More Related Content
Similar to Splunk Discovery: Milan 2018 - Get More From Your Machine Data with Splunk AI (20)
Splunk Discovery: Milan 2018 - Get More From Your Machine Data with Splunk AI
- 1. © 2017 SPLUNK INC.
Get More From Your Machine Data
With Splunk & AI
Emanuele Pasqualucci | Technical Partner Manager
SESSIONE 1
- 3. © 2017 SPLUNK INC.
▶ Face detection: find faces in images
▶ Spam filtering: identify SPAM messages
▶ Shopping recommendations: predict
what customers would like to buy
▶ Fraud detection: identify credit card
transactions
that may be fraudulent in nature
▶ Weather forecast: predict whether or not
it will rain tomorrow; estimate daily
max/min
ML is All Around You!
- 4. © 2017 SPLUNK INC.
Humans are good at
learning, but we get lost
in volume and details…
- 5. © 2017 SPLUNK INC.
▶ Improve decision-making
▶ Uncover hidden trends or
relationships
▶ Alert on deviations
▶ Forecast or anticipate incidents
All of this requires diverse data
from across many silos. Lots
of unstructured, real-time data.
Why AI & Machine Learning?
- 6. © 2017 SPLUNK INC.
Run the Business in Real Time
Data From the Past Real-Time Data Statistical Forecast
T – a few days T + a few days
Security Operations Center
IT Operations Center
Business Operations Center
Predictive
(Models)
Historical Reporting
(BI Tools, Data Lakes) Grey space
- 8. © 2017 SPLUNK INC.
The ML Process
Get and
explore data
Select and fit an
algorithm,
generating a model
Apply and
validate models
Surface model to
consumers to
solve problems
Problem: <Stuff in the world> causes big time and money expense. Value Hypothesis
Solution: Build ML model to forecast <possible incidents>, act pre-emptively and learn
Operationalize
- 10. © 2017 SPLUNK INC.
Overview of AI Powered by ML at Splunk
CORE PLATFORM
SEARCH
PACKAGED PREMIUM
SOLUTIONS
MACHINE LEARNING
TOOLKIT
- 11. © 2017 SPLUNK INC.
Search Includes Machine Learning
Core platform search is a powerful and highly flexible interface built with ML
- 12. © 2017 SPLUNK INC.
Machine learning-powered analytics for real-time service insights,
simplified operations and root-cause isolation
- 14. © 2017 SPLUNK INC.
Splunk IT Service Intelligence
Get Data
Define services,
entities and KPIs
Monitor and
troubleshoot
Analyze
and detect
Data-Defined, Data-Driven Service Insights
Adaptive Thresholds and Anomaly Detection
- 15. © 2017 SPLUNK INC.
Machine Learning Made Mainstream
Adaptive Thresholds Anomaly Detection Event Analytics
- 16. © 2017 SPLUNK INC.
Baseline Operational Patterns and Adapt Thresholds
Use machine learning to dynamically
adapt KPI thresholds by time
Maintain and preserve learned thresholds
to monitor KPI and service behavior
- 17. © 2017 SPLUNK INC.
Detect Normal and Abnormal Behavior
Baseline normal operations and
alert on anomalous conditions
Identify abnormal trends and
patterns in KPI data
- 18. © 2017 SPLUNK INC.
▶ Reduce event clutter and false
positives with multivariate anomaly
detection
▶ Use machine learning Smart Mode to
group related events and generate
human-scale alerts
▶ Create custom aggregation policies to
filter event noise
▶ Easily sift through events by filtering,
tagging and sorting
▶ Enrich and add context to events to
prioritize investigation and ensure
business-service availability
Sophisticated Event Analytics
- 19. © 2017 SPLUNK INC.
Breadth of Machine Learning Capabilities
Make IT Effective, Proactive and Predictive
Dynamic Thresholding
Thresholds adapt in real time
Trend and alert on anomalous
behavior
Prevent service degradation
Event Clustering
Detect and highlight the
events that matter
Prioritize events that need
action taken
Anomaly Detection
Alerts triggered automatically
by anomalous activity
Incident responders can see
across all silos to find a
quicker MTTR
Prediction
Predict outages and anomalies
before they occur
Act on these predictions so
your services are not affected
Platform for Machine Data
- 20. © 2017 SPLUNK INC.
Anomalous Behavior Risky Users Unknown Threats
Splunk User Behavior Analytics
An out-of-the-box solution that helps organizations find
with the use of machine learning
- 23. © 2017 SPLUNK INC.
• Risky Behavior Detection
• Entity Profiling, Scoring
• Kill chain, Graph analysis
Splunk Enterprise Security
Detect, Investigate & Response
• Single pane of glass
• Security Metrics & Incident
Response
• Adaptive Response
• Collaboration
Splunk Enterprise
Investigate
Realm of
Known
Human-driven
Splunk UBA
Detect
Realm of
Unknown
ML-driven
• Log Aggregation
• Rules, statistics, correlation
• Ad hoc searches and data pivot
- 24. © 2017 SPLUNK INC.
▶ Assistants: Guided model building, testing
and deployment for common objectives
▶ Showcases: Interactive examples for
typical IT, security, business and IoT use
cases
▶ Algorithms: 25+ standard algorithms
included with the Toolkit
▶ ML Commands: New SPL commands to fit,
test and operationalize models
▶ Python for Scientific Computing Library:
Access to 300+ open source algorithms
Splunk Machine Learning Toolkit
Extends Splunk platform functions and provides a guided modeling environment
Build custom analytics for any use case
- 25. © 2017 SPLUNK INC.
Custom Machine Learning – Success Formula
Identify use cases
Drive decisions
Set business/ops priorities
SPL
Data prep
Statistics/math background
Algorithm selection
Model building
Splunk ML Toolkit
facilitates and simplifies
via examples and guidance
Operational success
Data
Science
Expertise
Splunk
Expertise
Domain
Expertise
(IT, Security…)
- 27. © 2017 SPLUNK INC.
Continuous Data Ingest at Scale
DevelopVisualize PredictAlertSearch
Engineers Data
Analysts
Security
Analysts
Business
Users
Native Inputs
TCP, UDP, Logs, Scripts, Wire, Mobile
Industrial Data
SCADA, AMI, Meter Reads
Modular Inputs
MQTT, AMQP, COAP, REST, JMS
HTTP Event Collector
Token Authenticated Events
Technology Partnerships
Kepware, AWS IoT, Cisco, Palo Alto
Maintenance
Info
Asset
Info
Data
Stores
External
Lookups/EnrichmentOT
Industrial Assets
IT
Consumer and
Mobile Devices Real Time
- 28. © 2017 SPLUNK INC.
Search
Third-Party
Applications
Smartphones
and Devices
Tickets
Email
Send an
email
File a
ticket
Send a text
Flash lights
Trigger
process flow
Sense and Respond
Search Can Use
Machine Learning
OT
Industrial Assets
Consumer and
Mobile Devices
Alert
IT
Real Time
- 30. © 2017 SPLUNK INC.
▶ Real-time enterprise-wide infrastructure monitoring
▶ Robust solution to tear down IT silos and correlate
events
▶ Dashboards for different audiences, from problem-
solving techs to big-picture managers
Leidos Taps Splunk ITSI for Better
Event Management
“We have so much information at our fingertips thanks to
Splunk… we’re constantly solving business problems in creative
ways.”
– Director of Performance Management, Leidos
TECHNOLOGY – IT OPERATIONS
- 31. © 2017 SPLUNK INC.
▶ Using Splunk Enterprise to monitor potential external
security breaches and UBA to detect insider threats
▶ Analyst efficiency to gather data and speed security
investigations has increased by more than 50 percent
▶ Provides deep understanding of data and reusable
correlation rules across all support engineer levels
Nasdaq: Keeping Markets Moving
“Splunk allows us to have a single skill set that is common
across the entire organization. Information security is
writing queries but using the same language as our
operations team.”
– AVP, Nasdaq
FINANCIAL SERVICES – SECURITY
- 32. © 2017 SPLUNK INC.
Machine Learning Customer Success
Network Incident Detection
Service Degradation Detection
Security/Fraud Prevention
Machine Learning
Consulting Services
Analytics App Built
on ML Toolkit
Optimizing operations and business results
Predict Gaming Outages
Fraud Prevention
Entertainment
Company
Cell Tower Incident Detection
Optimize Repair Operations
Prioritize Website Issues
and Predict Root Cause