Monitoring 
to 
Continuous Operational Intelligence 
© 2014 Enterprise Management Associates, Inc.
The Big Picture 
IT has become essential business-enabling mechanism 
• Datacenter/network provides hosting & delivery for applications 
• All orgs use apps & IT services as basis of work/business 
processes 
And so…. 
• IT Ops must establish visibility into health and operations of 
essential application/business infrastructure. 
The challenge 
• Finding relevant insights 
• Keeping up w/ speed of actual business activity 
Slide 5 © 2014 Enterprise Management Associates, Inc.
IT Ops Moving Towards Service, Application 
Orientation – Even the Network Team! 
Which are becoming more important to the network management team? 
66% 
59% 
55% 
55% 
37% 
4% 
0% 10% 20% 30% 40% 50% 60% 70% 
Service Quality 
End User Experience 
Application Performance 
Problem Prevention 
Internal SLAs 
None of the above 
Source: Managing Networks in the Age of Cloud, SDN, and Big Data: Network Management Megatrends 2014, Enterprise Management Associates, April 2014 
Sample Size = 246 
Slide 6 © 2014 Enterprise Management Associates, Inc.
Why Operational Intelligence? 
IT Operations Monitoring is already valuable 
• Especially App-aware/Transaction-centric monitoring 
• Helps connect IT to business priorities 
But there’s much more value to be gained 
• Insights directly into business activity 
• Transaction types, rates and results 
Opportunity 
• Transform IT Monitoring 
into Business Aware Monitoring 
Slide 7 © 2014 Enterprise Management Associates, Inc.
Traditional Options for Business-Aware 
Monitoring 
Business Service Mgmnt (BSM) 
• “Top-Down” approach 
• Gather data via multiple underlying 
“domain” systems 
• Build models and write rules to 
correlate/normalize 
• Advantages: 
• Can be very complete, rigorous 
• Disadvantages: 
• Very expensive to deploy, 
maintain 
• Near real-time, at best 
Business Intelligence (BI) 
• “Data-centric” approach 
• Dump all available data into very 
large database (Big Data) 
• Run periodic or ad hoc queries 
• Advantages: 
• Can reveal important/surprising 
insights 
• Disadvantages: 
• Not real-time 
© 2014 Enterprise Management Associates, Inc.
What is Operational Intelligence? 
• Start with IT Operational Monitoring Data 
• Find Business relevant indicators and metrics 
• Transform into information by data enhancement 
• Apply analytics to elicit actionable results 
• Share the findings, and….. 
• Do it all at the speed of business: 
• REAL-TIME 
• CONTINUOUS 
Slide 9 © 2014 Enterprise Management Associates, Inc.
ExtraHop Networks 
Introduction
“With ExtraHop, we’ve achieved the ‘holy 
grail’ of IT operations. We’re not just 
remediating problems faster, but preventing 
problems from occurring in the first place.” 
— VP of Technical Operations 
Blue-Chip Customers 
Technology Partners 
Industry Recognition 
• Disruptive platform that enables 
greater visibility, insight and IT 
operations intelligence 
• Technology leadership in 
analyzing wire data 
• Monitoring over 1M systems and 
trillions of transactions daily 
• Founded in 2007; rapidly 
emerging leader
Everything Communicates on the Wire 
Fat Which clients, users web and browsers, client types mobile are affected? 
devices, VDI 
clients 
What are users doing on the network? 
Firewalls, How well are applications How well is load balancers, WAN using accelerators, 
the network? 
applications? 
switches, routers 
the network delivering 
Which servers are slow? What are the error 
Clients 
Network Tier 
Web Tier messages? 
Apache, IIS 
Which web services are broken? Which 
applications are affected? Am I detecting 
anomalous behaviors? 
SOAP/XML, JSON, AWS (EC2/SQS/S3), CICS, 
X12, AS2, Riak 
What Java/.is NET, baseline enterprise performance? apps, custom What apps, 
is the 
middleware 
impact of this code update in production? 
Authentication, Is authentication set up correctly on all 
systems? Is there DNS, a DNS FTP 
misconfiguration? 
Which queries are running slow? Which 
methods are used? How does this schema 
change affect performance? 
Oracle, SQL Server, DB2, Informix, MySQL, 
Postgres, Sybase 
What are file access times? Which users are 
SAN, accessing NAS 
sensitive files? Are my files 
exposed? 
Web Services 
App Tier 
Shared Services 
Database Tier 
Storage Tier 
External 
APIs
Three Key Steps to 
Continuous Operational Intelligence
Step #1: Finding the Right Data Source 
Many Choices for Operations Monitoring Data, 
but Not All Fit the Bill for Operational Intelligence 
• SNMP/WMI Polling: Not granular enough, not real-time 
• Logs: Very granular, but incomplete/inconsistent 
• Synthetic test: Helpful for prevention/early warning, but not real 
business activity 
• Wire data: Rich, real-time, all activity 
Slide 14 © 2014 Enterprise Management Associates, Inc.
Wire Data: 
Great Source, if You Can Handle it! 
Challenges with Wire Data 
• High speed/volume: Often 10Gbps+ 
• Low Signal/Noise: Must find relevant details 
• Hidden: Can require decryption 
Slide 15 © 2014 Enterprise Management Associates, Inc.
ExtraHop’s Wire Data Analytics Platform 
L2–L7 Packet Data Structured Wire Data 
ExtraHop’s Real-Time UI 
Real-Time Stream Processor 
Real-Time Stream-Processing for Data-Driven Operations 
Delivers Tremendous Value: 
• Cross-Tier Transaction & User Performance 
• Rapid Problem Identification & Resolution 
• Real-Time Business Analytics 
• Anomaly Detection & Security Monitoring
Core ExtraHop Value: Data Transformation 
From Raw 
Unstructured Data 
The Source of Truth and Insight 
To Structured 
Wire Data
Step #2: Turning Monitoring Data into 
Operational Intelligence 
First: Enhance wire data via additional info sources 
General 
• Translate IP addresses into human/system names 
• Translate protocols into application names 
• Add geo information 
• Etc…..! 
Application/Business-specific 
• Looking up transaction types from codes 
• Finding customer names from codes 
• Cross-referencing product types/families from SKUs 
• Etc…..! 
Slide 18 © 2014 Enterprise Management Associates, Inc.
Step #2: Turning Monitoring Data into 
Operational Intelligence, continued… 
Next: Apply Analytics 
• Track long-term behaviors and trends 
• Statistical Modeling 
• Dynamic Thresholding 
• Identify anomalous levels, events 
• Automation is essential! 
Slide 19 © 2014 Enterprise Management Associates, Inc.
Role-Based & Time-Based Data Visualization 
Role-based visualization 
Time-based comparison. What happened 
yesterday compared to now? 
Frequency-based comparison. What are the 
most frequently accessed files? 
What are the best and worst performing 
systems? Are they within my SLAs?
Rapid Analysis & Visualization 
Simply explore all 
metrics you want to 
visualize, compare, 
overlay, or trend. 
Understand the 
relationship of the top-level 
metric category 
with details. Custom 
metrics are treated as 
first order metrics!
Rapid Analysis & Visualization 
1. Search and add 
metric source 
2. Select associated 
detail metric(s) 
3. Add to dashboard
Rapid Analysis & Visualization
Enriched Insight: Open Data Context API 
The Open Data Context 
API enables customers to 
inject information from a 
wide range of third-party 
sources (e.g. user IDs) 
into ExtraHop’s session 
table, giving wire data 
more context. The API is 
bi-directional and also 
allows external sources to 
pull information from 
ExtraHop’s session table.
Turning Monitoring Data into Operational 
Intelligence 
IT Director 
– Payment Processing Co. 
Is there a correlation between my order 
transaction performance by merchant 
and revenue? Can I capture real-time 
order information without changing my 
apps or creating a rigid, slow, and 
expensive BI architecture?
ExtraHop Wire Data Stream Processing 
From this: REAL-TIME WIRE 
DATA STREAM 
PROCESSING 
of any raw bytes off 
the wire into 
structured data that 
can be measured, 
visualized, alerted 
upon, and trended. 
ExtraHop is the only 
modular and 
programmable Wire 
Data analytics 
platform in the 
industry. 
Customer Requirements: 
• Surgically collect and measure 
only these elements, no more 
Big Data garbage. 
• Do it with zero changes to my 
servers, apps, DBs, or 
infrastructure. 
• Implementation should take 
minutes, not months or years. 
• I want the option to stream this 
data and any other to a non-proprietary 
NoSQL data store to 
combine w/ other data sets.
ExtraHop: Wire Stream Processing in Action 
IT Director 
– Payment Processing Co. 
In less than 30 minutes, I wrote an 
Application Inspection Trigger and 
ExtraHop is correlating order transaction 
performance with all unique transactions, 
orders, and revenue by merchant.
Step #3: Sharing the Results 
What Can You Do With Operations Intelligence?? 
• Adapt for Key Constituencies 
• Personnel: Line of Business / Division / Department 
• Systems: Big Data, Business Intelligence 
• What is needed 
• Flexible, intuitive live dashboards 
• Easily consumable reports 
• APIs, data gateways for direct sharing 
Slide 28 © 2014 Enterprise Management Associates, Inc.
Real-Time Health Care Analytics 
ExtraHop’s out-of-band, real-time 
parsing of HL7 messages enables a 
faster, more accurate, non-invasive, 
and extremely cost 
effective mission operations 
analysis platform. Can easily be 
done by location and any attribute 
found in the HL7 message.
Enhanced Collaboration 
Personal and Shared Dashboards 
Copy/Create/Share Edit/Move Filter
Open Sharing with Other Systems 
Precision Transaction Streaming 
Non-Proprietary 
NoSQL DB 
REAL-TIME 
stream 
processing, 
analysis, 
and 
visualization 
POST-HOC 
Multi-dimensional analysis 
AND/OR 
Visualization Tools 
Chartio 
• Application teams 
• DBAs 
• Network team 
• Security team 
• Virtualization 
team 
• Business owners 
• … and more
We Believe Data Should Be Set Free 
Wire 
Data 
Machine 
Data 
Agent 
Data 
Synthetic 
Data 
Human-generated 
Data 
Open Source 
NoSQL DB 
Open ITOA Principles & Benefits 
• Non-proprietary db: No vendor lock-in 
• High-performance and scale 
• Non-invasive precision data collection 
• Lower costs: No data charge for use or growth 
• Flexible data exploration / analysis 
• Rapid and simple deployment
The Need for Storing & Querying Wire Data Transactions 
IT Director 
– Payment Processing Co. 
Finance called and said one of our 
merchant customers is complaining that 
we’re creating duplicate orders. Their 
customers are upset about over-charging. 
They’ve threatened to move to another 
clearinghouse. 
Is our payment processing 
application and engine broken? 
Which of their customers did 
this happen to, when and 
how many? 
Is it just this one 
merchant or are there 
others? 
How exposed are we to 
SLAs? 
How much revenue was 
involved?
Streaming Intelligence to Open Data Stores 
Limited only by the NoSQL DB’s 
sharding (clustering capability), 
ExtraHop can stream an unlimited 
number of cross-tier transactions 
(up to 400,000 per second from 
one appliance). All transactions are 
time-stamped and can be stored for 
any transaction, protocol and / or 
payload type for post-hoc and multi-dimensional 
analysis. 
All transactions are pre-processed 
and surgically extracted eliminating 
Big Data garbage. Streamed Wire 
Data is stored at no additional cost 
from ExtraHop. Use , combine, and 
grow data without fear.
A Simple Query Answering Hard Questions 
Director of IT 
– Payment Processing Co. 
A duplicate order search of ExtraHop’s Wire 
Data in my NoSQL DB is a simple query 
across tens of millions of records and I don’t 
have to pay for the growth and use of this 
data.
Rapidly Answering Near-Impossible Questions 
Is our payment processing application and engine broken? 
It’s not the payment processing app. Duplicate orders are only being 
processed from a single merchant indicating the problem is on their end. 
Also, in ExtraHop’s real-time dashboards, it shows all transactions have 
been processed without errors. 
Is it just one merchant or are there others we don’t yet know about? 
It’s only one merchant #9145290 which is Acme Inc., the one who called 
Finance.
Rapidly Answering Near-Impossible Questions 
How exposed are we to SLA penalties and how much revenue 
was involved? 
There will be no SLA penalties especially since we isolated the problem 
in under 10 minutes. Overcharges totaling $15K were involved. 
Which of their customers did this happen to, when, and how 
many? 
Only 2 customers were affected. Interestingly, both customers 
purchased an item on the exact same data and time, 08/04/2014 at 
5:51 PM. A call to the merchant revealed that was when IT was 
cutting over two e-commerce apps inherited from their recent 
acquisition of Zexel Corp. In the process, one of the appsmust have 
allowed multiple commits from an impatient user pushing the submit 
button more than once. 
Is it just one merchant or are there others we don’t yet know about? 
It’s only one merchant #9145290 which is Acme Inc., the one who called 
Finance.
EMA Key Takeaways 
• IT Operations Monitoring can evolve/transcend 
traditional functions to address direct, real-time business 
monitoring 
• Find a data set, such as wire data, that can provide the 
insights you need 
• Translate operational monitoring metrics into business 
relevance via data augmentation and analytics 
• Share the results for best leverage 
Slide 38 © 2014 Enterprise Management Associates, Inc.
Q&A 
Try the online interactive demo at 
http://www.extrahop.com/enterprise/start/

Weitere ähnliche Inhalte

Was ist angesagt?

Using Data Science for Cybersecurity
Using Data Science for CybersecurityUsing Data Science for Cybersecurity
Using Data Science for Cybersecurity
VMware Tanzu
 
6. Kepware_IIoT_Solution
6. Kepware_IIoT_Solution6. Kepware_IIoT_Solution
6. Kepware_IIoT_Solution
Steve Lim
 

Was ist angesagt? (20)

Operational Analytics at Credit Suisse from ThousandEyes Connect
Operational Analytics at Credit Suisse from ThousandEyes ConnectOperational Analytics at Credit Suisse from ThousandEyes Connect
Operational Analytics at Credit Suisse from ThousandEyes Connect
 
SplunkLive! Utrecht 2016 - NXP
SplunkLive! Utrecht 2016 - NXPSplunkLive! Utrecht 2016 - NXP
SplunkLive! Utrecht 2016 - NXP
 
How to Design, Build and Map IT and Business Services in Splunk
How to Design, Build and Map IT and Business Services in SplunkHow to Design, Build and Map IT and Business Services in Splunk
How to Design, Build and Map IT and Business Services in Splunk
 
How to Design, Build and Map IT and Business Services in Splunk
How to Design, Build and Map IT and Business Services in SplunkHow to Design, Build and Map IT and Business Services in Splunk
How to Design, Build and Map IT and Business Services in Splunk
 
Affecto Informatica World Tour 2015: The Age of Engagement
Affecto Informatica World Tour 2015: The Age of EngagementAffecto Informatica World Tour 2015: The Age of Engagement
Affecto Informatica World Tour 2015: The Age of Engagement
 
Decide if PhoneGap is for you as your mobile platform selection
Decide if PhoneGap is for you as your mobile platform selectionDecide if PhoneGap is for you as your mobile platform selection
Decide if PhoneGap is for you as your mobile platform selection
 
Taking Splunk to the Next Level - Management Breakout Session
Taking Splunk to the Next Level - Management Breakout SessionTaking Splunk to the Next Level - Management Breakout Session
Taking Splunk to the Next Level - Management Breakout Session
 
Splunk for IT Operations
Splunk for IT OperationsSplunk for IT Operations
Splunk for IT Operations
 
Splunk for IT Operations
Splunk for IT OperationsSplunk for IT Operations
Splunk for IT Operations
 
Security Breakout Session
Security Breakout Session Security Breakout Session
Security Breakout Session
 
Splunk for IT Operations
Splunk for IT OperationsSplunk for IT Operations
Splunk for IT Operations
 
Big Data Application Architectures - Fraud Detection
Big Data Application Architectures - Fraud DetectionBig Data Application Architectures - Fraud Detection
Big Data Application Architectures - Fraud Detection
 
Using Data Science for Cybersecurity
Using Data Science for CybersecurityUsing Data Science for Cybersecurity
Using Data Science for Cybersecurity
 
Keynote Presentation
Keynote PresentationKeynote Presentation
Keynote Presentation
 
Leverage Machine Data and Deliver New Insights for Business Analytics
Leverage Machine Data and Deliver New Insights for Business AnalyticsLeverage Machine Data and Deliver New Insights for Business Analytics
Leverage Machine Data and Deliver New Insights for Business Analytics
 
6. Kepware_IIoT_Solution
6. Kepware_IIoT_Solution6. Kepware_IIoT_Solution
6. Kepware_IIoT_Solution
 
Delivering business value from operational insights at ING Bank
Delivering business value from operational insights at ING BankDelivering business value from operational insights at ING Bank
Delivering business value from operational insights at ING Bank
 
Splunk MINT and Stream Breakout
Splunk MINT and Stream BreakoutSplunk MINT and Stream Breakout
Splunk MINT and Stream Breakout
 
Customer Presentation
Customer PresentationCustomer Presentation
Customer Presentation
 
Delivering Business Value from Operational Inisights at ING Bank
Delivering Business Value from Operational Inisights at ING BankDelivering Business Value from Operational Inisights at ING Bank
Delivering Business Value from Operational Inisights at ING Bank
 

Ähnlich wie EMA Presentation: Driving Business Value with Continuous Operational Intelligence

[Webinar] - Using RPA to Accelerate the Benefits from Shared Services
[Webinar] - Using RPA to Accelerate the Benefits from Shared Services[Webinar] - Using RPA to Accelerate the Benefits from Shared Services
[Webinar] - Using RPA to Accelerate the Benefits from Shared Services
JK Tech
 
Government and Education Webinar: Leveraging SolarWinds to Improve Remote Emp...
Government and Education Webinar: Leveraging SolarWinds to Improve Remote Emp...Government and Education Webinar: Leveraging SolarWinds to Improve Remote Emp...
Government and Education Webinar: Leveraging SolarWinds to Improve Remote Emp...
SolarWinds
 

Ähnlich wie EMA Presentation: Driving Business Value with Continuous Operational Intelligence (20)

Analytics in the Cloud and the ROI for B2B
Analytics in the Cloud and the ROI for B2BAnalytics in the Cloud and the ROI for B2B
Analytics in the Cloud and the ROI for B2B
 
What Does Artificial Intelligence Have to Do with IT Operations?
What Does Artificial Intelligence Have to Do with IT Operations?What Does Artificial Intelligence Have to Do with IT Operations?
What Does Artificial Intelligence Have to Do with IT Operations?
 
Why Modern Systems Require a New Approach to Observability
Why Modern Systems Require a New Approach to ObservabilityWhy Modern Systems Require a New Approach to Observability
Why Modern Systems Require a New Approach to Observability
 
NZS-4555 - IT Analytics Keynote - IT Analytics for the Enterprise
NZS-4555 - IT Analytics Keynote - IT Analytics for the EnterpriseNZS-4555 - IT Analytics Keynote - IT Analytics for the Enterprise
NZS-4555 - IT Analytics Keynote - IT Analytics for the Enterprise
 
Implementing Advanced Analytics Platform
Implementing Advanced Analytics PlatformImplementing Advanced Analytics Platform
Implementing Advanced Analytics Platform
 
Analytics Service Framework
Analytics Service Framework Analytics Service Framework
Analytics Service Framework
 
Aplication data security compliances
Aplication data security compliancesAplication data security compliances
Aplication data security compliances
 
Suffering from “Franken” Monitoring?
Suffering from “Franken” Monitoring?Suffering from “Franken” Monitoring?
Suffering from “Franken” Monitoring?
 
SG Data Mgt - Findings and Recommendations.pptx
SG Data Mgt - Findings and Recommendations.pptxSG Data Mgt - Findings and Recommendations.pptx
SG Data Mgt - Findings and Recommendations.pptx
 
Future-Proof Your Streaming Analytics Architecture- StreamAnalytix Webinar
Future-Proof Your Streaming Analytics Architecture- StreamAnalytix WebinarFuture-Proof Your Streaming Analytics Architecture- StreamAnalytix Webinar
Future-Proof Your Streaming Analytics Architecture- StreamAnalytix Webinar
 
The Zero-ETL Approach: Enhancing Data Agility and Insight
The Zero-ETL Approach: Enhancing Data Agility and InsightThe Zero-ETL Approach: Enhancing Data Agility and Insight
The Zero-ETL Approach: Enhancing Data Agility and Insight
 
The Business Justification for APM
The Business Justification for APMThe Business Justification for APM
The Business Justification for APM
 
Data Analytics in Digital Transformation
Data Analytics in Digital TransformationData Analytics in Digital Transformation
Data Analytics in Digital Transformation
 
Stress Testing for the Digital Economy: Are YOU Ready to Deliver High Perform...
Stress Testing for the Digital Economy: Are YOU Ready to Deliver High Perform...Stress Testing for the Digital Economy: Are YOU Ready to Deliver High Perform...
Stress Testing for the Digital Economy: Are YOU Ready to Deliver High Perform...
 
[Webinar] - Using RPA to Accelerate the Benefits from Shared Services
[Webinar] - Using RPA to Accelerate the Benefits from Shared Services[Webinar] - Using RPA to Accelerate the Benefits from Shared Services
[Webinar] - Using RPA to Accelerate the Benefits from Shared Services
 
Sgcp14dunlea
Sgcp14dunleaSgcp14dunlea
Sgcp14dunlea
 
Self-Service Analytics with Guard Rails
Self-Service Analytics with Guard RailsSelf-Service Analytics with Guard Rails
Self-Service Analytics with Guard Rails
 
Oil and gas big data edition
Oil and gas  big data editionOil and gas  big data edition
Oil and gas big data edition
 
What’s New: Splunk App for Stream and Splunk MINT
What’s New: Splunk App for Stream and Splunk MINTWhat’s New: Splunk App for Stream and Splunk MINT
What’s New: Splunk App for Stream and Splunk MINT
 
Government and Education Webinar: Leveraging SolarWinds to Improve Remote Emp...
Government and Education Webinar: Leveraging SolarWinds to Improve Remote Emp...Government and Education Webinar: Leveraging SolarWinds to Improve Remote Emp...
Government and Education Webinar: Leveraging SolarWinds to Improve Remote Emp...
 

Mehr von ExtraHop Networks

Mehr von ExtraHop Networks (11)

Ransomware: Hard to Stop for Enterprises, Highly Profitable for Criminals
Ransomware: Hard to Stop for Enterprises, Highly Profitable for CriminalsRansomware: Hard to Stop for Enterprises, Highly Profitable for Criminals
Ransomware: Hard to Stop for Enterprises, Highly Profitable for Criminals
 
City of Geel Case Study
City of Geel Case StudyCity of Geel Case Study
City of Geel Case Study
 
Zonar Case Study
Zonar Case StudyZonar Case Study
Zonar Case Study
 
ExtraHop Product Overview Datasheet
ExtraHop Product Overview DatasheetExtraHop Product Overview Datasheet
ExtraHop Product Overview Datasheet
 
Managed Services Provider Serves Customers Better with Wire Data
Managed Services Provider Serves Customers Better with Wire DataManaged Services Provider Serves Customers Better with Wire Data
Managed Services Provider Serves Customers Better with Wire Data
 
Conga case study: Application visibility in AWS with ExtraHop
Conga case study: Application visibility in AWS with ExtraHopConga case study: Application visibility in AWS with ExtraHop
Conga case study: Application visibility in AWS with ExtraHop
 
ExtraHop Atlas Services Operational Excellence datasheet
ExtraHop Atlas Services Operational Excellence datasheetExtraHop Atlas Services Operational Excellence datasheet
ExtraHop Atlas Services Operational Excellence datasheet
 
ExtraHop Atlas Services QuickStart datasheet
ExtraHop Atlas Services QuickStart datasheetExtraHop Atlas Services QuickStart datasheet
ExtraHop Atlas Services QuickStart datasheet
 
ExtraHop Splunk datasheet
ExtraHop Splunk datasheetExtraHop Splunk datasheet
ExtraHop Splunk datasheet
 
Atlas Services Remote Analysis Report Sample
Atlas Services Remote Analysis Report SampleAtlas Services Remote Analysis Report Sample
Atlas Services Remote Analysis Report Sample
 
Web Application Troubleshooting Guide
Web Application Troubleshooting GuideWeb Application Troubleshooting Guide
Web Application Troubleshooting Guide
 

Kürzlich hochgeladen

IAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI SolutionsIAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI Solutions
Enterprise Knowledge
 
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptxEIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
Earley Information Science
 

Kürzlich hochgeladen (20)

IAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI SolutionsIAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI Solutions
 
The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024
 
Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
 
GenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdfGenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdf
 
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
 
Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdfUnderstanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
 
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
 
Presentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreterPresentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreter
 
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
 
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
 
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptxEIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
 
Boost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfBoost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdf
 
Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 
Boost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityBoost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivity
 
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot TakeoffStrategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
 
What Are The Drone Anti-jamming Systems Technology?
What Are The Drone Anti-jamming Systems Technology?What Are The Drone Anti-jamming Systems Technology?
What Are The Drone Anti-jamming Systems Technology?
 
Exploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone ProcessorsExploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone Processors
 

EMA Presentation: Driving Business Value with Continuous Operational Intelligence

  • 1. Driving Business Value With Continuous Operational Intelligence 1
  • 2. Today’s Presenters Jim Frey Vice President of Research, Network Management Jim has over 25 years of experience in the computing industry developing, deploying, managing, and marketing software and hardware products, with the last 20 of those years spent in network and infrastructure management, straddling both enterprise and service provider sectors. Erik Giesa SVP of Marketing and Business Development, ExtraHop Networks Erik guides market strategy and execution with a focus on helping customers transform their IT operations. Erik offers keen insight into the goals and requirements of enterprise IT organizations and ensures ExtraHop meets those needs. Erik has held executive positions in product management, marketing, solutions architecture, and business development for companies like F5 Networks, Holistix, WRQ, and hDC Express.
  • 3. Agenda • Moving from Ops Monitoring to Continuous Ops Intell • ExtraHop Networks: Wire Data Analytics Solutions • Three Key Steps to Continuous Operations Intelligence • Finding the Right Data Set • Turning Data into Operational Intelligence • Sharing the Results • Wrap-up and Key Takeaways • Q&A Slide 3 © 2014 Enterprise Management Associates, Inc.
  • 4. Moving from Operations Monitoring to Continuous Operational Intelligence © 2014 Enterprise Management Associates, Inc.
  • 5. The Big Picture IT has become essential business-enabling mechanism • Datacenter/network provides hosting & delivery for applications • All orgs use apps & IT services as basis of work/business processes And so…. • IT Ops must establish visibility into health and operations of essential application/business infrastructure. The challenge • Finding relevant insights • Keeping up w/ speed of actual business activity Slide 5 © 2014 Enterprise Management Associates, Inc.
  • 6. IT Ops Moving Towards Service, Application Orientation – Even the Network Team! Which are becoming more important to the network management team? 66% 59% 55% 55% 37% 4% 0% 10% 20% 30% 40% 50% 60% 70% Service Quality End User Experience Application Performance Problem Prevention Internal SLAs None of the above Source: Managing Networks in the Age of Cloud, SDN, and Big Data: Network Management Megatrends 2014, Enterprise Management Associates, April 2014 Sample Size = 246 Slide 6 © 2014 Enterprise Management Associates, Inc.
  • 7. Why Operational Intelligence? IT Operations Monitoring is already valuable • Especially App-aware/Transaction-centric monitoring • Helps connect IT to business priorities But there’s much more value to be gained • Insights directly into business activity • Transaction types, rates and results Opportunity • Transform IT Monitoring into Business Aware Monitoring Slide 7 © 2014 Enterprise Management Associates, Inc.
  • 8. Traditional Options for Business-Aware Monitoring Business Service Mgmnt (BSM) • “Top-Down” approach • Gather data via multiple underlying “domain” systems • Build models and write rules to correlate/normalize • Advantages: • Can be very complete, rigorous • Disadvantages: • Very expensive to deploy, maintain • Near real-time, at best Business Intelligence (BI) • “Data-centric” approach • Dump all available data into very large database (Big Data) • Run periodic or ad hoc queries • Advantages: • Can reveal important/surprising insights • Disadvantages: • Not real-time © 2014 Enterprise Management Associates, Inc.
  • 9. What is Operational Intelligence? • Start with IT Operational Monitoring Data • Find Business relevant indicators and metrics • Transform into information by data enhancement • Apply analytics to elicit actionable results • Share the findings, and….. • Do it all at the speed of business: • REAL-TIME • CONTINUOUS Slide 9 © 2014 Enterprise Management Associates, Inc.
  • 11. “With ExtraHop, we’ve achieved the ‘holy grail’ of IT operations. We’re not just remediating problems faster, but preventing problems from occurring in the first place.” — VP of Technical Operations Blue-Chip Customers Technology Partners Industry Recognition • Disruptive platform that enables greater visibility, insight and IT operations intelligence • Technology leadership in analyzing wire data • Monitoring over 1M systems and trillions of transactions daily • Founded in 2007; rapidly emerging leader
  • 12. Everything Communicates on the Wire Fat Which clients, users web and browsers, client types mobile are affected? devices, VDI clients What are users doing on the network? Firewalls, How well are applications How well is load balancers, WAN using accelerators, the network? applications? switches, routers the network delivering Which servers are slow? What are the error Clients Network Tier Web Tier messages? Apache, IIS Which web services are broken? Which applications are affected? Am I detecting anomalous behaviors? SOAP/XML, JSON, AWS (EC2/SQS/S3), CICS, X12, AS2, Riak What Java/.is NET, baseline enterprise performance? apps, custom What apps, is the middleware impact of this code update in production? Authentication, Is authentication set up correctly on all systems? Is there DNS, a DNS FTP misconfiguration? Which queries are running slow? Which methods are used? How does this schema change affect performance? Oracle, SQL Server, DB2, Informix, MySQL, Postgres, Sybase What are file access times? Which users are SAN, accessing NAS sensitive files? Are my files exposed? Web Services App Tier Shared Services Database Tier Storage Tier External APIs
  • 13. Three Key Steps to Continuous Operational Intelligence
  • 14. Step #1: Finding the Right Data Source Many Choices for Operations Monitoring Data, but Not All Fit the Bill for Operational Intelligence • SNMP/WMI Polling: Not granular enough, not real-time • Logs: Very granular, but incomplete/inconsistent • Synthetic test: Helpful for prevention/early warning, but not real business activity • Wire data: Rich, real-time, all activity Slide 14 © 2014 Enterprise Management Associates, Inc.
  • 15. Wire Data: Great Source, if You Can Handle it! Challenges with Wire Data • High speed/volume: Often 10Gbps+ • Low Signal/Noise: Must find relevant details • Hidden: Can require decryption Slide 15 © 2014 Enterprise Management Associates, Inc.
  • 16. ExtraHop’s Wire Data Analytics Platform L2–L7 Packet Data Structured Wire Data ExtraHop’s Real-Time UI Real-Time Stream Processor Real-Time Stream-Processing for Data-Driven Operations Delivers Tremendous Value: • Cross-Tier Transaction & User Performance • Rapid Problem Identification & Resolution • Real-Time Business Analytics • Anomaly Detection & Security Monitoring
  • 17. Core ExtraHop Value: Data Transformation From Raw Unstructured Data The Source of Truth and Insight To Structured Wire Data
  • 18. Step #2: Turning Monitoring Data into Operational Intelligence First: Enhance wire data via additional info sources General • Translate IP addresses into human/system names • Translate protocols into application names • Add geo information • Etc…..! Application/Business-specific • Looking up transaction types from codes • Finding customer names from codes • Cross-referencing product types/families from SKUs • Etc…..! Slide 18 © 2014 Enterprise Management Associates, Inc.
  • 19. Step #2: Turning Monitoring Data into Operational Intelligence, continued… Next: Apply Analytics • Track long-term behaviors and trends • Statistical Modeling • Dynamic Thresholding • Identify anomalous levels, events • Automation is essential! Slide 19 © 2014 Enterprise Management Associates, Inc.
  • 20. Role-Based & Time-Based Data Visualization Role-based visualization Time-based comparison. What happened yesterday compared to now? Frequency-based comparison. What are the most frequently accessed files? What are the best and worst performing systems? Are they within my SLAs?
  • 21. Rapid Analysis & Visualization Simply explore all metrics you want to visualize, compare, overlay, or trend. Understand the relationship of the top-level metric category with details. Custom metrics are treated as first order metrics!
  • 22. Rapid Analysis & Visualization 1. Search and add metric source 2. Select associated detail metric(s) 3. Add to dashboard
  • 23. Rapid Analysis & Visualization
  • 24. Enriched Insight: Open Data Context API The Open Data Context API enables customers to inject information from a wide range of third-party sources (e.g. user IDs) into ExtraHop’s session table, giving wire data more context. The API is bi-directional and also allows external sources to pull information from ExtraHop’s session table.
  • 25. Turning Monitoring Data into Operational Intelligence IT Director – Payment Processing Co. Is there a correlation between my order transaction performance by merchant and revenue? Can I capture real-time order information without changing my apps or creating a rigid, slow, and expensive BI architecture?
  • 26. ExtraHop Wire Data Stream Processing From this: REAL-TIME WIRE DATA STREAM PROCESSING of any raw bytes off the wire into structured data that can be measured, visualized, alerted upon, and trended. ExtraHop is the only modular and programmable Wire Data analytics platform in the industry. Customer Requirements: • Surgically collect and measure only these elements, no more Big Data garbage. • Do it with zero changes to my servers, apps, DBs, or infrastructure. • Implementation should take minutes, not months or years. • I want the option to stream this data and any other to a non-proprietary NoSQL data store to combine w/ other data sets.
  • 27. ExtraHop: Wire Stream Processing in Action IT Director – Payment Processing Co. In less than 30 minutes, I wrote an Application Inspection Trigger and ExtraHop is correlating order transaction performance with all unique transactions, orders, and revenue by merchant.
  • 28. Step #3: Sharing the Results What Can You Do With Operations Intelligence?? • Adapt for Key Constituencies • Personnel: Line of Business / Division / Department • Systems: Big Data, Business Intelligence • What is needed • Flexible, intuitive live dashboards • Easily consumable reports • APIs, data gateways for direct sharing Slide 28 © 2014 Enterprise Management Associates, Inc.
  • 29. Real-Time Health Care Analytics ExtraHop’s out-of-band, real-time parsing of HL7 messages enables a faster, more accurate, non-invasive, and extremely cost effective mission operations analysis platform. Can easily be done by location and any attribute found in the HL7 message.
  • 30. Enhanced Collaboration Personal and Shared Dashboards Copy/Create/Share Edit/Move Filter
  • 31. Open Sharing with Other Systems Precision Transaction Streaming Non-Proprietary NoSQL DB REAL-TIME stream processing, analysis, and visualization POST-HOC Multi-dimensional analysis AND/OR Visualization Tools Chartio • Application teams • DBAs • Network team • Security team • Virtualization team • Business owners • … and more
  • 32. We Believe Data Should Be Set Free Wire Data Machine Data Agent Data Synthetic Data Human-generated Data Open Source NoSQL DB Open ITOA Principles & Benefits • Non-proprietary db: No vendor lock-in • High-performance and scale • Non-invasive precision data collection • Lower costs: No data charge for use or growth • Flexible data exploration / analysis • Rapid and simple deployment
  • 33. The Need for Storing & Querying Wire Data Transactions IT Director – Payment Processing Co. Finance called and said one of our merchant customers is complaining that we’re creating duplicate orders. Their customers are upset about over-charging. They’ve threatened to move to another clearinghouse. Is our payment processing application and engine broken? Which of their customers did this happen to, when and how many? Is it just this one merchant or are there others? How exposed are we to SLAs? How much revenue was involved?
  • 34. Streaming Intelligence to Open Data Stores Limited only by the NoSQL DB’s sharding (clustering capability), ExtraHop can stream an unlimited number of cross-tier transactions (up to 400,000 per second from one appliance). All transactions are time-stamped and can be stored for any transaction, protocol and / or payload type for post-hoc and multi-dimensional analysis. All transactions are pre-processed and surgically extracted eliminating Big Data garbage. Streamed Wire Data is stored at no additional cost from ExtraHop. Use , combine, and grow data without fear.
  • 35. A Simple Query Answering Hard Questions Director of IT – Payment Processing Co. A duplicate order search of ExtraHop’s Wire Data in my NoSQL DB is a simple query across tens of millions of records and I don’t have to pay for the growth and use of this data.
  • 36. Rapidly Answering Near-Impossible Questions Is our payment processing application and engine broken? It’s not the payment processing app. Duplicate orders are only being processed from a single merchant indicating the problem is on their end. Also, in ExtraHop’s real-time dashboards, it shows all transactions have been processed without errors. Is it just one merchant or are there others we don’t yet know about? It’s only one merchant #9145290 which is Acme Inc., the one who called Finance.
  • 37. Rapidly Answering Near-Impossible Questions How exposed are we to SLA penalties and how much revenue was involved? There will be no SLA penalties especially since we isolated the problem in under 10 minutes. Overcharges totaling $15K were involved. Which of their customers did this happen to, when, and how many? Only 2 customers were affected. Interestingly, both customers purchased an item on the exact same data and time, 08/04/2014 at 5:51 PM. A call to the merchant revealed that was when IT was cutting over two e-commerce apps inherited from their recent acquisition of Zexel Corp. In the process, one of the appsmust have allowed multiple commits from an impatient user pushing the submit button more than once. Is it just one merchant or are there others we don’t yet know about? It’s only one merchant #9145290 which is Acme Inc., the one who called Finance.
  • 38. EMA Key Takeaways • IT Operations Monitoring can evolve/transcend traditional functions to address direct, real-time business monitoring • Find a data set, such as wire data, that can provide the insights you need • Translate operational monitoring metrics into business relevance via data augmentation and analytics • Share the results for best leverage Slide 38 © 2014 Enterprise Management Associates, Inc.
  • 39. Q&A Try the online interactive demo at http://www.extrahop.com/enterprise/start/