SlideShare a Scribd company logo
1 of 32
Copyright © 2015 Splunk Inc.
Getty Images
Rick Donohue
Product Owner
Enterprise Monitoring
2
Product Owner:
EnterpriseMonitoring
Ensuring businesscritical systemsareperformant & the
right person iscalled to fix
When I’m not Splunking…
Running, cycling or racing sail boats
456685818, John Moore
463873923, Jonathan Ferrey
462648484, Christopher Polk
Kelvin Murray
2696319, Robert Sargent
11
12
13
14
15
Enterprise
Monitoring at Getty
200070269-001, Tim Flach
16
Deciding on Splunk
462531283, Christopher Kimmel
17
Vitals for
Hardware
Diehards
454125810, Christopher Polk
18
Adoption
136289099, HansPalmboom
19
v1: Shotgun
Approach
460596632, LarsBarron
NASA, ullstein bild
Services
Oriented
Alerting
21
22
23
24
Extracting Full Value
25
26
27
28
Lessons
Fishing
Partnership
Easy for some
Forgetting the old way
Scale out
IO hog…srsly
Beg borrow and steal
Social
facebook.com/gettyimages
instagram.com/gettyimages
plus.google.com/+gettyimages
linkedin.com/company/getty-images
Twitter:
@GettyImages
@iStock
@GettyImagesNews
@GettyImagesReportage
@GettyGallery
@GettyFashion
@GettySport
@GettyVIP
@GettyCreativity
@GettyMuseum
Rick Donohue
Product Owner; EnterpriseMonitoring
Rick.Donohue@Gettyimages.com
206.925.6526
Thank you
459248436, handout
Getty Images Customer Presentation

More Related Content

More from Splunk

Der Weg in den vollautomatisierten SOC Betrieb
Der Weg in den vollautomatisierten SOC BetriebDer Weg in den vollautomatisierten SOC Betrieb
Der Weg in den vollautomatisierten SOC Betrieb
Splunk
 

More from Splunk (20)

.conf go 2023 - Cyber Resilienz – Herausforderungen und Ansatz für Energiever...
.conf go 2023 - Cyber Resilienz – Herausforderungen und Ansatz für Energiever....conf go 2023 - Cyber Resilienz – Herausforderungen und Ansatz für Energiever...
.conf go 2023 - Cyber Resilienz – Herausforderungen und Ansatz für Energiever...
 
.conf go 2023 - De NOC a CSIRT (Cellnex)
.conf go 2023 - De NOC a CSIRT (Cellnex).conf go 2023 - De NOC a CSIRT (Cellnex)
.conf go 2023 - De NOC a CSIRT (Cellnex)
 
conf go 2023 - El camino hacia la ciberseguridad (ABANCA)
conf go 2023 - El camino hacia la ciberseguridad (ABANCA)conf go 2023 - El camino hacia la ciberseguridad (ABANCA)
conf go 2023 - El camino hacia la ciberseguridad (ABANCA)
 
Splunk - BMW connects business and IT with data driven operations SRE and O11y
Splunk - BMW connects business and IT with data driven operations SRE and O11ySplunk - BMW connects business and IT with data driven operations SRE and O11y
Splunk - BMW connects business and IT with data driven operations SRE and O11y
 
Splunk x Freenet - .conf Go Köln
Splunk x Freenet - .conf Go KölnSplunk x Freenet - .conf Go Köln
Splunk x Freenet - .conf Go Köln
 
Splunk Security Session - .conf Go Köln
Splunk Security Session - .conf Go KölnSplunk Security Session - .conf Go Köln
Splunk Security Session - .conf Go Köln
 
Data foundations building success, at city scale – Imperial College London
 Data foundations building success, at city scale – Imperial College London Data foundations building success, at city scale – Imperial College London
Data foundations building success, at city scale – Imperial College London
 
Splunk: How Vodafone established Operational Analytics in a Hybrid Environmen...
Splunk: How Vodafone established Operational Analytics in a Hybrid Environmen...Splunk: How Vodafone established Operational Analytics in a Hybrid Environmen...
Splunk: How Vodafone established Operational Analytics in a Hybrid Environmen...
 
SOC, Amore Mio! | Security Webinar
SOC, Amore Mio! | Security WebinarSOC, Amore Mio! | Security Webinar
SOC, Amore Mio! | Security Webinar
 
.conf Go 2022 - Observability Session
.conf Go 2022 - Observability Session.conf Go 2022 - Observability Session
.conf Go 2022 - Observability Session
 
.conf Go Zurich 2022 - Keynote
.conf Go Zurich 2022 - Keynote.conf Go Zurich 2022 - Keynote
.conf Go Zurich 2022 - Keynote
 
.conf Go Zurich 2022 - Platform Session
.conf Go Zurich 2022 - Platform Session.conf Go Zurich 2022 - Platform Session
.conf Go Zurich 2022 - Platform Session
 
.conf Go Zurich 2022 - Security Session
.conf Go Zurich 2022 - Security Session.conf Go Zurich 2022 - Security Session
.conf Go Zurich 2022 - Security Session
 
Inside SecOps at bet365
Inside SecOps at bet365 Inside SecOps at bet365
Inside SecOps at bet365
 
Best of .conf22 Session Recommendations
Best of .conf22 Session RecommendationsBest of .conf22 Session Recommendations
Best of .conf22 Session Recommendations
 
IT Sicherheitsgesetz 2.0
 IT Sicherheitsgesetz 2.0 IT Sicherheitsgesetz 2.0
IT Sicherheitsgesetz 2.0
 
Risikowahrnehmung und Cyber-Resilienz Herausforderungen in der Angriffserkennung
Risikowahrnehmung und Cyber-Resilienz Herausforderungen in der AngriffserkennungRisikowahrnehmung und Cyber-Resilienz Herausforderungen in der Angriffserkennung
Risikowahrnehmung und Cyber-Resilienz Herausforderungen in der Angriffserkennung
 
Der Weg in den vollautomatisierten SOC Betrieb
Der Weg in den vollautomatisierten SOC BetriebDer Weg in den vollautomatisierten SOC Betrieb
Der Weg in den vollautomatisierten SOC Betrieb
 
Die Grundlagen für den KI gestützten IT-Betrieb
Die Grundlagen für den KI gestützten IT-BetriebDie Grundlagen für den KI gestützten IT-Betrieb
Die Grundlagen für den KI gestützten IT-Betrieb
 
SVA: Digitaler Föderalismus
SVA: Digitaler FöderalismusSVA: Digitaler Föderalismus
SVA: Digitaler Föderalismus
 

Recently uploaded

+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
?#DUbAI#??##{{(☎️+971_581248768%)**%*]'#abortion pills for sale in dubai@
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Safe Software
 
Why Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businessWhy Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire business
panagenda
 

Recently uploaded (20)

EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWEREMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
 
Boost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfBoost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdf
 
Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...
Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...
Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...
 
Exploring Multimodal Embeddings with Milvus
Exploring Multimodal Embeddings with MilvusExploring Multimodal Embeddings with Milvus
Exploring Multimodal Embeddings with Milvus
 
Strategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a FresherStrategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a Fresher
 
Polkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin WoodPolkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin Wood
 
presentation ICT roal in 21st century education
presentation ICT roal in 21st century educationpresentation ICT roal in 21st century education
presentation ICT roal in 21st century education
 
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
 
Manulife - Insurer Transformation Award 2024
Manulife - Insurer Transformation Award 2024Manulife - Insurer Transformation Award 2024
Manulife - Insurer Transformation Award 2024
 
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, AdobeApidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
 
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
 
AXA XL - Insurer Innovation Award Americas 2024
AXA XL - Insurer Innovation Award Americas 2024AXA XL - Insurer Innovation Award Americas 2024
AXA XL - Insurer Innovation Award Americas 2024
 
"I see eyes in my soup": How Delivery Hero implemented the safety system for ...
"I see eyes in my soup": How Delivery Hero implemented the safety system for ..."I see eyes in my soup": How Delivery Hero implemented the safety system for ...
"I see eyes in my soup": How Delivery Hero implemented the safety system for ...
 
Biography Of Angeliki Cooney | Senior Vice President Life Sciences | Albany, ...
Biography Of Angeliki Cooney | Senior Vice President Life Sciences | Albany, ...Biography Of Angeliki Cooney | Senior Vice President Life Sciences | Albany, ...
Biography Of Angeliki Cooney | Senior Vice President Life Sciences | Albany, ...
 
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
 
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
 
ICT role in 21st century education and its challenges
ICT role in 21st century education and its challengesICT role in 21st century education and its challenges
ICT role in 21st century education and its challenges
 
Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...
Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...
Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...
 
Why Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businessWhy Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire business
 

Editor's Notes

  1. A little about Getty Images for those of you who may not be familiar. Imagery is the universal language of our time and Getty Images is the global leader in visual communications – we distribute award-winning stills, footage, video, music and multimedia. We operate through various channels, predominately Gettyimages.com, iStockphoto.com and thinkstockphotos.com.
  2. Getty has in house and freelance contributors around the world providing rich editorial content (that essentially means news worthy), of the top issues of our time and presenting them in a method everyone can understand.
  3. Our Sports coverage is unparalleled. Getty is the exclusive provider of content for FIFA, the IOC and many, many more
  4. Our contributors have access to locations around the world that other agencies and photographers literally can’t access giving us un-paralled access to the best shots
  5. And our creative content pushes boundaries; defining and living on the edge of the visual trends of our time.
  6. Finally, we have the most exhaustive collection of archival content anywhere in the world
  7. Last year, we launched our embed which enables anyone to share the vast majority of our content for free for non-commercial purposes. I encourage you to head over to gettyimages.com and start using embed.
  8. Getty Images Stream for iphone and Ipad, available in the app store
  9. Naturally, to showcase this superb content, we have some equally amazing websites with istockphoto.com as well as our flagship brand, Gettyimages.com among others, including our consumer oriented photos.com. And as you know, behind the pretty pixels, is lots of hardware and lots, and lots and lots of code….
  10. What does enterprise monitoring mean at Getty? Whats working – what isn’t, scope of impact Reliable – alerts (accurate) and uptime Decomposition of services – visualizations of system activiy Accessible to anyone; engineers to tech manager, business leaders Want to do alerting differently than ‘just’ scom/Nagios, zabbix etc. Entered into process ‘eyes wide open’ knowing that this is a very hard nut to crack Splunk a huge leg up in meeting our goals
  11. Went all-in on splunk focal point of our monitoring/alerting architecture All data in one place, even from other tools (solar winds, 24x7 etc.) Integrates with other tools and workflows (Alerting, Incident workflow etc) SNOW Democratization of data - anyone can visualize and consume the data 1 tool, many uses. Fewer apps to support
  12. Vitals: 1 search head (4 in broken cluster) 9 indexers; 2 job servers ~1.4T/Day; ~350k searches/day Highly optimized and tuned to perform on small hardware footprint – slow but works Running 6.0.3 Recent expansion from 9 to 20 indexers Upgrade to latest rev coming
  13. Different from what I’ve seen in the market Early adoption, app dev. Not much TS. Different from many businesses App dev built out heavily, tended to have faster resolution times thanks to splunk/correlations etc TS leadership pointed to success, said now we must follow ~40% users w/ splunk window open at any time
  14. 1.0 w/ shotgun approach State tracking v1 Created 1sy 2sy alerting, chasing pri1 and 2 events Focused on hardware, not services; - ‘great, x is broken, what does it mean to the business’ Spotty coverage map Random charts, for every group, only a few understood what was what No holistic coverage for service stacks (think end user experience)
  15. Time to start doing it better: Now logically building our own schema based on our business, user experiences Noc dash EventDrivenArchitecture and Alerting schema Integrating multiple other tools w/ Splunk Site24x7 SolrWinds Keynote ServiceNow CRM Data Splunk is not a magic solution – none of the solutions are. Hard work, most value is done in knowing your data Hard work in deeply understanding your business and systems/integrations Building roll up framework and logic that any alert fits into. A skeleton of our business and all alerts and dashboards slot in to fill a need
  16. Current state Splunk Tech Add-Ons add much value Limit need for, or compliment to other integration points Adopted ES for INFOSEC Heavily relied on for ITSM Measuring impact of ITSM process Change Management Must have tool, can’t release without it Data center move: monitoring performance from one DC to the other; Those who didn’t want it, now really see value Small Nagios ‘watches the watchmen’ Limited need for scom (NOC workflow, have roadmap to change that)
  17. How is our new code performing – from different data centers, different geo’s Reduced testing time – roll the code, see the impact Enables us to be more aggressive, move faster, bring value to customers faster than we could otherwise Takes the ‘hope’ out of the equation Compare real user metrics from logs w/ Keynote Speeds time to production, enables us to take calculated risks Fits with agile way Ensure new code doesn’t negatively impact performance or user experience Immediate visibility into real-time code health/ performance stats
  18. Tracking our performance -incidents -change -monitored vs not
  19. Knowing whats out there “…would love to have known that chart existed during the p1”
  20. Lessons Learned Being the monitoring team, not the dashboard building team Teach users to fish…but still need to fish for them at times Query hygiene. Index=* all time real time Tech talk Splunk on-site trainings, even in Calgary Splunk good partner, helped with training, huge assistance, even in Calgary Comes natural to some, but not all Convincing people to drop their old tools Expand your hardware footprint as use grows; DON’T WAIT! LOTS of tuning and optimization to ‘keep lights on’ w/o more infrastructure Just buy the damn boxes, don’t invest huge learning curve for optimization. Follow best practice Feeling the pain of not investing in infrastructure Poor experience due to lack of hardware footprint Biggest limitation is IO Not building out infrastructure underneath will result in fragmentation, users finding new tools if performance isn’t there. Encourage people to share searches and content they have built Learn by stealing! Weekly ‘Splunk Tech Talk’ meeting – open forum to help new and expert users
  21. Getty has in house and freelance contributors around the world providing rich editorial content (that essentially means news worthy), of the top issues of our time and presenting them in a method everyone can understand.