SlideShare ist ein Scribd-Unternehmen logo
1 von 30
Taking'Splunk'to'the'
Next'Level'for'Management
Doug%May
Director,%Global%Business%Value%Consulting
Splunk>
March&11,&2015
Legal'Notice
During the course of this presentation, we may make forward looking statements regarding future
events or the expected performance of the company. We caution you that such statements reflect
our current expectations and estimates based on factors currently known to us and that actual events
or results could differ materially. For important factors that may cause actual results to differ from
those contained in our forward-looking statements, please review our filings with the SEC. The
forward-looking statements made in this presentation are being made as of the time and date of its
live presentation. If reviewed after its live presentation, this presentation may not contain current or
accurate information. We do not assume any obligation to update any forward looking statements
we may make. In addition, any information about our roadmap outlines our general product direction
and is subject to change at any time without notice. It is for informational purposes only and shall
not be incorporated into any contract or other commitment. Splunk undertakes no obligation either to
develop the features or functionality described or to include any such feature or functionality in a
future release.
Splunk®, Splunk>®, Listen to Your Data®, The Engine for Machine Data®, Hunk™, Splunk Cloud™,
Splunk Storm® and SPL™ are registered trademarks or trademarks of Splunk Inc. in the United
States and/or other countries. All other brand names, product names or trademarks belong
to their respective owners. © 2014 Splunk Inc. All rights reserved.
Help Splunk customers, prospects, and partners
document the projected and already realized
business value of making machine data accessible,
usable, and valuable for everyone
Common Deliverables:
› CFO-Ready Business Cases
› Value Realization Studies
› Adoption Roadmaps and Maturity Assessments
› Customer and Use Case Benchmarks
Business Value Consulting @Splunk
3
Why Position Business Value?
4
Your%process%requires%it
Create%and%maintain%visibility
Replicate%success%across%the%org
Accelerate%enterprise%adoption
Maximize%business%results
Splunk is a Hidden Gem
5
Way%cool,%
dude.
What%business%
value%do%I%get?
I’m%invincible!%
Top Challenges to Documenting Value
Lack'of'Splunk'
and'Industry'
Benchmarks
x
Data
Lack'of'Tools'to'
Make'Value'
Measurement'Easy
x
Tools
Not'Enough'
Time'to'Assess'
Your'Value
x
Time
Splunk Can Help Documenting Value
All'Splunk'Tools'
Are'Available'to'
All'of'You
ToolsTime
Tools,'Content'
and'Team'Will'
Save'You'Time
Access'to'Splunk'
and'Industry'
Benchmarks
Data
Best Practices for Documenting & Positioning
Value
Taking your Splunk deployment to the next level
4
Measure and
Track Your
Success
1
Align with Key
Business
Objectives
Qualify and
Quantify
Business Value
2 3
Incremental
Steps with a
Big Picture Plan
Value is in the Eye of the Beholder
1
Align with Key
Business
Objectives
Did%you%know%you%can%save%
15%%on%your%car%insurance%
when%you%call%Geico?
Is%that%important%to%you?
Maybe%it’s%not.
Link your project to important goals and strategies to prioritize your project
Aligning with Company Priorities
10
Profit
Double&revenues&while&
increasing&margins
Productivity
Design&and&implement&to&
most&effective&and&
efficient&business&system
People
Attract,&engage,&and&
retain&the&best&talent
Partners
Become&a&critical&part&of&
our&customers’&growth&
strategies
Portfolio
Double&servings&per&day&
and&be&#1&provider
Planet
Create&advantage&by&
fulfilling&our&Live&
Positively&commitments
“We&also&launched&a&productivity%and%
reinvestment%program%to%create%$550%
million%to%$650%million%in%annual%savings%by%
2015.&By&freeing&up&resources&via&supplyH
chain&optimization,&improved&marketing&
effectiveness,&operational&excellence&and&
systems&standardization,&we%can%invest%more%
in%innovation,&marketing&and&additional&
“feet&on&the&street”%to%drive%our%growth.”&&H
CEO
From%investor%presentations,%annual%reports,%
and%executive%presentations
Steps to Qualify Value
• Align%your%project%with%something%strategic
• Document%why%something%should%change%or%be%added
• Describe%the%current%challenges%and%the%desired%state
• Summarize%and%socialize%O gain%support
• Then%quantify%that%impact
• Summarize&and&Socialize
Qualify and
Quantify
Business Value
2
Qualifying Value Example
12
Visibility'to'Environment'Health'&'User'Exp.
! Brute%force%approach%providing%visibility%to%key%
processes%isn’t%working%and%won’t%scale
! Operations%still%lacks%complete%endOtoOend%visibility%
to%the%environment’s%health,%use%and%trends
! Blinds%spots%still%exist%in%monitoring%and%data%access%
for%Operations%which%could%help%improve%
troubleshooting%and%uptime%/%availability
Incident'/'Issue'Notification
! Brute%force%approach%to%proactive%monitoring%isn’t%
working%consistently%and%won’t%scale
! There’s%a%“Waterfall%effect”%– small%issues%go%
without%broader%notification%triggering%other%issues%
eventually%leading%to%a%bigger%incident
! Users%are%aware%of%issues%before%Operations%and%
call%the%helpdesk%
! All%the%lights%are%“green”%but%still%~65%%of%incidents%
overall%are%reported%first%by%the%business
Troubleshooting'Incidents'/'Issues
! Operations%troubleshooting%is%cumbersome%and%
suboptimal
! It’s%still%manual%across%IT%silos
! It’s%difficult%to%find%root%cause%of%incidents%quickly
! Performance%issues%are%difficult%to%resolve
! Outages%and%impact%are%elongated%due%to%manual%
efforts%and%silos
! Teams%are%distracted%from%their%core%work%when%
they’re%troubleshooting
Recurring'Incidents'/'Issues
! The%Problem%Management%process%isn’t%working%
because%there%are%many%high%severity%incidents%still%
without%root%cause%determined
! As%a%result,%Operations%is%solving%the%same%problems%
again%and%again
! Opportunities%exist%to%improve%on%incident%avoidance%
since%@25%+%of%incidents%are%repeats
DESIRED%STATE%VISION:
Complete%visibility%to%
environment%health%&%trends%
across%full%application%stack%for%all%
stakeholders
Proactively%avoid%issues%before%
the%business%is%impacted
Reduce%MTTR%with%rapid%root%
cause%analysis
Quantifying Value with Splunk Tools
Financial'Analysis'Made'Easy
• Over%40%Value%Calculators
• Driven%by%Actual%Customer%Results
• Complete%Financial%Analysis
• Best%Practice%TCO%Models
Don’t'Forget
• Follow%the%Impact
• Capture%All%the%Value
• Summarize&and&Socialize
13
Execute Against a Strategy
Take directional, incremental steps
• Avoid%being%reactive%– don’t%drive%by%data%source
• Develop%a%plan%to%expand%Splunk
• Link%the%plan%to%strategic%company%goals
• Document%the%anticipated%value
• Set%baselines%for%success
3
Incremental
Steps with a
Big Picture Plan
Measuring & Tracking Success
Helping you take it to the next level
• Demonstrating'success'will'help'further'the'cause
• Tell%the%story%of%your%Splunk%usage
• Compare%your%success%against%Splunk%customer%
benchmarks
• Assess%your%usage%and%staff%maturity
• Then%bring%it%all%together
4
Measure and
Track Your
Success
Measure Success with Value Realization
“Money follows money well spent”
• Summarize%
BEFORE%and%
AFTER%Splunk
• Capture%
metrics%of%
improvement
• Socialize%your%
success
Splunk IT Operations Benchmarks
Know what to project and/or compare how you’re doing
17
Reduced%Sev1%and%
Sev2%incidents%by%43%
Reduced%MTTR%by%
95%%and%reduced%
escalations%by%50%
Improved%capacity%
utilization%and%avoided%
$200k%in%infrastructure
15%'to 45%'reduction%in%system%incidents
70%'to 90%'faster%investigation%of%system%incidents
67%'to 82%'reduction%in%financial%impact%from%outages
5%'to 20%'optimization%with%server%capacity%allocation
Splunk Application Support/Dev Benchmarks
Know what to project and/or compare how you’re doing
18
15%'to 45%'reduction%in%application%incidents
70%'to 90%'faster%investigation%of%QA%defects%and%incidents
10%'to 50%'faster%time%to%market
10%'to 50%'increase%in%value%for%key%projects
Went%from%1%
release/day%to%8%
because%of%Splunk
Shortened%their%
development%
cycles%by%30%
Reduced%the%number%of%
incidents%leading%to%9M%
Euro%per%year%in%revenue%
recaptured
Splunk Security & Compliance Benchmarks
Know what to project and/or compare how you’re doing
19
70%'to 90% improvement%with%detection%and%research%of%events
70% to 90% faster%investigation%of%security%incidents
10% to 50% lower%risks%with%data%breaches,%fraud%and%IP%theft
70% to 90% reduction%in%compliance%labor
Reduced%investigation%
effort%by%more%than%75%
Reduced%the%time%to%
report%on%SAS70%
compliance%by%83%
Reduced%the%number%of%
security%incidents%by%80%
Usage Maturity Assessment – IT OPS
Drive expansion through highlighting value opportunities
20
Groups
%'Data'
Indexed
Log'
Collection
Incident'
Investigation
Root'Cause'
Analysis
Proactive'
Alerting
Operational'
Dashboards
Business
Analytic
s'
Capacity'
PlanningLevel'1'
Triage
Level'2'&'
3'
Escalation
Virtualization 0%
OS'_ Unix 25%
OS'_ Windows 0%
Storage 33%
Network 100%
=%Splunk%fully%in%use% =%Splunk%partially%in%use% =%Splunk%not%in%use
Usage Maturity Assessments – App Dev
Drive expansion through highlighting value opportunities
21
Top'Apps
%'
Indexed
Evaluate'and Assess'Needs Develop'and'Release
Data'Collection Business'Insight
Test'Failure'
Analysis
Defect'
Investigation
SAP 0%
Warehouse'Mgt 0%
E_Commerce'Website 0%
Call'Center 0%
=%Splunk%fully%in%use% =%Splunk%partially%in%use% =%Splunk%not%in%use
Usage Maturity Assessments – Security
Drive expansion through highlighting value opportunities
22
Data'
Sources
%'
Indexed
Log'
Collection
Level'1'
Triage
Monitoring'/'
Alerting
Investigations
Incident
Response
Compliance'
Reporting
Routine'
Log'
Reviews
Threat'Intel:
(3rd Party)
70%
Threat Intel:
(OS%Blacklist)
70%
Network:
(Firewall)
90%
Network:
(IDS/IPS)
90%
Endpoint:
(PCLM)
80%
Access'&'
Identity'Mgt
75%
=%Splunk%fully%in%use% =%Splunk%partially%in%use% =%Splunk%not%in%use
Currently%handled%by%MSSP
Usage Maturity Assessments – Security Controls
Drive expansion through highlighting value opportunities
23
Critical'Control In'Place?
Monitor'unauthorized'devices'or'software
Monitor'unmanaged'devices'or'software'
Monitor'configuration'compliance'
Monitor'patch'compliance'
Monitor'malware'defense
Monitor'application'software'security
Monitor'wireless'access'control
Analyze audit'logs'with'time_based'correlation'
Critical'Control In'Place?
Monitor'use'of'ports,'protocols,'and'services'
Monitor'controlled'use'of'admin'privileges
Monitor'perimeter'IDS
Monitor'controlled'/'uncontrolled access
Monitor'orphan,'expired,'miss'use'of'accounts
Monitor'potential'exfiltration'of'information
Monitor'secure'IP'restriction'policies'
Maintain'data'going'back'months
=%Splunk%fully%in%use% =%Splunk%partially%in%use% =%Splunk%not%in%use
A Real Customer Example - Operations
MostcommonusesofSplunkdeliveringvalue
Business'
Service'
Components
%''of'
Data
Indexed
Log'/'Data'
Collection
Incident'Investigation
Root'Cause'
Analysis
Proactive'
Alerting
Operational'
Dashboards
Business'
AnalyticsLevel'1'
Triage
Level'2'&'3'
Escalation
Custom'Web'Apps 80%
3rd Party'Web_Apps 100%
Apps 75%
Web'Server 50%
Database 100%
OS 100%
Network 95%
=%Splunk%fully%in%use% =%Splunk%partially%in%use% =%Splunk%not%in%use
E_Commerce'Site
Splunk Staffing Roles
Be sure you have the staff and skills to maximize value
25
A%successful%and%scalable%deployment%of%
Splunk%relies%on%the%orchestration%of%key%
roles%and%responsibilities,%primarily%
centered%around:
" Architecture
" Administration
" User%adoption%(Power%User)
" Application%development
Basic Communication Framework
26
Architect
Admin
Works%with%power%users%to%determine%
which%data%sources%should%be%indexed%
to%meet%each%department’s%needs
Scales%the%Splunk%architecture%to%meet%
business%demand
Power'Users Department%Users
Adds%data%sources%to%the%Splunk%
platform%according%to%business%needs
Assist%power%users%with%the%
development%of%advanced%dashboards,%
alerting%and%reporting
Maintains%the%Splunk%SW%and%it’s%
infrastructure%for%optimal%performance%
1%Power%user%per%department
Provides%basic&support&for%new%and%existing%reports%
and%dashboards
Works%with%their%group%to%identify%opportunities%
where%Splunk%can%provide%value%%
Splunk Roles & Recommended Training
27
Splunk'
Roles
Using%
Splunk
Splunk%
Administration
Searching%
and%
Reporting
Creating%
Knowledge%
Objects
Advanced%
Searching%&%
Reporting
Developing
Apps%with%
Splunk
Developing%
with%Splunk
SDKs
Architect Required Required Optional Optional Optional Optional Optional
Admin Required Required Optional Optional
Power%User Required Required Required Optional
Developer Required Optional Required Required Optional Required Optional
for%Splunk%onOpremises
Map Your Roles & Highlight Training Gaps
28
Splunk%Architect
#name
Splunk%
Developer
#name
Security
Power%User
#name
Collaboration
Power%User
#name
Database
Power%User
#name
CRM
Power%User
#name
Network
Power%User
#name
Financial'Apps
Power%User
#name
Splunk%Architect
#name
=%Fully%Trained =%Partially%Trained =%Not%assigned
Web
Power%User
#name
Server
Power%User
#name
Your'Company
Position%Value%in%
Expansion%Area
Taking%it%to%the%Next'Level
Value'Opportunity:''
• faster detection,%
• faster investigation,%
• faster root%cause%
analysis%of%application%
incidents
• fewer'developer%
escalation
After'3'to'6'
months
After'3'to'6'
months
Document%Success%for%
Server%&%Network%teams
Document%Success%for%
App%&%DB%teams
Position%Value%in%
Expansion%Area
Application'
Development
Value'Opportunity:''
• faster'test%analysis,%
• faster'investigation%of%preO
production%bugs,%
• faster'releases%cycles
Position%Value%in%
Expansion%Area
Security'&'
Compliance
Value'Opportunity:''
• faster'detection,%%faster triage,%
• faster investigation%of%security%incidents
Value%Realized:%%
• faster detection,%
• faster investigation,%
• faster root%cause%
analysis%of%system%
incidents
IT'Operations
Application'
Support
Best Practices for Documenting & Positioning
Value
Taking your Splunk deployment to the next level
4
Measure and
Track Your
Success
1
Align with Key
Business
Objectives
Qualify and
Quantify
Business Value
2 3
Incremental
Steps with a
Big Picture Plan

Weitere ähnliche Inhalte

Was ist angesagt?

Was ist angesagt? (20)

Service intelligence hands on workshop
Service intelligence hands on workshopService intelligence hands on workshop
Service intelligence hands on workshop
 
DevOps: Why Should We Care?
DevOps: Why Should We Care?DevOps: Why Should We Care?
DevOps: Why Should We Care?
 
Gap analysis
Gap analysisGap analysis
Gap analysis
 
AppSphere 15 - Smoke Jumping with AppDynamics
AppSphere 15 - Smoke Jumping with AppDynamicsAppSphere 15 - Smoke Jumping with AppDynamics
AppSphere 15 - Smoke Jumping with AppDynamics
 
The Hitchhikers Guide to Service Intelligence
The Hitchhikers Guide to Service Intelligence The Hitchhikers Guide to Service Intelligence
The Hitchhikers Guide to Service Intelligence
 
Agile teams get a grip - martijn groenewegen
Agile teams   get a grip - martijn groenewegenAgile teams   get a grip - martijn groenewegen
Agile teams get a grip - martijn groenewegen
 
Preparing for Your Oracle EBS Cloud Migration: Organizational Readiness
Preparing for Your Oracle EBS Cloud Migration: Organizational ReadinessPreparing for Your Oracle EBS Cloud Migration: Organizational Readiness
Preparing for Your Oracle EBS Cloud Migration: Organizational Readiness
 
Intro to PE 01/26/2016 UK
Intro to PE 01/26/2016 UKIntro to PE 01/26/2016 UK
Intro to PE 01/26/2016 UK
 
Scm webinar digital transformation
Scm webinar   digital transformationScm webinar   digital transformation
Scm webinar digital transformation
 
Behind the Magic – Your ERP Secrets Revealed
Behind the Magic – Your ERP Secrets RevealedBehind the Magic – Your ERP Secrets Revealed
Behind the Magic – Your ERP Secrets Revealed
 
Top 10 Tips for a Successful HCM Cloud Implementation - James King, Oracle & ...
Top 10 Tips for a Successful HCM Cloud Implementation - James King, Oracle & ...Top 10 Tips for a Successful HCM Cloud Implementation - James King, Oracle & ...
Top 10 Tips for a Successful HCM Cloud Implementation - James King, Oracle & ...
 
Moving from ops to dev ops
Moving from ops to dev opsMoving from ops to dev ops
Moving from ops to dev ops
 
Big Data LDN 2018: MICROLISE: USING BIG DATA AND AI IN TRANSPORT AND LOGISTICS
Big Data LDN 2018: MICROLISE: USING BIG DATA AND AI IN TRANSPORT AND LOGISTICSBig Data LDN 2018: MICROLISE: USING BIG DATA AND AI IN TRANSPORT AND LOGISTICS
Big Data LDN 2018: MICROLISE: USING BIG DATA AND AI IN TRANSPORT AND LOGISTICS
 
Metrics driven development 10.09.2014
Metrics driven development   10.09.2014Metrics driven development   10.09.2014
Metrics driven development 10.09.2014
 
The Modern Collaboration Hub: Using Slack and Atlassian to Integrate People, ...
The Modern Collaboration Hub: Using Slack and Atlassian to Integrate People, ...The Modern Collaboration Hub: Using Slack and Atlassian to Integrate People, ...
The Modern Collaboration Hub: Using Slack and Atlassian to Integrate People, ...
 
7 Tips & Tricks to Having Happy Customers at Scale
7 Tips & Tricks to Having Happy Customers at Scale7 Tips & Tricks to Having Happy Customers at Scale
7 Tips & Tricks to Having Happy Customers at Scale
 
DevSecOps Value & Its Organizational Impact: A CSO's Perspective
DevSecOps Value & Its Organizational Impact: A CSO's PerspectiveDevSecOps Value & Its Organizational Impact: A CSO's Perspective
DevSecOps Value & Its Organizational Impact: A CSO's Perspective
 
SAP HANA Cloud Platform - The big picture
SAP HANA Cloud Platform - The big picture SAP HANA Cloud Platform - The big picture
SAP HANA Cloud Platform - The big picture
 
20111110 how puppet-fits_into_your_existing_infrastructure_and_change_managem...
20111110 how puppet-fits_into_your_existing_infrastructure_and_change_managem...20111110 how puppet-fits_into_your_existing_infrastructure_and_change_managem...
20111110 how puppet-fits_into_your_existing_infrastructure_and_change_managem...
 
The Business Case for DevOps - Justifying the Journey
The Business Case for DevOps - Justifying the JourneyThe Business Case for DevOps - Justifying the Journey
The Business Case for DevOps - Justifying the Journey
 

Ähnlich wie Taking Splunk to the Next Level - Management

SplunkLive! Analytics with Splunk Enterprise - Part 1
SplunkLive! Analytics with Splunk Enterprise - Part 1SplunkLive! Analytics with Splunk Enterprise - Part 1
SplunkLive! Analytics with Splunk Enterprise - Part 1
Splunk
 

Ähnlich wie Taking Splunk to the Next Level - Management (20)

Taking Splunk to the Next Level - Management
Taking Splunk to the Next Level - ManagementTaking Splunk to the Next Level - Management
Taking Splunk to the Next Level - Management
 
Taking Splunk to the Next Level - Management Breakout Session
Taking Splunk to the Next Level - Management Breakout SessionTaking Splunk to the Next Level - Management Breakout Session
Taking Splunk to the Next Level - Management Breakout Session
 
Accelerate Digital Transformation of Finance with Concur Solutions
Accelerate Digital Transformation of Finance with Concur Solutions Accelerate Digital Transformation of Finance with Concur Solutions
Accelerate Digital Transformation of Finance with Concur Solutions
 
Accelerate Digital Transformation of Finance with Concur Solutions
Accelerate Digital Transformation of Finance with Concur Solutions 	Accelerate Digital Transformation of Finance with Concur Solutions
Accelerate Digital Transformation of Finance with Concur Solutions
 
Taking Splunk to the Next Level – Management - Advanced
Taking Splunk to the Next Level – Management - AdvancedTaking Splunk to the Next Level – Management - Advanced
Taking Splunk to the Next Level – Management - Advanced
 
Taking Splunk to the Next Level - Management Breakout Session
Taking Splunk to the Next Level - Management Breakout SessionTaking Splunk to the Next Level - Management Breakout Session
Taking Splunk to the Next Level - Management Breakout Session
 
Splunk in Staples: IT Operations
Splunk in Staples: IT OperationsSplunk in Staples: IT Operations
Splunk in Staples: IT Operations
 
SplunkLive! Frankfurt 2018 - Predictive, Proactive, and Collaborative ML with...
SplunkLive! Frankfurt 2018 - Predictive, Proactive, and Collaborative ML with...SplunkLive! Frankfurt 2018 - Predictive, Proactive, and Collaborative ML with...
SplunkLive! Frankfurt 2018 - Predictive, Proactive, and Collaborative ML with...
 
Taking Splunk to the Next Level - New to Splunk
Taking Splunk to the Next Level - New to SplunkTaking Splunk to the Next Level - New to Splunk
Taking Splunk to the Next Level - New to Splunk
 
SplunkLive! Analytics with Splunk Enterprise - Part 1
SplunkLive! Analytics with Splunk Enterprise - Part 1SplunkLive! Analytics with Splunk Enterprise - Part 1
SplunkLive! Analytics with Splunk Enterprise - Part 1
 
How to justify the economic value of your data investment
How to justify the economic value of your data investmentHow to justify the economic value of your data investment
How to justify the economic value of your data investment
 
SplunkLive! Munich 2018: Predictive, Proactive, and Collaborative ML with IT ...
SplunkLive! Munich 2018: Predictive, Proactive, and Collaborative ML with IT ...SplunkLive! Munich 2018: Predictive, Proactive, and Collaborative ML with IT ...
SplunkLive! Munich 2018: Predictive, Proactive, and Collaborative ML with IT ...
 
Stefan Van der Wilt - How can SuccessFactors Analytics support the HR line of...
Stefan Van der Wilt - How can SuccessFactors Analytics support the HR line of...Stefan Van der Wilt - How can SuccessFactors Analytics support the HR line of...
Stefan Van der Wilt - How can SuccessFactors Analytics support the HR line of...
 
Still Suffering from IT Outages? Accept Failure, Learn from Failure and Get R...
Still Suffering from IT Outages? Accept Failure, Learn from Failure and Get R...Still Suffering from IT Outages? Accept Failure, Learn from Failure and Get R...
Still Suffering from IT Outages? Accept Failure, Learn from Failure and Get R...
 
SplunkLive! Paris 2018: Delivering New Visibility And Analytics For IT Operat...
SplunkLive! Paris 2018: Delivering New Visibility And Analytics For IT Operat...SplunkLive! Paris 2018: Delivering New Visibility And Analytics For IT Operat...
SplunkLive! Paris 2018: Delivering New Visibility And Analytics For IT Operat...
 
The C-Suite Data Advantage: How Workday Executives Reduce Costs and Make Bett...
The C-Suite Data Advantage: How Workday Executives Reduce Costs and Make Bett...The C-Suite Data Advantage: How Workday Executives Reduce Costs and Make Bett...
The C-Suite Data Advantage: How Workday Executives Reduce Costs and Make Bett...
 
Extending Splunk to Business Use Cases With Automated Process Mining
Extending Splunk to Business Use Cases With Automated Process MiningExtending Splunk to Business Use Cases With Automated Process Mining
Extending Splunk to Business Use Cases With Automated Process Mining
 
Enterprise Risk Analysis PowerPoint Presentation Slides
Enterprise Risk Analysis PowerPoint Presentation SlidesEnterprise Risk Analysis PowerPoint Presentation Slides
Enterprise Risk Analysis PowerPoint Presentation Slides
 
Extending Splunk to Business use cases with Process Mining
Extending Splunk to Business use cases with Process MiningExtending Splunk to Business use cases with Process Mining
Extending Splunk to Business use cases with Process Mining
 
Extending Splunk to Business use cases with Process Mining
Extending Splunk to Business use cases with Process MiningExtending Splunk to Business use cases with Process Mining
Extending Splunk to Business use cases with Process Mining
 

Mehr von Splunk

Mehr von Splunk (20)

.conf Go 2023 - Data analysis as a routine
.conf Go 2023 - Data analysis as a routine.conf Go 2023 - Data analysis as a routine
.conf Go 2023 - Data analysis as a routine
 
.conf Go 2023 - How KPN drives Customer Satisfaction on IPTV
.conf Go 2023 - How KPN drives Customer Satisfaction on IPTV.conf Go 2023 - How KPN drives Customer Satisfaction on IPTV
.conf Go 2023 - How KPN drives Customer Satisfaction on IPTV
 
.conf Go 2023 - Navegando la normativa SOX (Telefónica)
.conf Go 2023 - Navegando la normativa SOX (Telefónica).conf Go 2023 - Navegando la normativa SOX (Telefónica)
.conf Go 2023 - Navegando la normativa SOX (Telefónica)
 
.conf Go 2023 - Raiffeisen Bank International
.conf Go 2023 - Raiffeisen Bank International.conf Go 2023 - Raiffeisen Bank International
.conf Go 2023 - Raiffeisen Bank International
 
.conf Go 2023 - På liv og død Om sikkerhetsarbeid i Norsk helsenett
.conf Go 2023 - På liv og død Om sikkerhetsarbeid i Norsk helsenett .conf Go 2023 - På liv og død Om sikkerhetsarbeid i Norsk helsenett
.conf Go 2023 - På liv og død Om sikkerhetsarbeid i Norsk helsenett
 
.conf Go 2023 - Many roads lead to Rome - this was our journey (Julius Bär)
.conf Go 2023 - Many roads lead to Rome - this was our journey (Julius Bär).conf Go 2023 - Many roads lead to Rome - this was our journey (Julius Bär)
.conf Go 2023 - Many roads lead to Rome - this was our journey (Julius Bär)
 
.conf Go 2023 - Das passende Rezept für die digitale (Security) Revolution zu...
.conf Go 2023 - Das passende Rezept für die digitale (Security) Revolution zu....conf Go 2023 - Das passende Rezept für die digitale (Security) Revolution zu...
.conf Go 2023 - Das passende Rezept für die digitale (Security) Revolution zu...
 
.conf go 2023 - Cyber Resilienz – Herausforderungen und Ansatz für Energiever...
.conf go 2023 - Cyber Resilienz – Herausforderungen und Ansatz für Energiever....conf go 2023 - Cyber Resilienz – Herausforderungen und Ansatz für Energiever...
.conf go 2023 - Cyber Resilienz – Herausforderungen und Ansatz für Energiever...
 
.conf go 2023 - De NOC a CSIRT (Cellnex)
.conf go 2023 - De NOC a CSIRT (Cellnex).conf go 2023 - De NOC a CSIRT (Cellnex)
.conf go 2023 - De NOC a CSIRT (Cellnex)
 
conf go 2023 - El camino hacia la ciberseguridad (ABANCA)
conf go 2023 - El camino hacia la ciberseguridad (ABANCA)conf go 2023 - El camino hacia la ciberseguridad (ABANCA)
conf go 2023 - El camino hacia la ciberseguridad (ABANCA)
 
Splunk - BMW connects business and IT with data driven operations SRE and O11y
Splunk - BMW connects business and IT with data driven operations SRE and O11ySplunk - BMW connects business and IT with data driven operations SRE and O11y
Splunk - BMW connects business and IT with data driven operations SRE and O11y
 
Splunk x Freenet - .conf Go Köln
Splunk x Freenet - .conf Go KölnSplunk x Freenet - .conf Go Köln
Splunk x Freenet - .conf Go Köln
 
Splunk Security Session - .conf Go Köln
Splunk Security Session - .conf Go KölnSplunk Security Session - .conf Go Köln
Splunk Security Session - .conf Go Köln
 
Data foundations building success, at city scale – Imperial College London
 Data foundations building success, at city scale – Imperial College London Data foundations building success, at city scale – Imperial College London
Data foundations building success, at city scale – Imperial College London
 
Splunk: How Vodafone established Operational Analytics in a Hybrid Environmen...
Splunk: How Vodafone established Operational Analytics in a Hybrid Environmen...Splunk: How Vodafone established Operational Analytics in a Hybrid Environmen...
Splunk: How Vodafone established Operational Analytics in a Hybrid Environmen...
 
SOC, Amore Mio! | Security Webinar
SOC, Amore Mio! | Security WebinarSOC, Amore Mio! | Security Webinar
SOC, Amore Mio! | Security Webinar
 
.conf Go 2022 - Observability Session
.conf Go 2022 - Observability Session.conf Go 2022 - Observability Session
.conf Go 2022 - Observability Session
 
.conf Go Zurich 2022 - Keynote
.conf Go Zurich 2022 - Keynote.conf Go Zurich 2022 - Keynote
.conf Go Zurich 2022 - Keynote
 
.conf Go Zurich 2022 - Platform Session
.conf Go Zurich 2022 - Platform Session.conf Go Zurich 2022 - Platform Session
.conf Go Zurich 2022 - Platform Session
 
.conf Go Zurich 2022 - Security Session
.conf Go Zurich 2022 - Security Session.conf Go Zurich 2022 - Security Session
.conf Go Zurich 2022 - Security Session
 

Kürzlich hochgeladen

Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Finding Java's Hidden Performance Traps @ DevoxxUK 2024Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Victor Rentea
 
Architecting Cloud Native Applications
Architecting Cloud Native ApplicationsArchitecting Cloud Native Applications
Architecting Cloud Native Applications
WSO2
 
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Victor Rentea
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Safe Software
 
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
?#DUbAI#??##{{(☎️+971_581248768%)**%*]'#abortion pills for sale in dubai@
 

Kürzlich hochgeladen (20)

Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Finding Java's Hidden Performance Traps @ DevoxxUK 2024Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Finding Java's Hidden Performance Traps @ DevoxxUK 2024
 
DEV meet-up UiPath Document Understanding May 7 2024 Amsterdam
DEV meet-up UiPath Document Understanding May 7 2024 AmsterdamDEV meet-up UiPath Document Understanding May 7 2024 Amsterdam
DEV meet-up UiPath Document Understanding May 7 2024 Amsterdam
 
Architecting Cloud Native Applications
Architecting Cloud Native ApplicationsArchitecting Cloud Native Applications
Architecting Cloud Native Applications
 
Mcleodganj Call Girls 🥰 8617370543 Service Offer VIP Hot Model
Mcleodganj Call Girls 🥰 8617370543 Service Offer VIP Hot ModelMcleodganj Call Girls 🥰 8617370543 Service Offer VIP Hot Model
Mcleodganj Call Girls 🥰 8617370543 Service Offer VIP Hot Model
 
"I see eyes in my soup": How Delivery Hero implemented the safety system for ...
"I see eyes in my soup": How Delivery Hero implemented the safety system for ..."I see eyes in my soup": How Delivery Hero implemented the safety system for ...
"I see eyes in my soup": How Delivery Hero implemented the safety system for ...
 
CNIC Information System with Pakdata Cf In Pakistan
CNIC Information System with Pakdata Cf In PakistanCNIC Information System with Pakdata Cf In Pakistan
CNIC Information System with Pakdata Cf In Pakistan
 
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
 
Understanding the FAA Part 107 License ..
Understanding the FAA Part 107 License ..Understanding the FAA Part 107 License ..
Understanding the FAA Part 107 License ..
 
presentation ICT roal in 21st century education
presentation ICT roal in 21st century educationpresentation ICT roal in 21st century education
presentation ICT roal in 21st century education
 
Boost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfBoost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdf
 
Elevate Developer Efficiency & build GenAI Application with Amazon Q​
Elevate Developer Efficiency & build GenAI Application with Amazon Q​Elevate Developer Efficiency & build GenAI Application with Amazon Q​
Elevate Developer Efficiency & build GenAI Application with Amazon Q​
 
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
 
Strategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a FresherStrategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a Fresher
 
Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...
 
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
 
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
 
Six Myths about Ontologies: The Basics of Formal Ontology
Six Myths about Ontologies: The Basics of Formal OntologySix Myths about Ontologies: The Basics of Formal Ontology
Six Myths about Ontologies: The Basics of Formal Ontology
 
Biography Of Angeliki Cooney | Senior Vice President Life Sciences | Albany, ...
Biography Of Angeliki Cooney | Senior Vice President Life Sciences | Albany, ...Biography Of Angeliki Cooney | Senior Vice President Life Sciences | Albany, ...
Biography Of Angeliki Cooney | Senior Vice President Life Sciences | Albany, ...
 
WSO2's API Vision: Unifying Control, Empowering Developers
WSO2's API Vision: Unifying Control, Empowering DevelopersWSO2's API Vision: Unifying Control, Empowering Developers
WSO2's API Vision: Unifying Control, Empowering Developers
 

Taking Splunk to the Next Level - Management

  • 2. Legal'Notice During the course of this presentation, we may make forward looking statements regarding future events or the expected performance of the company. We caution you that such statements reflect our current expectations and estimates based on factors currently known to us and that actual events or results could differ materially. For important factors that may cause actual results to differ from those contained in our forward-looking statements, please review our filings with the SEC. The forward-looking statements made in this presentation are being made as of the time and date of its live presentation. If reviewed after its live presentation, this presentation may not contain current or accurate information. We do not assume any obligation to update any forward looking statements we may make. In addition, any information about our roadmap outlines our general product direction and is subject to change at any time without notice. It is for informational purposes only and shall not be incorporated into any contract or other commitment. Splunk undertakes no obligation either to develop the features or functionality described or to include any such feature or functionality in a future release. Splunk®, Splunk>®, Listen to Your Data®, The Engine for Machine Data®, Hunk™, Splunk Cloud™, Splunk Storm® and SPL™ are registered trademarks or trademarks of Splunk Inc. in the United States and/or other countries. All other brand names, product names or trademarks belong to their respective owners. © 2014 Splunk Inc. All rights reserved.
  • 3. Help Splunk customers, prospects, and partners document the projected and already realized business value of making machine data accessible, usable, and valuable for everyone Common Deliverables: › CFO-Ready Business Cases › Value Realization Studies › Adoption Roadmaps and Maturity Assessments › Customer and Use Case Benchmarks Business Value Consulting @Splunk 3
  • 4. Why Position Business Value? 4 Your%process%requires%it Create%and%maintain%visibility Replicate%success%across%the%org Accelerate%enterprise%adoption Maximize%business%results
  • 5. Splunk is a Hidden Gem 5 Way%cool,% dude. What%business% value%do%I%get? I’m%invincible!%
  • 6. Top Challenges to Documenting Value Lack'of'Splunk' and'Industry' Benchmarks x Data Lack'of'Tools'to' Make'Value' Measurement'Easy x Tools Not'Enough' Time'to'Assess' Your'Value x Time
  • 7. Splunk Can Help Documenting Value All'Splunk'Tools' Are'Available'to' All'of'You ToolsTime Tools,'Content' and'Team'Will' Save'You'Time Access'to'Splunk' and'Industry' Benchmarks Data
  • 8. Best Practices for Documenting & Positioning Value Taking your Splunk deployment to the next level 4 Measure and Track Your Success 1 Align with Key Business Objectives Qualify and Quantify Business Value 2 3 Incremental Steps with a Big Picture Plan
  • 9. Value is in the Eye of the Beholder 1 Align with Key Business Objectives Did%you%know%you%can%save% 15%%on%your%car%insurance% when%you%call%Geico? Is%that%important%to%you? Maybe%it’s%not.
  • 10. Link your project to important goals and strategies to prioritize your project Aligning with Company Priorities 10 Profit Double&revenues&while& increasing&margins Productivity Design&and&implement&to& most&effective&and& efficient&business&system People Attract,&engage,&and& retain&the&best&talent Partners Become&a&critical&part&of& our&customers’&growth& strategies Portfolio Double&servings&per&day& and&be&#1&provider Planet Create&advantage&by& fulfilling&our&Live& Positively&commitments “We&also&launched&a&productivity%and% reinvestment%program%to%create%$550% million%to%$650%million%in%annual%savings%by% 2015.&By&freeing&up&resources&via&supplyH chain&optimization,&improved&marketing& effectiveness,&operational&excellence&and& systems&standardization,&we%can%invest%more% in%innovation,&marketing&and&additional& “feet&on&the&street”%to%drive%our%growth.”&&H CEO From%investor%presentations,%annual%reports,% and%executive%presentations
  • 11. Steps to Qualify Value • Align%your%project%with%something%strategic • Document%why%something%should%change%or%be%added • Describe%the%current%challenges%and%the%desired%state • Summarize%and%socialize%O gain%support • Then%quantify%that%impact • Summarize&and&Socialize Qualify and Quantify Business Value 2
  • 12. Qualifying Value Example 12 Visibility'to'Environment'Health'&'User'Exp. ! Brute%force%approach%providing%visibility%to%key% processes%isn’t%working%and%won’t%scale ! Operations%still%lacks%complete%endOtoOend%visibility% to%the%environment’s%health,%use%and%trends ! Blinds%spots%still%exist%in%monitoring%and%data%access% for%Operations%which%could%help%improve% troubleshooting%and%uptime%/%availability Incident'/'Issue'Notification ! Brute%force%approach%to%proactive%monitoring%isn’t% working%consistently%and%won’t%scale ! There’s%a%“Waterfall%effect”%– small%issues%go% without%broader%notification%triggering%other%issues% eventually%leading%to%a%bigger%incident ! Users%are%aware%of%issues%before%Operations%and% call%the%helpdesk% ! All%the%lights%are%“green”%but%still%~65%%of%incidents% overall%are%reported%first%by%the%business Troubleshooting'Incidents'/'Issues ! Operations%troubleshooting%is%cumbersome%and% suboptimal ! It’s%still%manual%across%IT%silos ! It’s%difficult%to%find%root%cause%of%incidents%quickly ! Performance%issues%are%difficult%to%resolve ! Outages%and%impact%are%elongated%due%to%manual% efforts%and%silos ! Teams%are%distracted%from%their%core%work%when% they’re%troubleshooting Recurring'Incidents'/'Issues ! The%Problem%Management%process%isn’t%working% because%there%are%many%high%severity%incidents%still% without%root%cause%determined ! As%a%result,%Operations%is%solving%the%same%problems% again%and%again ! Opportunities%exist%to%improve%on%incident%avoidance% since%@25%+%of%incidents%are%repeats DESIRED%STATE%VISION: Complete%visibility%to% environment%health%&%trends% across%full%application%stack%for%all% stakeholders Proactively%avoid%issues%before% the%business%is%impacted Reduce%MTTR%with%rapid%root% cause%analysis
  • 13. Quantifying Value with Splunk Tools Financial'Analysis'Made'Easy • Over%40%Value%Calculators • Driven%by%Actual%Customer%Results • Complete%Financial%Analysis • Best%Practice%TCO%Models Don’t'Forget • Follow%the%Impact • Capture%All%the%Value • Summarize&and&Socialize 13
  • 14. Execute Against a Strategy Take directional, incremental steps • Avoid%being%reactive%– don’t%drive%by%data%source • Develop%a%plan%to%expand%Splunk • Link%the%plan%to%strategic%company%goals • Document%the%anticipated%value • Set%baselines%for%success 3 Incremental Steps with a Big Picture Plan
  • 15. Measuring & Tracking Success Helping you take it to the next level • Demonstrating'success'will'help'further'the'cause • Tell%the%story%of%your%Splunk%usage • Compare%your%success%against%Splunk%customer% benchmarks • Assess%your%usage%and%staff%maturity • Then%bring%it%all%together 4 Measure and Track Your Success
  • 16. Measure Success with Value Realization “Money follows money well spent” • Summarize% BEFORE%and% AFTER%Splunk • Capture% metrics%of% improvement • Socialize%your% success
  • 17. Splunk IT Operations Benchmarks Know what to project and/or compare how you’re doing 17 Reduced%Sev1%and% Sev2%incidents%by%43% Reduced%MTTR%by% 95%%and%reduced% escalations%by%50% Improved%capacity% utilization%and%avoided% $200k%in%infrastructure 15%'to 45%'reduction%in%system%incidents 70%'to 90%'faster%investigation%of%system%incidents 67%'to 82%'reduction%in%financial%impact%from%outages 5%'to 20%'optimization%with%server%capacity%allocation
  • 18. Splunk Application Support/Dev Benchmarks Know what to project and/or compare how you’re doing 18 15%'to 45%'reduction%in%application%incidents 70%'to 90%'faster%investigation%of%QA%defects%and%incidents 10%'to 50%'faster%time%to%market 10%'to 50%'increase%in%value%for%key%projects Went%from%1% release/day%to%8% because%of%Splunk Shortened%their% development% cycles%by%30% Reduced%the%number%of% incidents%leading%to%9M% Euro%per%year%in%revenue% recaptured
  • 19. Splunk Security & Compliance Benchmarks Know what to project and/or compare how you’re doing 19 70%'to 90% improvement%with%detection%and%research%of%events 70% to 90% faster%investigation%of%security%incidents 10% to 50% lower%risks%with%data%breaches,%fraud%and%IP%theft 70% to 90% reduction%in%compliance%labor Reduced%investigation% effort%by%more%than%75% Reduced%the%time%to% report%on%SAS70% compliance%by%83% Reduced%the%number%of% security%incidents%by%80%
  • 20. Usage Maturity Assessment – IT OPS Drive expansion through highlighting value opportunities 20 Groups %'Data' Indexed Log' Collection Incident' Investigation Root'Cause' Analysis Proactive' Alerting Operational' Dashboards Business Analytic s' Capacity' PlanningLevel'1' Triage Level'2'&' 3' Escalation Virtualization 0% OS'_ Unix 25% OS'_ Windows 0% Storage 33% Network 100% =%Splunk%fully%in%use% =%Splunk%partially%in%use% =%Splunk%not%in%use
  • 21. Usage Maturity Assessments – App Dev Drive expansion through highlighting value opportunities 21 Top'Apps %' Indexed Evaluate'and Assess'Needs Develop'and'Release Data'Collection Business'Insight Test'Failure' Analysis Defect' Investigation SAP 0% Warehouse'Mgt 0% E_Commerce'Website 0% Call'Center 0% =%Splunk%fully%in%use% =%Splunk%partially%in%use% =%Splunk%not%in%use
  • 22. Usage Maturity Assessments – Security Drive expansion through highlighting value opportunities 22 Data' Sources %' Indexed Log' Collection Level'1' Triage Monitoring'/' Alerting Investigations Incident Response Compliance' Reporting Routine' Log' Reviews Threat'Intel: (3rd Party) 70% Threat Intel: (OS%Blacklist) 70% Network: (Firewall) 90% Network: (IDS/IPS) 90% Endpoint: (PCLM) 80% Access'&' Identity'Mgt 75% =%Splunk%fully%in%use% =%Splunk%partially%in%use% =%Splunk%not%in%use Currently%handled%by%MSSP
  • 23. Usage Maturity Assessments – Security Controls Drive expansion through highlighting value opportunities 23 Critical'Control In'Place? Monitor'unauthorized'devices'or'software Monitor'unmanaged'devices'or'software' Monitor'configuration'compliance' Monitor'patch'compliance' Monitor'malware'defense Monitor'application'software'security Monitor'wireless'access'control Analyze audit'logs'with'time_based'correlation' Critical'Control In'Place? Monitor'use'of'ports,'protocols,'and'services' Monitor'controlled'use'of'admin'privileges Monitor'perimeter'IDS Monitor'controlled'/'uncontrolled access Monitor'orphan,'expired,'miss'use'of'accounts Monitor'potential'exfiltration'of'information Monitor'secure'IP'restriction'policies' Maintain'data'going'back'months =%Splunk%fully%in%use% =%Splunk%partially%in%use% =%Splunk%not%in%use
  • 24. A Real Customer Example - Operations MostcommonusesofSplunkdeliveringvalue Business' Service' Components %''of' Data Indexed Log'/'Data' Collection Incident'Investigation Root'Cause' Analysis Proactive' Alerting Operational' Dashboards Business' AnalyticsLevel'1' Triage Level'2'&'3' Escalation Custom'Web'Apps 80% 3rd Party'Web_Apps 100% Apps 75% Web'Server 50% Database 100% OS 100% Network 95% =%Splunk%fully%in%use% =%Splunk%partially%in%use% =%Splunk%not%in%use E_Commerce'Site
  • 25. Splunk Staffing Roles Be sure you have the staff and skills to maximize value 25 A%successful%and%scalable%deployment%of% Splunk%relies%on%the%orchestration%of%key% roles%and%responsibilities,%primarily% centered%around: " Architecture " Administration " User%adoption%(Power%User) " Application%development
  • 26. Basic Communication Framework 26 Architect Admin Works%with%power%users%to%determine% which%data%sources%should%be%indexed% to%meet%each%department’s%needs Scales%the%Splunk%architecture%to%meet% business%demand Power'Users Department%Users Adds%data%sources%to%the%Splunk% platform%according%to%business%needs Assist%power%users%with%the% development%of%advanced%dashboards,% alerting%and%reporting Maintains%the%Splunk%SW%and%it’s% infrastructure%for%optimal%performance% 1%Power%user%per%department Provides%basic&support&for%new%and%existing%reports% and%dashboards Works%with%their%group%to%identify%opportunities% where%Splunk%can%provide%value%%
  • 27. Splunk Roles & Recommended Training 27 Splunk' Roles Using% Splunk Splunk% Administration Searching% and% Reporting Creating% Knowledge% Objects Advanced% Searching%&% Reporting Developing Apps%with% Splunk Developing% with%Splunk SDKs Architect Required Required Optional Optional Optional Optional Optional Admin Required Required Optional Optional Power%User Required Required Required Optional Developer Required Optional Required Required Optional Required Optional for%Splunk%onOpremises
  • 28. Map Your Roles & Highlight Training Gaps 28 Splunk%Architect #name Splunk% Developer #name Security Power%User #name Collaboration Power%User #name Database Power%User #name CRM Power%User #name Network Power%User #name Financial'Apps Power%User #name Splunk%Architect #name =%Fully%Trained =%Partially%Trained =%Not%assigned Web Power%User #name Server Power%User #name Your'Company
  • 29. Position%Value%in% Expansion%Area Taking%it%to%the%Next'Level Value'Opportunity:'' • faster detection,% • faster investigation,% • faster root%cause% analysis%of%application% incidents • fewer'developer% escalation After'3'to'6' months After'3'to'6' months Document%Success%for% Server%&%Network%teams Document%Success%for% App%&%DB%teams Position%Value%in% Expansion%Area Application' Development Value'Opportunity:'' • faster'test%analysis,% • faster'investigation%of%preO production%bugs,% • faster'releases%cycles Position%Value%in% Expansion%Area Security'&' Compliance Value'Opportunity:'' • faster'detection,%%faster triage,% • faster investigation%of%security%incidents Value%Realized:%% • faster detection,% • faster investigation,% • faster root%cause% analysis%of%system% incidents IT'Operations Application' Support
  • 30. Best Practices for Documenting & Positioning Value Taking your Splunk deployment to the next level 4 Measure and Track Your Success 1 Align with Key Business Objectives Qualify and Quantify Business Value 2 3 Incremental Steps with a Big Picture Plan