SlideShare ist ein Scribd-Unternehmen logo
1 von 9
.conf  2011 Keynote Outline August 15, 2011 Web Analytics  Throwdown  with NPR and Intuit Sondra Russell and Tim Suh
24/7
Why Splunk? I started using Splunk because I could… I fell in love because I could…. ,[object Object],[object Object],[object Object],[object Object],[object Object],[object Object]
Audio and Video Tracking: The Basic Setup MP3 Downloads On Demand Flash Live Streams ProgramID (?P<ProgramID>[^]*)(?=) UserAgent (?P<UserAgent>[^amp;quot;]*)(?=amp;quot; ) AppVersion “ *(? =) ” Ingest  Raw Data Extract Fields Define Transactions >   sourcetype = download  AND status < 300  AND Method=Get | transaction IPAddress UserAgent maxspan=120… Create Summary Indexes 08/08/2011=>31800 08/09/2011=>29655 08/10/2011=>29903 08/11/2011=>53443 08/12/2011=>32593 08/13/2011=>88654 08/14/2011=>11231 1 2 3 4
>   index=“summary” search_name=“ si_download_programID ”   ProgramName= “ All Songs Considered ”   “ How has my podcast been doing?” pulls from the summary index maps ProgramID to lookup table
>  *  | eval Platform = mvfilter(match(eventtype,&quot;plat*&quot;)) | timechart span=1w count by Platform  “ What platforms are people using to access our show?” Filters for eventtypes that include “plat”  plat_iphone_browser UserAgent=&quot;*iPhone*&quot; AND UserAgent!=&quot;*NPRRadio*&quot; AND UserAgent!=&quot;*iPod*“ AND sc!=18
>  *  | rex field=_raw &quot;Darwin(?<Version>[0-9]*)amp;quot;“ | top Version “ What percentage of our users have upgraded?” Uses regex to extract element from raw log &quot;NPRMusic/2.7 CFNetwork/459 Darwin/10.0.0d3&quot;
>   index=“twitter” | stats count by story_url “ Which stories are getting Tweeted the most?” timestamp =&quot;2011-07-18T15:40:34Z&quot;,  author =&quot;drpdtapp (Dr. P. D Tapp)&quot;,  tweet =&quot;Tinnitus: Why Won't My Ears Stop Ringing?”,  story_url =&quot;http://www.npr.org/2011/07/18/138163304/tinnitus-why-wont-my-ears-stop-ringing?sc=tw&quot;, Creates reports from a custom log
.conf  2011 Keynote Outline August 15, 2011 Questions? Sondra Russell and Tim Suh

Weitere ähnliche Inhalte

Andere mochten auch

Data Mining with Splunk
Data Mining with SplunkData Mining with Splunk
Data Mining with Splunk
David Carasso
 
Detecting-Preventing-Insider-Threat
Detecting-Preventing-Insider-ThreatDetecting-Preventing-Insider-Threat
Detecting-Preventing-Insider-Threat
Mike Saunders
 

Andere mochten auch (8)

Visualizing the Insider Threat: Challenges and tools for identifying maliciou...
Visualizing the Insider Threat: Challenges and tools for identifying maliciou...Visualizing the Insider Threat: Challenges and tools for identifying maliciou...
Visualizing the Insider Threat: Challenges and tools for identifying maliciou...
 
Threat Hunting
Threat HuntingThreat Hunting
Threat Hunting
 
Rapidly Improving Security Posture - CanDeal
Rapidly Improving Security Posture - CanDealRapidly Improving Security Posture - CanDeal
Rapidly Improving Security Posture - CanDeal
 
Data Mining with Splunk
Data Mining with SplunkData Mining with Splunk
Data Mining with Splunk
 
Insider Threat Kill Chain: Detecting Human Indicators of Compromise
Insider Threat Kill Chain: Detecting Human Indicators of CompromiseInsider Threat Kill Chain: Detecting Human Indicators of Compromise
Insider Threat Kill Chain: Detecting Human Indicators of Compromise
 
Insider threat event presentation
Insider threat event presentationInsider threat event presentation
Insider threat event presentation
 
Delivering business value from operational insights at ING Bank
Delivering business value from operational insights at ING BankDelivering business value from operational insights at ING Bank
Delivering business value from operational insights at ING Bank
 
Detecting-Preventing-Insider-Threat
Detecting-Preventing-Insider-ThreatDetecting-Preventing-Insider-Threat
Detecting-Preventing-Insider-Threat
 

Ähnlich wie .conf2011: Web Analytics Throwdown: with NPR and Intuit

What's New with Windows Phone - FoxCon Talk
What's New with Windows Phone - FoxCon TalkWhat's New with Windows Phone - FoxCon Talk
What's New with Windows Phone - FoxCon Talk
Sam Basu
 
Let's Peel Mangos
Let's Peel MangosLet's Peel Mangos
Let's Peel Mangos
Sam Basu
 

Ähnlich wie .conf2011: Web Analytics Throwdown: with NPR and Intuit (20)

What's New with Windows Phone - FoxCon Talk
What's New with Windows Phone - FoxCon TalkWhat's New with Windows Phone - FoxCon Talk
What's New with Windows Phone - FoxCon Talk
 
Let's Peel Mangos
Let's Peel MangosLet's Peel Mangos
Let's Peel Mangos
 
Building real-time collaborative apps with Ajax.org Platform
Building real-time collaborative apps with Ajax.org PlatformBuilding real-time collaborative apps with Ajax.org Platform
Building real-time collaborative apps with Ajax.org Platform
 
Splunk at opa
Splunk at opaSplunk at opa
Splunk at opa
 
IBM Lotus Notes Domino XPages and XPages for Mobile
IBM Lotus Notes Domino XPages and XPages for MobileIBM Lotus Notes Domino XPages and XPages for Mobile
IBM Lotus Notes Domino XPages and XPages for Mobile
 
Consuming open and linked data with open source tools
Consuming open and linked data with open source toolsConsuming open and linked data with open source tools
Consuming open and linked data with open source tools
 
SplunkLive! Munich 2018: Data Onboarding Overview
SplunkLive! Munich 2018: Data Onboarding OverviewSplunkLive! Munich 2018: Data Onboarding Overview
SplunkLive! Munich 2018: Data Onboarding Overview
 
A Deep Dive into Structured Streaming in Apache Spark
A Deep Dive into Structured Streaming in Apache Spark A Deep Dive into Structured Streaming in Apache Spark
A Deep Dive into Structured Streaming in Apache Spark
 
Machine Data Is EVERYWHERE: Use It for Testing
Machine Data Is EVERYWHERE: Use It for TestingMachine Data Is EVERYWHERE: Use It for Testing
Machine Data Is EVERYWHERE: Use It for Testing
 
SplunkLive! Frankfurt 2018 - Data Onboarding Overview
SplunkLive! Frankfurt 2018 - Data Onboarding OverviewSplunkLive! Frankfurt 2018 - Data Onboarding Overview
SplunkLive! Frankfurt 2018 - Data Onboarding Overview
 
Html5 Overview
Html5 OverviewHtml5 Overview
Html5 Overview
 
Jayson lorenzen iptc_rnews_overview
Jayson lorenzen iptc_rnews_overviewJayson lorenzen iptc_rnews_overview
Jayson lorenzen iptc_rnews_overview
 
What is going on - Application diagnostics on Azure - TechDays Finland
What is going on - Application diagnostics on Azure - TechDays FinlandWhat is going on - Application diagnostics on Azure - TechDays Finland
What is going on - Application diagnostics on Azure - TechDays Finland
 
Beyond the Node: Arkestration with Noah
Beyond the Node: Arkestration with NoahBeyond the Node: Arkestration with Noah
Beyond the Node: Arkestration with Noah
 
A Deep Dive into Structured Streaming: Apache Spark Meetup at Bloomberg 2016
A Deep Dive into Structured Streaming:  Apache Spark Meetup at Bloomberg 2016 A Deep Dive into Structured Streaming:  Apache Spark Meetup at Bloomberg 2016
A Deep Dive into Structured Streaming: Apache Spark Meetup at Bloomberg 2016
 
Presentation wpf
Presentation wpfPresentation wpf
Presentation wpf
 
Mashup Y! widget
Mashup Y! widgetMashup Y! widget
Mashup Y! widget
 
Continuous Application with Structured Streaming 2.0
Continuous Application with Structured Streaming 2.0Continuous Application with Structured Streaming 2.0
Continuous Application with Structured Streaming 2.0
 
Odp
OdpOdp
Odp
 
SplunkLive! Munich 2018: Getting Started with Splunk Enterprise
SplunkLive! Munich 2018: Getting Started with Splunk EnterpriseSplunkLive! Munich 2018: Getting Started with Splunk Enterprise
SplunkLive! Munich 2018: Getting Started with Splunk Enterprise
 

Kürzlich hochgeladen

Future Visions: Predictions to Guide and Time Tech Innovation, Peter Udo Diehl
Future Visions: Predictions to Guide and Time Tech Innovation, Peter Udo DiehlFuture Visions: Predictions to Guide and Time Tech Innovation, Peter Udo Diehl
Future Visions: Predictions to Guide and Time Tech Innovation, Peter Udo Diehl
Peter Udo Diehl
 

Kürzlich hochgeladen (20)

A Business-Centric Approach to Design System Strategy
A Business-Centric Approach to Design System StrategyA Business-Centric Approach to Design System Strategy
A Business-Centric Approach to Design System Strategy
 
What's New in Teams Calling, Meetings and Devices April 2024
What's New in Teams Calling, Meetings and Devices April 2024What's New in Teams Calling, Meetings and Devices April 2024
What's New in Teams Calling, Meetings and Devices April 2024
 
Behind the Scenes From the Manager's Chair: Decoding the Secrets of Successfu...
Behind the Scenes From the Manager's Chair: Decoding the Secrets of Successfu...Behind the Scenes From the Manager's Chair: Decoding the Secrets of Successfu...
Behind the Scenes From the Manager's Chair: Decoding the Secrets of Successfu...
 
Free and Effective: Making Flows Publicly Accessible, Yumi Ibrahimzade
Free and Effective: Making Flows Publicly Accessible, Yumi IbrahimzadeFree and Effective: Making Flows Publicly Accessible, Yumi Ibrahimzade
Free and Effective: Making Flows Publicly Accessible, Yumi Ibrahimzade
 
Introduction to FDO and How It works Applications _ Richard at FIDO Alliance.pdf
Introduction to FDO and How It works Applications _ Richard at FIDO Alliance.pdfIntroduction to FDO and How It works Applications _ Richard at FIDO Alliance.pdf
Introduction to FDO and How It works Applications _ Richard at FIDO Alliance.pdf
 
Google I/O Extended 2024 Warsaw
Google I/O Extended 2024 WarsawGoogle I/O Extended 2024 Warsaw
Google I/O Extended 2024 Warsaw
 
1111 ChatGPT Prompts PDF Free Download - Prompts for ChatGPT
1111 ChatGPT Prompts PDF Free Download - Prompts for ChatGPT1111 ChatGPT Prompts PDF Free Download - Prompts for ChatGPT
1111 ChatGPT Prompts PDF Free Download - Prompts for ChatGPT
 
Microsoft CSP Briefing Pre-Engagement - Questionnaire
Microsoft CSP Briefing Pre-Engagement - QuestionnaireMicrosoft CSP Briefing Pre-Engagement - Questionnaire
Microsoft CSP Briefing Pre-Engagement - Questionnaire
 
WSO2CONMay2024OpenSourceConferenceDebrief.pptx
WSO2CONMay2024OpenSourceConferenceDebrief.pptxWSO2CONMay2024OpenSourceConferenceDebrief.pptx
WSO2CONMay2024OpenSourceConferenceDebrief.pptx
 
AI presentation and introduction - Retrieval Augmented Generation RAG 101
AI presentation and introduction - Retrieval Augmented Generation RAG 101AI presentation and introduction - Retrieval Augmented Generation RAG 101
AI presentation and introduction - Retrieval Augmented Generation RAG 101
 
Future Visions: Predictions to Guide and Time Tech Innovation, Peter Udo Diehl
Future Visions: Predictions to Guide and Time Tech Innovation, Peter Udo DiehlFuture Visions: Predictions to Guide and Time Tech Innovation, Peter Udo Diehl
Future Visions: Predictions to Guide and Time Tech Innovation, Peter Udo Diehl
 
FDO for Camera, Sensor and Networking Device – Commercial Solutions from VinC...
FDO for Camera, Sensor and Networking Device – Commercial Solutions from VinC...FDO for Camera, Sensor and Networking Device – Commercial Solutions from VinC...
FDO for Camera, Sensor and Networking Device – Commercial Solutions from VinC...
 
AI revolution and Salesforce, Jiří Karpíšek
AI revolution and Salesforce, Jiří KarpíšekAI revolution and Salesforce, Jiří Karpíšek
AI revolution and Salesforce, Jiří Karpíšek
 
Oauth 2.0 Introduction and Flows with MuleSoft
Oauth 2.0 Introduction and Flows with MuleSoftOauth 2.0 Introduction and Flows with MuleSoft
Oauth 2.0 Introduction and Flows with MuleSoft
 
The Metaverse: Are We There Yet?
The  Metaverse:    Are   We  There  Yet?The  Metaverse:    Are   We  There  Yet?
The Metaverse: Are We There Yet?
 
Secure Zero Touch enabled Edge compute with Dell NativeEdge via FDO _ Brad at...
Secure Zero Touch enabled Edge compute with Dell NativeEdge via FDO _ Brad at...Secure Zero Touch enabled Edge compute with Dell NativeEdge via FDO _ Brad at...
Secure Zero Touch enabled Edge compute with Dell NativeEdge via FDO _ Brad at...
 
How we scaled to 80K users by doing nothing!.pdf
How we scaled to 80K users by doing nothing!.pdfHow we scaled to 80K users by doing nothing!.pdf
How we scaled to 80K users by doing nothing!.pdf
 
Choosing the Right FDO Deployment Model for Your Application _ Geoffrey at In...
Choosing the Right FDO Deployment Model for Your Application _ Geoffrey at In...Choosing the Right FDO Deployment Model for Your Application _ Geoffrey at In...
Choosing the Right FDO Deployment Model for Your Application _ Geoffrey at In...
 
ASRock Industrial FDO Solutions in Action for Industrial Edge AI _ Kenny at A...
ASRock Industrial FDO Solutions in Action for Industrial Edge AI _ Kenny at A...ASRock Industrial FDO Solutions in Action for Industrial Edge AI _ Kenny at A...
ASRock Industrial FDO Solutions in Action for Industrial Edge AI _ Kenny at A...
 
Linux Foundation Edge _ Overview of FDO Software Components _ Randy at Intel.pdf
Linux Foundation Edge _ Overview of FDO Software Components _ Randy at Intel.pdfLinux Foundation Edge _ Overview of FDO Software Components _ Randy at Intel.pdf
Linux Foundation Edge _ Overview of FDO Software Components _ Randy at Intel.pdf
 

.conf2011: Web Analytics Throwdown: with NPR and Intuit

  • 1. .conf 2011 Keynote Outline August 15, 2011 Web Analytics Throwdown with NPR and Intuit Sondra Russell and Tim Suh
  • 3.
  • 4. Audio and Video Tracking: The Basic Setup MP3 Downloads On Demand Flash Live Streams ProgramID (?P<ProgramID>[^]*)(?=) UserAgent (?P<UserAgent>[^amp;quot;]*)(?=amp;quot; ) AppVersion “ *(? =) ” Ingest Raw Data Extract Fields Define Transactions > sourcetype = download AND status < 300 AND Method=Get | transaction IPAddress UserAgent maxspan=120… Create Summary Indexes 08/08/2011=>31800 08/09/2011=>29655 08/10/2011=>29903 08/11/2011=>53443 08/12/2011=>32593 08/13/2011=>88654 08/14/2011=>11231 1 2 3 4
  • 5. > index=“summary” search_name=“ si_download_programID ” ProgramName= “ All Songs Considered ” “ How has my podcast been doing?” pulls from the summary index maps ProgramID to lookup table
  • 6. > * | eval Platform = mvfilter(match(eventtype,&quot;plat*&quot;)) | timechart span=1w count by Platform “ What platforms are people using to access our show?” Filters for eventtypes that include “plat” plat_iphone_browser UserAgent=&quot;*iPhone*&quot; AND UserAgent!=&quot;*NPRRadio*&quot; AND UserAgent!=&quot;*iPod*“ AND sc!=18
  • 7. > * | rex field=_raw &quot;Darwin(?<Version>[0-9]*)amp;quot;“ | top Version “ What percentage of our users have upgraded?” Uses regex to extract element from raw log &quot;NPRMusic/2.7 CFNetwork/459 Darwin/10.0.0d3&quot;
  • 8. > index=“twitter” | stats count by story_url “ Which stories are getting Tweeted the most?” timestamp =&quot;2011-07-18T15:40:34Z&quot;, author =&quot;drpdtapp (Dr. P. D Tapp)&quot;, tweet =&quot;Tinnitus: Why Won't My Ears Stop Ringing?”, story_url =&quot;http://www.npr.org/2011/07/18/138163304/tinnitus-why-wont-my-ears-stop-ringing?sc=tw&quot;, Creates reports from a custom log
  • 9. .conf 2011 Keynote Outline August 15, 2011 Questions? Sondra Russell and Tim Suh