SlideShare uma empresa Scribd logo
1 de 14
Baixar para ler offline
New	
  York	
  City	
  
October	
  27,	
  2011	
  
Chris	
  DeMeo	
  
                                             Sr.	
  Director	
  Technology	
  
New	
  York,	
  October	
  27,	
  2011	
     Architecture	
           Copyright	
  ©	
  2011,	
  Splunk	
  Inc.	
  
About	
  Me	
  

!   One	
  of	
  the	
  founders	
  of	
  
    DealerTrack	
  
!   With	
  the	
  company	
  since	
  
    incepJon	
  
!   Technology	
  Architecture	
  Lead	
  
    -­‐	
  Infrastructure	
  


           New	
  York,	
  October	
  27,	
  2011	
           3	
         Copyright	
  ©	
  2011,	
  Splunk	
  Inc.	
  
About	
  DealerTrack	
  
!   Leading	
  provider	
  of	
  on-­‐demand	
  soOware	
  and	
  
    services	
  for	
  the	
  automoJve	
  retail	
  industry	
  
!   Industry’s	
  First	
  and	
  Largest	
  Credit	
  ApplicaJon	
  
    Network	
  
!   ConnecJng	
  approximately	
  17,000	
  dealers	
  
    with	
  more	
  than	
  1,000	
  lenders	
  
!   Dealer	
  Management	
  SoluJons,	
  Inventory	
  
    SoluJons,	
  Sales	
  SoluJons	
  and	
  Processing	
  
    SoluJons	
  
	
               New	
  York,	
  October	
  27,	
  2011	
     4	
       Copyright	
  ©	
  2011,	
  Splunk	
  Inc.	
  
The	
  Challenge	
  
•  Web	
  logs,	
  proprietary	
  logs,	
  database	
  logs,	
  operaJng	
  system	
  logs	
  –	
  
   No	
  way	
  to	
  look	
  through	
  them	
  easily,	
  it	
  took	
  hours	
  
•  Over	
  Jme,	
  acquired	
  several	
  companies	
  resulJng	
  in	
  more	
  
   dependencies	
  and	
  the	
  need	
  to	
  consolidate	
  logs	
  across	
  geo's	
  and	
  
   datacenters	
  	
  
•  In	
  POC	
  there	
  was	
  doubt	
  about	
  the	
  value	
  of	
  the	
  tool.	
  How	
  many	
  
   hours	
  would	
  it	
  take	
  to	
  get	
  up	
  and	
  running?	
  How	
  quickly	
  before	
  we	
  
   see	
  value?	
  

                              "We	
  needed	
  a	
  tool	
  that	
  could	
  correlate	
  all	
  logs."	
  

                New	
  York,	
  October	
  27,	
  2011	
           5	
                                        Copyright	
  ©	
  2011,	
  Splunk	
  Inc.	
  
The	
  First	
  of	
  Many	
  Aha	
  Moments	
  
•    Oracle	
  RAC	
  database	
  cluster	
  failover	
  -­‐	
  root	
  cause	
  analysis	
  
•    E-­‐contracJng	
  transacJon	
  -­‐	
  correlaJon	
  of	
  customer	
  
     impacJng	
  bug	
  using	
  3	
  correlated	
  log	
  types	
  
•    Database	
  connecJons	
  –	
  custom	
  input	
  allowed	
  trending	
  in	
  
     new	
  ways	
  
•    With	
  Splunk	
  ability	
  to	
  quickly	
  get	
  to	
  root	
  cause	
  (assuming	
  
     you	
  logged	
  something!)	
  
•    Different	
  from	
  anything	
  we	
  used	
  before	
  
•    Ability	
  to	
  show	
  a	
  developer	
  the	
  anatomy	
  of	
  a	
  problem	
  –	
  
     transacJon	
  tracing	
  

                   New	
  York,	
  October	
  27,	
  2011	
     6	
                              Copyright	
  ©	
  2011,	
  Splunk	
  Inc.	
  
The	
  Second	
  of	
  Many	
  Aha	
  Moments	
  
•  Capacity	
  Planning	
  –	
  now	
  has	
  the	
  ability	
  to	
  easily	
  
   validate	
  transacJon	
  mixes	
  and	
  volumes	
  
•  Capacity	
  Planning	
  –	
  idenJfied	
  “bunching”	
  of	
  
   transacJons	
  during	
  load	
  tests	
  
•  Increased	
  product	
  usage	
  and	
  customer	
  retenJon	
  –	
  
   through	
  idenJficaJon	
  of	
  their	
  legacy	
  product	
  usage	
  	
  
•  Outage	
  Impact	
  –	
  more	
  accurate	
  outage	
  impact	
  
   with	
  access	
  to	
  addiJonal	
  logs	
  


              New	
  York,	
  October	
  27,	
  2011	
     7	
             Copyright	
  ©	
  2011,	
  Splunk	
  Inc.	
  
What	
  Also	
  Helped…..	
  	
  
•    AOer	
  3	
  months	
  execuJves	
  felt	
  Splunk	
  paid	
  for	
  itself	
  

•    Ease	
  of	
  Use	
  
        • Development	
  can	
  build	
  their	
  own	
  dashboards	
  

        • Business	
  folks	
  saw	
  value	
  and	
  asked	
  for	
  informaJon	
  

        • We	
  had	
  Splunk	
  up	
  and	
  running	
  in	
  less	
  than	
  2	
  months	
  
        own	
  dashboards	
  


                  New	
  York,	
  October	
  27,	
  2011	
     8	
                        Copyright	
  ©	
  2011,	
  Splunk	
  Inc.	
  
Vale	
  Add	
  to	
  Lending	
  Partners	
  
•  Real-­‐Jme	
  visibility	
  into	
  credit	
  applicaJon	
  and	
  decision	
  
   volumes	
  across	
  all	
  lenders	
  
•  Report	
  to	
  lenders	
  where	
  they	
  stand	
  against	
  the	
  
   compeJJon—drives	
  more	
  compeJJve	
  response	
  




              New	
  York,	
  October	
  27,	
  2011	
     9	
             Copyright	
  ©	
  2011,	
  Splunk	
  Inc.	
  
Historical	
  Data	
  Search	
  
!   Log	
  view	
  uJlity	
  for	
  our	
  own	
  proprietary	
  logs…	
  
!   Our	
  own	
  tool	
  doesn’t	
  search	
  over	
  more	
  than	
  7	
  days	
  of	
  data	
  
!   Now	
  we	
  can	
  search	
  historical	
  data	
  for	
  trending	
  analysis	
  




                 New	
  York,	
  October	
  27,	
  2011	
     10	
                        Copyright	
  ©	
  2011,	
  Splunk	
  Inc.	
  
Current	
  Environment	
  and	
  Set	
  up	
  
!   Deployed	
  across	
  4	
  applicaJon	
  environments	
  
!   Non-­‐Cloud	
  based	
  -­‐	
  Run	
  our	
  own	
  equipment	
  
!   Each	
  environment	
  has	
  1	
  server	
  (will	
  make	
  into	
  HA	
  
    configuraJon)	
  
!   Everything	
  runs	
  on	
  a	
  single	
  server	
  	
  
!   Virtual	
  machines	
  in	
  non-­‐producJon	
  environments	
  
!   Local	
  storage	
  

              New	
  York,	
  October	
  27,	
  2011	
     11	
            Copyright	
  ©	
  2011,	
  Splunk	
  Inc.	
  
Coming	
  Soon	
  
!     Syslog	
  inputs	
  
!     HA	
  configuraJon	
  with	
  mulJple	
  search	
  heads	
  and	
  SAN	
  storage	
  
!     Looking	
  to	
  install	
  Web	
  AnalyJcs	
  app	
  for	
  business	
  users	
  
!     IntegraJon	
  with	
  other	
  monitoring	
  tools	
  
!     User	
  adopJon-­‐-­‐work	
  on	
  user	
  educaJon-­‐-­‐how	
  they	
  are	
  using	
  it	
  
!     Want	
  to	
  give	
  Security	
  group	
  ability	
  to	
  search	
  across	
  years	
  of	
  data	
  
!     Rollout	
  to	
  subsidiaries	
  so	
  each	
  has	
  their	
  own	
  indexer	
  

     "Finding	
  data	
  in	
  our	
  logs	
  that	
  we	
  never	
  even	
  knew	
  was	
  there	
  and	
  that	
  people	
  are	
  
                                                      ge8ng	
  value	
  from."	
  

                      New	
  York,	
  October	
  27,	
  2011	
         12	
                                    Copyright	
  ©	
  2011,	
  Splunk	
  Inc.	
  
Lessons	
  Learned	
  	
  
!   Before	
  we	
  didn't	
  have	
  the	
  data,	
  now	
  we	
  want	
  to	
  save	
  everything	
  
!   Professional	
  Services	
  and	
  EducaJon	
  –	
  They	
  armed	
  us	
  and	
  made	
  us	
  
    more	
  than	
  dangerous!	
  
!   Developed	
  internal	
  user	
  doc	
  with	
  best	
  pracJces	
  and	
  use	
  cases	
  
!   Knowledge	
  of	
  your	
  logs	
  will	
  help	
  to	
  realize	
  value	
  quickly	
  




                New	
  York,	
  October	
  27,	
  2011	
     13	
                        Copyright	
  ©	
  2011,	
  Splunk	
  Inc.	
  
Thank	
  you	
  



                                             Chris	
  DeMeo	
  
                                             Sr.	
  Director	
  Technology	
  	
  
                                             Architect	
  
New	
  York,	
  October	
  27,	
  2011	
                           Copyright	
  ©	
  2011,	
  Splunk	
  Inc.	
  

Mais conteúdo relacionado

Semelhante a SplunkLive New York 2011: DealerTrack

SplunkLive! Denver - Nov 2012 - Interac
SplunkLive! Denver - Nov 2012 - InteracSplunkLive! Denver - Nov 2012 - Interac
SplunkLive! Denver - Nov 2012 - InteracSplunk
 
Splunk sales presentation
Splunk sales presentationSplunk sales presentation
Splunk sales presentationjpelletier123
 
SplunkLive! Toronto - Ceryx
SplunkLive! Toronto - CeryxSplunkLive! Toronto - Ceryx
SplunkLive! Toronto - CeryxSplunk
 
SplunkLive 2011 Advanced Session
SplunkLive 2011 Advanced SessionSplunkLive 2011 Advanced Session
SplunkLive 2011 Advanced SessionSplunk
 
SplunkGettingStartedWorkshop.pptx
SplunkGettingStartedWorkshop.pptxSplunkGettingStartedWorkshop.pptx
SplunkGettingStartedWorkshop.pptxKhongHieu2
 
SplunkGettingStartedWorkshop.pptx
SplunkGettingStartedWorkshop.pptxSplunkGettingStartedWorkshop.pptx
SplunkGettingStartedWorkshop.pptxCazlp1
 
CMPE 297 Lecture: Building Infrastructure Clouds with OpenStack
CMPE 297 Lecture: Building Infrastructure Clouds with OpenStackCMPE 297 Lecture: Building Infrastructure Clouds with OpenStack
CMPE 297 Lecture: Building Infrastructure Clouds with OpenStackJoe Arnold
 
Infusion for the birds
Infusion for the birdsInfusion for the birds
Infusion for the birdscolinbdclark
 
Monitoring is easy, why are we so bad at it presentation
Monitoring is easy, why are we so bad at it  presentationMonitoring is easy, why are we so bad at it  presentation
Monitoring is easy, why are we so bad at it presentationTheo Schlossnagle
 
Splunk in 60 Minutes | Splunk Tutorial For Beginners | Splunk Training | Splu...
Splunk in 60 Minutes | Splunk Tutorial For Beginners | Splunk Training | Splu...Splunk in 60 Minutes | Splunk Tutorial For Beginners | Splunk Training | Splu...
Splunk in 60 Minutes | Splunk Tutorial For Beginners | Splunk Training | Splu...Edureka!
 
SplunkLive! Philadelphia - University of Scranton
SplunkLive! Philadelphia - University of ScrantonSplunkLive! Philadelphia - University of Scranton
SplunkLive! Philadelphia - University of ScrantonSplunk
 
SplunkLive Miami Carnival Cruiselines - John Masseria
SplunkLive Miami   Carnival Cruiselines - John MasseriaSplunkLive Miami   Carnival Cruiselines - John Masseria
SplunkLive Miami Carnival Cruiselines - John MasseriaSplunk
 
A Yarn About Twine -- ISWC 2009 Keynote -- Nova Spivack
A Yarn About Twine -- ISWC 2009 Keynote --   Nova SpivackA Yarn About Twine -- ISWC 2009 Keynote --   Nova Spivack
A Yarn About Twine -- ISWC 2009 Keynote -- Nova SpivackNova Spivack
 
ScrumDay 2014 - Développer des produits avec des équipes distribuées - Alexis...
ScrumDay 2014 - Développer des produits avec des équipes distribuées - Alexis...ScrumDay 2014 - Développer des produits avec des équipes distribuées - Alexis...
ScrumDay 2014 - Développer des produits avec des équipes distribuées - Alexis...Alexis Monville
 
Taxonomies for Publishing
Taxonomies for PublishingTaxonomies for Publishing
Taxonomies for PublishingTSoholt
 
Digital Asset Management with Alfresco
Digital Asset Management with AlfrescoDigital Asset Management with Alfresco
Digital Asset Management with Alfrescorivetlogic
 
Splunk .conf18 Updates, Config Add-on, SplDevOps
Splunk .conf18 Updates, Config Add-on, SplDevOpsSplunk .conf18 Updates, Config Add-on, SplDevOps
Splunk .conf18 Updates, Config Add-on, SplDevOpsHarry McLaren
 
Agile software-requirements-agile-denver-pptx
Agile software-requirements-agile-denver-pptxAgile software-requirements-agile-denver-pptx
Agile software-requirements-agile-denver-pptxRobert Ximenes
 
SEI Webinar Series: Making Agile Work for You
SEI Webinar Series: Making Agile Work for YouSEI Webinar Series: Making Agile Work for You
SEI Webinar Series: Making Agile Work for YouLa Red DBAccess
 

Semelhante a SplunkLive New York 2011: DealerTrack (20)

SplunkLive! Denver - Nov 2012 - Interac
SplunkLive! Denver - Nov 2012 - InteracSplunkLive! Denver - Nov 2012 - Interac
SplunkLive! Denver - Nov 2012 - Interac
 
Splunk sales presentation
Splunk sales presentationSplunk sales presentation
Splunk sales presentation
 
SplunkLive! Toronto - Ceryx
SplunkLive! Toronto - CeryxSplunkLive! Toronto - Ceryx
SplunkLive! Toronto - Ceryx
 
SplunkLive 2011 Advanced Session
SplunkLive 2011 Advanced SessionSplunkLive 2011 Advanced Session
SplunkLive 2011 Advanced Session
 
SplunkGettingStartedWorkshop.pptx
SplunkGettingStartedWorkshop.pptxSplunkGettingStartedWorkshop.pptx
SplunkGettingStartedWorkshop.pptx
 
SplunkGettingStartedWorkshop.pptx
SplunkGettingStartedWorkshop.pptxSplunkGettingStartedWorkshop.pptx
SplunkGettingStartedWorkshop.pptx
 
CMPE 297 Lecture: Building Infrastructure Clouds with OpenStack
CMPE 297 Lecture: Building Infrastructure Clouds with OpenStackCMPE 297 Lecture: Building Infrastructure Clouds with OpenStack
CMPE 297 Lecture: Building Infrastructure Clouds with OpenStack
 
Infusion for the birds
Infusion for the birdsInfusion for the birds
Infusion for the birds
 
Monitoring is easy, why are we so bad at it presentation
Monitoring is easy, why are we so bad at it  presentationMonitoring is easy, why are we so bad at it  presentation
Monitoring is easy, why are we so bad at it presentation
 
Splunk in 60 Minutes | Splunk Tutorial For Beginners | Splunk Training | Splu...
Splunk in 60 Minutes | Splunk Tutorial For Beginners | Splunk Training | Splu...Splunk in 60 Minutes | Splunk Tutorial For Beginners | Splunk Training | Splu...
Splunk in 60 Minutes | Splunk Tutorial For Beginners | Splunk Training | Splu...
 
SplunkLive! Philadelphia - University of Scranton
SplunkLive! Philadelphia - University of ScrantonSplunkLive! Philadelphia - University of Scranton
SplunkLive! Philadelphia - University of Scranton
 
SplunkLive Miami Carnival Cruiselines - John Masseria
SplunkLive Miami   Carnival Cruiselines - John MasseriaSplunkLive Miami   Carnival Cruiselines - John Masseria
SplunkLive Miami Carnival Cruiselines - John Masseria
 
A Yarn About Twine -- ISWC 2009 Keynote -- Nova Spivack
A Yarn About Twine -- ISWC 2009 Keynote --   Nova SpivackA Yarn About Twine -- ISWC 2009 Keynote --   Nova Spivack
A Yarn About Twine -- ISWC 2009 Keynote -- Nova Spivack
 
ScrumDay 2014 - Développer des produits avec des équipes distribuées - Alexis...
ScrumDay 2014 - Développer des produits avec des équipes distribuées - Alexis...ScrumDay 2014 - Développer des produits avec des équipes distribuées - Alexis...
ScrumDay 2014 - Développer des produits avec des équipes distribuées - Alexis...
 
Taxonomies for Publishing
Taxonomies for PublishingTaxonomies for Publishing
Taxonomies for Publishing
 
DevOps and Splunk
DevOps and SplunkDevOps and Splunk
DevOps and Splunk
 
Digital Asset Management with Alfresco
Digital Asset Management with AlfrescoDigital Asset Management with Alfresco
Digital Asset Management with Alfresco
 
Splunk .conf18 Updates, Config Add-on, SplDevOps
Splunk .conf18 Updates, Config Add-on, SplDevOpsSplunk .conf18 Updates, Config Add-on, SplDevOps
Splunk .conf18 Updates, Config Add-on, SplDevOps
 
Agile software-requirements-agile-denver-pptx
Agile software-requirements-agile-denver-pptxAgile software-requirements-agile-denver-pptx
Agile software-requirements-agile-denver-pptx
 
SEI Webinar Series: Making Agile Work for You
SEI Webinar Series: Making Agile Work for YouSEI Webinar Series: Making Agile Work for You
SEI Webinar Series: Making Agile Work for You
 

Mais de Splunk

.conf Go 2023 - Data analysis as a routine
.conf Go 2023 - Data analysis as a routine.conf Go 2023 - Data analysis as a routine
.conf Go 2023 - Data analysis as a routineSplunk
 
.conf Go 2023 - How KPN drives Customer Satisfaction on IPTV
.conf Go 2023 - How KPN drives Customer Satisfaction on IPTV.conf Go 2023 - How KPN drives Customer Satisfaction on IPTV
.conf Go 2023 - How KPN drives Customer Satisfaction on IPTVSplunk
 
.conf Go 2023 - Navegando la normativa SOX (Telefónica)
.conf Go 2023 - Navegando la normativa SOX (Telefónica).conf Go 2023 - Navegando la normativa SOX (Telefónica)
.conf Go 2023 - Navegando la normativa SOX (Telefónica)Splunk
 
.conf Go 2023 - Raiffeisen Bank International
.conf Go 2023 - Raiffeisen Bank International.conf Go 2023 - Raiffeisen Bank International
.conf Go 2023 - Raiffeisen Bank InternationalSplunk
 
.conf Go 2023 - På liv og død Om sikkerhetsarbeid i Norsk helsenett
.conf Go 2023 - På liv og død Om sikkerhetsarbeid i Norsk helsenett .conf Go 2023 - På liv og død Om sikkerhetsarbeid i Norsk helsenett
.conf Go 2023 - På liv og død Om sikkerhetsarbeid i Norsk helsenett Splunk
 
.conf Go 2023 - Many roads lead to Rome - this was our journey (Julius Bär)
.conf Go 2023 - Many roads lead to Rome - this was our journey (Julius Bär).conf Go 2023 - Many roads lead to Rome - this was our journey (Julius Bär)
.conf Go 2023 - Many roads lead to Rome - this was our journey (Julius Bär)Splunk
 
.conf Go 2023 - Das passende Rezept für die digitale (Security) Revolution zu...
.conf Go 2023 - Das passende Rezept für die digitale (Security) Revolution zu....conf Go 2023 - Das passende Rezept für die digitale (Security) Revolution zu...
.conf Go 2023 - Das passende Rezept für die digitale (Security) Revolution zu...Splunk
 
.conf go 2023 - Cyber Resilienz – Herausforderungen und Ansatz für Energiever...
.conf go 2023 - Cyber Resilienz – Herausforderungen und Ansatz für Energiever....conf go 2023 - Cyber Resilienz – Herausforderungen und Ansatz für Energiever...
.conf go 2023 - Cyber Resilienz – Herausforderungen und Ansatz für Energiever...Splunk
 
.conf go 2023 - De NOC a CSIRT (Cellnex)
.conf go 2023 - De NOC a CSIRT (Cellnex).conf go 2023 - De NOC a CSIRT (Cellnex)
.conf go 2023 - De NOC a CSIRT (Cellnex)Splunk
 
conf go 2023 - El camino hacia la ciberseguridad (ABANCA)
conf go 2023 - El camino hacia la ciberseguridad (ABANCA)conf go 2023 - El camino hacia la ciberseguridad (ABANCA)
conf go 2023 - El camino hacia la ciberseguridad (ABANCA)Splunk
 
Splunk - BMW connects business and IT with data driven operations SRE and O11y
Splunk - BMW connects business and IT with data driven operations SRE and O11ySplunk - BMW connects business and IT with data driven operations SRE and O11y
Splunk - BMW connects business and IT with data driven operations SRE and O11ySplunk
 
Splunk x Freenet - .conf Go Köln
Splunk x Freenet - .conf Go KölnSplunk x Freenet - .conf Go Köln
Splunk x Freenet - .conf Go KölnSplunk
 
Splunk Security Session - .conf Go Köln
Splunk Security Session - .conf Go KölnSplunk Security Session - .conf Go Köln
Splunk Security Session - .conf Go KölnSplunk
 
Data foundations building success, at city scale – Imperial College London
 Data foundations building success, at city scale – Imperial College London Data foundations building success, at city scale – Imperial College London
Data foundations building success, at city scale – Imperial College LondonSplunk
 
Splunk: How Vodafone established Operational Analytics in a Hybrid Environmen...
Splunk: How Vodafone established Operational Analytics in a Hybrid Environmen...Splunk: How Vodafone established Operational Analytics in a Hybrid Environmen...
Splunk: How Vodafone established Operational Analytics in a Hybrid Environmen...Splunk
 
SOC, Amore Mio! | Security Webinar
SOC, Amore Mio! | Security WebinarSOC, Amore Mio! | Security Webinar
SOC, Amore Mio! | Security WebinarSplunk
 
.conf Go 2022 - Observability Session
.conf Go 2022 - Observability Session.conf Go 2022 - Observability Session
.conf Go 2022 - Observability SessionSplunk
 
.conf Go Zurich 2022 - Keynote
.conf Go Zurich 2022 - Keynote.conf Go Zurich 2022 - Keynote
.conf Go Zurich 2022 - KeynoteSplunk
 
.conf Go Zurich 2022 - Platform Session
.conf Go Zurich 2022 - Platform Session.conf Go Zurich 2022 - Platform Session
.conf Go Zurich 2022 - Platform SessionSplunk
 
.conf Go Zurich 2022 - Security Session
.conf Go Zurich 2022 - Security Session.conf Go Zurich 2022 - Security Session
.conf Go Zurich 2022 - Security SessionSplunk
 

Mais de Splunk (20)

.conf Go 2023 - Data analysis as a routine
.conf Go 2023 - Data analysis as a routine.conf Go 2023 - Data analysis as a routine
.conf Go 2023 - Data analysis as a routine
 
.conf Go 2023 - How KPN drives Customer Satisfaction on IPTV
.conf Go 2023 - How KPN drives Customer Satisfaction on IPTV.conf Go 2023 - How KPN drives Customer Satisfaction on IPTV
.conf Go 2023 - How KPN drives Customer Satisfaction on IPTV
 
.conf Go 2023 - Navegando la normativa SOX (Telefónica)
.conf Go 2023 - Navegando la normativa SOX (Telefónica).conf Go 2023 - Navegando la normativa SOX (Telefónica)
.conf Go 2023 - Navegando la normativa SOX (Telefónica)
 
.conf Go 2023 - Raiffeisen Bank International
.conf Go 2023 - Raiffeisen Bank International.conf Go 2023 - Raiffeisen Bank International
.conf Go 2023 - Raiffeisen Bank International
 
.conf Go 2023 - På liv og død Om sikkerhetsarbeid i Norsk helsenett
.conf Go 2023 - På liv og død Om sikkerhetsarbeid i Norsk helsenett .conf Go 2023 - På liv og død Om sikkerhetsarbeid i Norsk helsenett
.conf Go 2023 - På liv og død Om sikkerhetsarbeid i Norsk helsenett
 
.conf Go 2023 - Many roads lead to Rome - this was our journey (Julius Bär)
.conf Go 2023 - Many roads lead to Rome - this was our journey (Julius Bär).conf Go 2023 - Many roads lead to Rome - this was our journey (Julius Bär)
.conf Go 2023 - Many roads lead to Rome - this was our journey (Julius Bär)
 
.conf Go 2023 - Das passende Rezept für die digitale (Security) Revolution zu...
.conf Go 2023 - Das passende Rezept für die digitale (Security) Revolution zu....conf Go 2023 - Das passende Rezept für die digitale (Security) Revolution zu...
.conf Go 2023 - Das passende Rezept für die digitale (Security) Revolution zu...
 
.conf go 2023 - Cyber Resilienz – Herausforderungen und Ansatz für Energiever...
.conf go 2023 - Cyber Resilienz – Herausforderungen und Ansatz für Energiever....conf go 2023 - Cyber Resilienz – Herausforderungen und Ansatz für Energiever...
.conf go 2023 - Cyber Resilienz – Herausforderungen und Ansatz für Energiever...
 
.conf go 2023 - De NOC a CSIRT (Cellnex)
.conf go 2023 - De NOC a CSIRT (Cellnex).conf go 2023 - De NOC a CSIRT (Cellnex)
.conf go 2023 - De NOC a CSIRT (Cellnex)
 
conf go 2023 - El camino hacia la ciberseguridad (ABANCA)
conf go 2023 - El camino hacia la ciberseguridad (ABANCA)conf go 2023 - El camino hacia la ciberseguridad (ABANCA)
conf go 2023 - El camino hacia la ciberseguridad (ABANCA)
 
Splunk - BMW connects business and IT with data driven operations SRE and O11y
Splunk - BMW connects business and IT with data driven operations SRE and O11ySplunk - BMW connects business and IT with data driven operations SRE and O11y
Splunk - BMW connects business and IT with data driven operations SRE and O11y
 
Splunk x Freenet - .conf Go Köln
Splunk x Freenet - .conf Go KölnSplunk x Freenet - .conf Go Köln
Splunk x Freenet - .conf Go Köln
 
Splunk Security Session - .conf Go Köln
Splunk Security Session - .conf Go KölnSplunk Security Session - .conf Go Köln
Splunk Security Session - .conf Go Köln
 
Data foundations building success, at city scale – Imperial College London
 Data foundations building success, at city scale – Imperial College London Data foundations building success, at city scale – Imperial College London
Data foundations building success, at city scale – Imperial College London
 
Splunk: How Vodafone established Operational Analytics in a Hybrid Environmen...
Splunk: How Vodafone established Operational Analytics in a Hybrid Environmen...Splunk: How Vodafone established Operational Analytics in a Hybrid Environmen...
Splunk: How Vodafone established Operational Analytics in a Hybrid Environmen...
 
SOC, Amore Mio! | Security Webinar
SOC, Amore Mio! | Security WebinarSOC, Amore Mio! | Security Webinar
SOC, Amore Mio! | Security Webinar
 
.conf Go 2022 - Observability Session
.conf Go 2022 - Observability Session.conf Go 2022 - Observability Session
.conf Go 2022 - Observability Session
 
.conf Go Zurich 2022 - Keynote
.conf Go Zurich 2022 - Keynote.conf Go Zurich 2022 - Keynote
.conf Go Zurich 2022 - Keynote
 
.conf Go Zurich 2022 - Platform Session
.conf Go Zurich 2022 - Platform Session.conf Go Zurich 2022 - Platform Session
.conf Go Zurich 2022 - Platform Session
 
.conf Go Zurich 2022 - Security Session
.conf Go Zurich 2022 - Security Session.conf Go Zurich 2022 - Security Session
.conf Go Zurich 2022 - Security Session
 

Último

Unraveling Multimodality with Large Language Models.pdf
Unraveling Multimodality with Large Language Models.pdfUnraveling Multimodality with Large Language Models.pdf
Unraveling Multimodality with Large Language Models.pdfAlex Barbosa Coqueiro
 
Transcript: New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024Transcript: New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024BookNet Canada
 
From Family Reminiscence to Scholarly Archive .
From Family Reminiscence to Scholarly Archive .From Family Reminiscence to Scholarly Archive .
From Family Reminiscence to Scholarly Archive .Alan Dix
 
The State of Passkeys with FIDO Alliance.pptx
The State of Passkeys with FIDO Alliance.pptxThe State of Passkeys with FIDO Alliance.pptx
The State of Passkeys with FIDO Alliance.pptxLoriGlavin3
 
Gen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdfGen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdfAddepto
 
New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024BookNet Canada
 
SIP trunking in Janus @ Kamailio World 2024
SIP trunking in Janus @ Kamailio World 2024SIP trunking in Janus @ Kamailio World 2024
SIP trunking in Janus @ Kamailio World 2024Lorenzo Miniero
 
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)Mark Simos
 
The Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptx
The Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptxThe Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptx
The Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptxLoriGlavin3
 
What's New in Teams Calling, Meetings and Devices March 2024
What's New in Teams Calling, Meetings and Devices March 2024What's New in Teams Calling, Meetings and Devices March 2024
What's New in Teams Calling, Meetings and Devices March 2024Stephanie Beckett
 
Anypoint Exchange: It’s Not Just a Repo!
Anypoint Exchange: It’s Not Just a Repo!Anypoint Exchange: It’s Not Just a Repo!
Anypoint Exchange: It’s Not Just a Repo!Manik S Magar
 
TeamStation AI System Report LATAM IT Salaries 2024
TeamStation AI System Report LATAM IT Salaries 2024TeamStation AI System Report LATAM IT Salaries 2024
TeamStation AI System Report LATAM IT Salaries 2024Lonnie McRorey
 
What is Artificial Intelligence?????????
What is Artificial Intelligence?????????What is Artificial Intelligence?????????
What is Artificial Intelligence?????????blackmambaettijean
 
DSPy a system for AI to Write Prompts and Do Fine Tuning
DSPy a system for AI to Write Prompts and Do Fine TuningDSPy a system for AI to Write Prompts and Do Fine Tuning
DSPy a system for AI to Write Prompts and Do Fine TuningLars Bell
 
Moving Beyond Passwords: FIDO Paris Seminar.pdf
Moving Beyond Passwords: FIDO Paris Seminar.pdfMoving Beyond Passwords: FIDO Paris Seminar.pdf
Moving Beyond Passwords: FIDO Paris Seminar.pdfLoriGlavin3
 
"ML in Production",Oleksandr Bagan
"ML in Production",Oleksandr Bagan"ML in Production",Oleksandr Bagan
"ML in Production",Oleksandr BaganFwdays
 
The Role of FIDO in a Cyber Secure Netherlands: FIDO Paris Seminar.pptx
The Role of FIDO in a Cyber Secure Netherlands: FIDO Paris Seminar.pptxThe Role of FIDO in a Cyber Secure Netherlands: FIDO Paris Seminar.pptx
The Role of FIDO in a Cyber Secure Netherlands: FIDO Paris Seminar.pptxLoriGlavin3
 
What is DBT - The Ultimate Data Build Tool.pdf
What is DBT - The Ultimate Data Build Tool.pdfWhat is DBT - The Ultimate Data Build Tool.pdf
What is DBT - The Ultimate Data Build Tool.pdfMounikaPolabathina
 
Use of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptx
Use of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptxUse of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptx
Use of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptxLoriGlavin3
 
Ensuring Technical Readiness For Copilot in Microsoft 365
Ensuring Technical Readiness For Copilot in Microsoft 365Ensuring Technical Readiness For Copilot in Microsoft 365
Ensuring Technical Readiness For Copilot in Microsoft 3652toLead Limited
 

Último (20)

Unraveling Multimodality with Large Language Models.pdf
Unraveling Multimodality with Large Language Models.pdfUnraveling Multimodality with Large Language Models.pdf
Unraveling Multimodality with Large Language Models.pdf
 
Transcript: New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024Transcript: New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
 
From Family Reminiscence to Scholarly Archive .
From Family Reminiscence to Scholarly Archive .From Family Reminiscence to Scholarly Archive .
From Family Reminiscence to Scholarly Archive .
 
The State of Passkeys with FIDO Alliance.pptx
The State of Passkeys with FIDO Alliance.pptxThe State of Passkeys with FIDO Alliance.pptx
The State of Passkeys with FIDO Alliance.pptx
 
Gen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdfGen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdf
 
New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
 
SIP trunking in Janus @ Kamailio World 2024
SIP trunking in Janus @ Kamailio World 2024SIP trunking in Janus @ Kamailio World 2024
SIP trunking in Janus @ Kamailio World 2024
 
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
 
The Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptx
The Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptxThe Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptx
The Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptx
 
What's New in Teams Calling, Meetings and Devices March 2024
What's New in Teams Calling, Meetings and Devices March 2024What's New in Teams Calling, Meetings and Devices March 2024
What's New in Teams Calling, Meetings and Devices March 2024
 
Anypoint Exchange: It’s Not Just a Repo!
Anypoint Exchange: It’s Not Just a Repo!Anypoint Exchange: It’s Not Just a Repo!
Anypoint Exchange: It’s Not Just a Repo!
 
TeamStation AI System Report LATAM IT Salaries 2024
TeamStation AI System Report LATAM IT Salaries 2024TeamStation AI System Report LATAM IT Salaries 2024
TeamStation AI System Report LATAM IT Salaries 2024
 
What is Artificial Intelligence?????????
What is Artificial Intelligence?????????What is Artificial Intelligence?????????
What is Artificial Intelligence?????????
 
DSPy a system for AI to Write Prompts and Do Fine Tuning
DSPy a system for AI to Write Prompts and Do Fine TuningDSPy a system for AI to Write Prompts and Do Fine Tuning
DSPy a system for AI to Write Prompts and Do Fine Tuning
 
Moving Beyond Passwords: FIDO Paris Seminar.pdf
Moving Beyond Passwords: FIDO Paris Seminar.pdfMoving Beyond Passwords: FIDO Paris Seminar.pdf
Moving Beyond Passwords: FIDO Paris Seminar.pdf
 
"ML in Production",Oleksandr Bagan
"ML in Production",Oleksandr Bagan"ML in Production",Oleksandr Bagan
"ML in Production",Oleksandr Bagan
 
The Role of FIDO in a Cyber Secure Netherlands: FIDO Paris Seminar.pptx
The Role of FIDO in a Cyber Secure Netherlands: FIDO Paris Seminar.pptxThe Role of FIDO in a Cyber Secure Netherlands: FIDO Paris Seminar.pptx
The Role of FIDO in a Cyber Secure Netherlands: FIDO Paris Seminar.pptx
 
What is DBT - The Ultimate Data Build Tool.pdf
What is DBT - The Ultimate Data Build Tool.pdfWhat is DBT - The Ultimate Data Build Tool.pdf
What is DBT - The Ultimate Data Build Tool.pdf
 
Use of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptx
Use of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptxUse of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptx
Use of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptx
 
Ensuring Technical Readiness For Copilot in Microsoft 365
Ensuring Technical Readiness For Copilot in Microsoft 365Ensuring Technical Readiness For Copilot in Microsoft 365
Ensuring Technical Readiness For Copilot in Microsoft 365
 

SplunkLive New York 2011: DealerTrack

  • 1. New  York  City   October  27,  2011  
  • 2. Chris  DeMeo   Sr.  Director  Technology   New  York,  October  27,  2011   Architecture   Copyright  ©  2011,  Splunk  Inc.  
  • 3. About  Me   !  One  of  the  founders  of   DealerTrack   !   With  the  company  since   incepJon   !   Technology  Architecture  Lead   -­‐  Infrastructure   New  York,  October  27,  2011   3   Copyright  ©  2011,  Splunk  Inc.  
  • 4. About  DealerTrack   !  Leading  provider  of  on-­‐demand  soOware  and   services  for  the  automoJve  retail  industry   !   Industry’s  First  and  Largest  Credit  ApplicaJon   Network   !   ConnecJng  approximately  17,000  dealers   with  more  than  1,000  lenders   !   Dealer  Management  SoluJons,  Inventory   SoluJons,  Sales  SoluJons  and  Processing   SoluJons     New  York,  October  27,  2011   4   Copyright  ©  2011,  Splunk  Inc.  
  • 5. The  Challenge   •  Web  logs,  proprietary  logs,  database  logs,  operaJng  system  logs  –   No  way  to  look  through  them  easily,  it  took  hours   •  Over  Jme,  acquired  several  companies  resulJng  in  more   dependencies  and  the  need  to  consolidate  logs  across  geo's  and   datacenters     •  In  POC  there  was  doubt  about  the  value  of  the  tool.  How  many   hours  would  it  take  to  get  up  and  running?  How  quickly  before  we   see  value?   "We  needed  a  tool  that  could  correlate  all  logs."   New  York,  October  27,  2011   5   Copyright  ©  2011,  Splunk  Inc.  
  • 6. The  First  of  Many  Aha  Moments   •  Oracle  RAC  database  cluster  failover  -­‐  root  cause  analysis   •  E-­‐contracJng  transacJon  -­‐  correlaJon  of  customer   impacJng  bug  using  3  correlated  log  types   •  Database  connecJons  –  custom  input  allowed  trending  in   new  ways   •  With  Splunk  ability  to  quickly  get  to  root  cause  (assuming   you  logged  something!)   •  Different  from  anything  we  used  before   •  Ability  to  show  a  developer  the  anatomy  of  a  problem  –   transacJon  tracing   New  York,  October  27,  2011   6   Copyright  ©  2011,  Splunk  Inc.  
  • 7. The  Second  of  Many  Aha  Moments   •  Capacity  Planning  –  now  has  the  ability  to  easily   validate  transacJon  mixes  and  volumes   •  Capacity  Planning  –  idenJfied  “bunching”  of   transacJons  during  load  tests   •  Increased  product  usage  and  customer  retenJon  –   through  idenJficaJon  of  their  legacy  product  usage     •  Outage  Impact  –  more  accurate  outage  impact   with  access  to  addiJonal  logs   New  York,  October  27,  2011   7   Copyright  ©  2011,  Splunk  Inc.  
  • 8. What  Also  Helped…..     •  AOer  3  months  execuJves  felt  Splunk  paid  for  itself   •  Ease  of  Use   • Development  can  build  their  own  dashboards   • Business  folks  saw  value  and  asked  for  informaJon   • We  had  Splunk  up  and  running  in  less  than  2  months   own  dashboards   New  York,  October  27,  2011   8   Copyright  ©  2011,  Splunk  Inc.  
  • 9. Vale  Add  to  Lending  Partners   •  Real-­‐Jme  visibility  into  credit  applicaJon  and  decision   volumes  across  all  lenders   •  Report  to  lenders  where  they  stand  against  the   compeJJon—drives  more  compeJJve  response   New  York,  October  27,  2011   9   Copyright  ©  2011,  Splunk  Inc.  
  • 10. Historical  Data  Search   !  Log  view  uJlity  for  our  own  proprietary  logs…   !   Our  own  tool  doesn’t  search  over  more  than  7  days  of  data   !   Now  we  can  search  historical  data  for  trending  analysis   New  York,  October  27,  2011   10   Copyright  ©  2011,  Splunk  Inc.  
  • 11. Current  Environment  and  Set  up   !  Deployed  across  4  applicaJon  environments   !   Non-­‐Cloud  based  -­‐  Run  our  own  equipment   !   Each  environment  has  1  server  (will  make  into  HA   configuraJon)   !   Everything  runs  on  a  single  server     !   Virtual  machines  in  non-­‐producJon  environments   !   Local  storage   New  York,  October  27,  2011   11   Copyright  ©  2011,  Splunk  Inc.  
  • 12. Coming  Soon   !  Syslog  inputs   !  HA  configuraJon  with  mulJple  search  heads  and  SAN  storage   !  Looking  to  install  Web  AnalyJcs  app  for  business  users   !  IntegraJon  with  other  monitoring  tools   !  User  adopJon-­‐-­‐work  on  user  educaJon-­‐-­‐how  they  are  using  it   !  Want  to  give  Security  group  ability  to  search  across  years  of  data   !  Rollout  to  subsidiaries  so  each  has  their  own  indexer   "Finding  data  in  our  logs  that  we  never  even  knew  was  there  and  that  people  are   ge8ng  value  from."   New  York,  October  27,  2011   12   Copyright  ©  2011,  Splunk  Inc.  
  • 13. Lessons  Learned     !  Before  we  didn't  have  the  data,  now  we  want  to  save  everything   !   Professional  Services  and  EducaJon  –  They  armed  us  and  made  us   more  than  dangerous!   !   Developed  internal  user  doc  with  best  pracJces  and  use  cases   !   Knowledge  of  your  logs  will  help  to  realize  value  quickly   New  York,  October  27,  2011   13   Copyright  ©  2011,  Splunk  Inc.  
  • 14. Thank  you   Chris  DeMeo   Sr.  Director  Technology     Architect   New  York,  October  27,  2011   Copyright  ©  2011,  Splunk  Inc.