Windows Inputs and MicrosoC Apps Strategy



Similar documents
Splunk Apps for Monitoring Microso< Based Infrastructure

Deployment Best PracHces for Splunk Apps Monitoring MicrosoK- based Infrastructure

The Jiffy Lube Quick Tune- up for your Splunk Environment

Workflow ProducCvity in Splunk Enterprise

More Comprehensive Digital Intelligence - CorrelaFng Client and Server- side Data

Gain Insight into Your Cloud Usage with the Splunk App for AWS

Splunk/Ironstream and z/os IT Ops

Splunk Enterprise in the Cloud Vision and Roadmap

Architec;ng Splunk for High Availability and Disaster Recovery

How to Leverage Splunk s Security Intelligence PlaKorm for Security OperaNons Environments

Incident Response Using Splunk for State and Local Governments

Deploying the Splunk App for Microso> Exchange

Technology Partners. Acceleratio Ltd. is a software development company based in Zagreb, Croatia, founded in 2009.

How and When to Use Dynamic Lookups

Perfmon Collection Setup Instructions for Windows Server 2008+

Server & Application Monitor

Technical Deep Dive: Hunk: Splunk Analy<cs for Hadoop Beta

Splunk for Networking and SDN

IBM Tivoli Monitoring V6.2.3, how to debug issues with Windows performance objects issues - overview and tools.

Project Server hardware and software requirements

System Requirements for Microsoft Dynamics SL 2015

Goliath Performance Monitor Prerequisites v11.6

System Requirements for Microsoft Dynamics NAV 2013 R2

simplify monitoring Environment Prerequisites for Installation Simplify Monitoring 11.4 (v11.4) Document Date: January

Server and Storage Sizing Guide for Windows 7 TECHNICAL NOTES

Aqua Connect Load Balancer User Manual (Mac)

SolarWinds Network Performance Monitor powerful network fault & availabilty management

Best PracBces: Deploying Splunk on Physical, Virtual, and Cloud Infrastructure

Sage 200 Online. System Requirements and Prerequisites

User Reports. Time on System. Session Count. Detailed Reports. Summary Reports. Individual Gantt Charts

Understand Troubleshooting Methodology

System Requirements for Microsoft Dynamics NAV 2016

Table of Contents. Introduction...9. Installation Program Tour The Program Components...10 Main Program Features...11

SolarWinds Network Performance Monitor

System Requirements and Prerequisites

This document is provided to you by ABC E BUSINESS, Microsoft Dynamics Preferred partner. System Requirements NAV 2016

Configuration Maximums VMware Infrastructure 3

Real World Big Data Architecture - Splunk, Hadoop, RDBMS

SOLARWINDS NETWORK PERFORMANCE MONITOR

System Requirements for Microsoft Dynamics NAV 2016

Hardware Recommendations

Hardware and Software Requirements for Server Applications

vcenter Operations Management Pack for SAP HANA Installation and Configuration Guide

A Guide to New Features in Propalms OneGate 4.0

TNT SOFTWARE White Paper Series

System Requirements. Microsoft Dynamics NAV 2016

System Requirements for Microsoft Dynamics NAV 2016

SolarWinds Network Performance Monitor

SQL diagnostic manager Management Pack for Microsoft System Center. Overview

Deploying XenApp 7.5 on Microsoft Azure cloud

Sage 200 On Premise. System Requirements and Prerequisites

Operating System Installation Guide

Enterprise Manager. Version 6.2. Installation Guide

SAGE 500 PRODUCT ROADMAP

Cloud Services MDM. ios User Guide

Module 10: Maintaining Active Directory

Stream Deployments in the Real World: Enhance Opera?onal Intelligence Across Applica?on Delivery, IT Ops, Security, and More

Smart Business Architecture for Midsize Networks Network Management Deployment Guide

Enterprise Manager. Version 6.2. Administrator s Guide

Web. Anti- Spam. Disk. Mail DNS. Server. Backup

By the Citrix Publications Department. Citrix Systems, Inc.

WhatsUp Event Archiver v10 and v10.1 Quick Setup Guide

Planning Domain Controller Capacity

StreamServe Persuasion SP5 StreamStudio

Enterprise Reporter Report Library

System Requirements for Microsoft Dynamics NAV 2015

Volume SYSLOG JUNCTION. User s Guide. User s Guide

11.1. Performance Monitoring

MONITORING PERFORMANCE IN WINDOWS 7

Best Practices & Deployment SurfControl Mobile Filter v

STEALTHbits Technologies, Inc. StealthAUDIT v5.1 System Requirements and Installation Notes

Transform E- Commerce the Domino s Pizza Way

From the Datacenter to the Dean s office

One of the database administrators

Perfmon counters for Enterprise MOSS

Server Software Installation Guide

Network device management solution.

AssetWise Performance Management. APM Installation Prerequisites

RAP as a Service for. Team Foundation Server. Prerequisites

CA Service Desk Manager - Mobile Enabler 2.0

Part2 Hyper-V Replica and Hyper-V Recovery Manager. Datacenter Specialist

Installing and Configuring vcenter Multi-Hypervisor Manager

Practical Performance Understanding the Performance of Your Application

System Requirements for Microsoft Dynamics GP 2015

MCSE Core exams (Networking) One Client OS Exam. Core Exams (6 Exams Required)

System Requirements for Microsoft Dynamics NAV 2016

Backup Exec System Recovery Management Solution 2010 FAQ

LEPIDEAUDITOR SUITE- DATASHEET

WhatsUp Gold v16.2 MSP Edition Deployment Guide This guide provides information about installing and configuring WhatsUp Gold MSP Edition to central

CA Unified Infrastructure Management

Veeam Task Manager for Hyper-V

There are numerous ways to access monitors:

NETASQ SSO Agent Installation and deployment

Infor Web UI Sizing and Deployment for a Thin Client Solution

1. Server Microsoft FEP Instalation

NetIQ Privileged User Manager

Managing Capacity Using VMware vcenter CapacityIQ TECHNICAL WHITE PAPER

Before deploying SiteAudit it is recommended to review the information below. This will ensure efficient installation and operation of SiteAudit.

Transcription:

Copyright 2013 Splunk Inc. Windows Inputs and MicrosoC Apps Strategy Sharad Kylasam Sr. Product Manager #splunkconf

Legal NoIces During the course of this presentaion, we may make forward- looking statements regarding future events or the expected performance of the company. We cauion you that such statements reflect our current expectaions and esimates based on factors currently known to us and that actual events or results could differ materially. For important factors that may cause actual results to differ from those contained in our forward- looking statements, please review our filings with the SEC. The forward- looking statements made in this presentaion are being made as of the Ime and date of its live presentaion. If reviewed acer its live presentaion, this presentaion may not contain current or accurate informaion. We do not assume any obligaion to update any forward- looking statements we may make. In addiion, any informaion about our roadmap outlines our general product direcion and is subject to change at any Ime without noice. It is for informaional purposes only and shall not, be incorporated into any contract or other commitment. Splunk undertakes no obligaion either to develop the features or funcionality described or to include any such feature or funcionality in a future release. Splunk, Splunk>, Splunk Storm, Listen to Your Data, SPL and The Engine for Machine Data are trademarks and registered trademarks of Splunk Inc. in the United States and other countries. All other brand names, product names, or trademarks belong to their respeccve owners. 2013 Splunk Inc. All rights reserved. 2

About Me Sharad Kylasam:! At Splunk for 1 year! Product Manager responsible for Splunk on Windows and MicrosoC Apps! Previously at MicrosoC for 6 years as PM in Windows Networking working on Remote Access technologies 3

Agenda! Windows Inputs New inputs (Splunk Enterprise 6 only) Host monitoring, network monitoring, file monitoring Changes to exising inputs Demo! Fundamentals improvements! MicrosoC Apps Now and What s coming 4

Windows Inputs - New

Host Monitoring! Used to capture hardware and socware a`ributes of a given host! Fairly staic, low volume, high value data! Split collecions for data that you want to capture at different frequencies [WinHostMon://WinHostMon]! interval = 86400! type = Computer;OperatingSystem;Disk;N etworkadapter;processor;driver; Process;Service;Application! 6

Network Monitoring! Used to capture network traffic characterisics - inbound and outbound connecions from a given host! High volume, high value data! Filtering and MulIKV opions to reduce data volumes while maintaining data integrity [WinNetMon://WinNetMon]! addressfamily = ipv6;ipv4! direction = inbound;outbound! packettype = connect;accept! protocol = tcp;udp! 7

Print Monitoring! Used to monitor printer- related acivity from print servers and clients! Low/medium volume, medium value! Baseline opion to gather current state when monitoring begins [WinPrintMon://WinPrintMon]! baseline = 1! type = Port;Job;Driver;Printer! 8

File Monitoring Live Tailing! Used for live monitoring of a file! Use this instead of monitor stanza where monitor does not work with files that have conflicing file handles; e.g DNS debug log! Some limitaions Doesn t currently include baseline funcionality Currently only supports monitoring of one file at a given Ime [MonitorNoHandle://C:\Windows\System32\dns \debug.log]! disabled = 0! index = main! 9

Windows Inputs Enhancements

Changes to ExisIng Inputs! Converted exising inputs to modular inputs Regmon, Admon and Eventlog Note: All new inputs previously discussed are also implemented as modular inputs Benefits: 1. Backward compat ExisIng custom dashboard built on this data coninue to work in Splunk Enterprise 6 2. Built on standard plakorm Streamlined Windows input processing pipeline 3. More reliable Gets data into Splunk without risk of losing events 4. More performant Less custom processing on the UF for line breaking and parsing resuling in a more performant input 11

Perfmon! Ability to capture short- lived processes! Ability to enabling sampling and derive addiional staisics average, std. deviaion, max, min! Added support for regex on object parameter! Ability to reduce data volumes using MulIKV format [perfmon://perfmon]! counters = % C1 Time;% C2 Time;% C3 Time;% DPC Time;% Idle Time;% Interrupt Time;% Privileged Time;% Processor Time;% User Time;C1 Transitions/sec;C2 Transitions/sec;C3 Transitions/sec;DPC Rate;DPCs Queued/sec;Interrupts/sec! instances = _Total! interval = 10! object = Processor! samplinginterval=1000! stats=average;min;max;dev;count! mode=single! 12

File Monitoring Access! Leverage Windows security audit mechanism h`p://technet.microsoc.com/en- us/library/cc727935%28v=ws.10%29.aspx! AddiIonal filtering capability whitelist, blacklist on a per stanza basis [WinEventLog://Security]! checkpointinterval = 5! current_only = 0! disabled = 0! start_from = oldest! whitelist=4663! 13

Demo Common Use Cases for New Inputs

Fundamentals

Performance Splunk Add- On for Windows default configuraion:! 3 event log channels security, system and applicaion! 4 performance objects Memory, CPU, disk, network interface CPU Splunk 5.x CPU Splunk 6 Memory Splunk 5.x (in MB) Note All performance tests were conducted on Windows 7 Hyper- V VM, 4 cores, 4GB Memory Memory Splunk 6 (in MB) splunkd 2.80 0.28 85 75 Splunk- perfmon 0.10 0.01 17 11 Splunk- wineventlog N/A 2.33 N/A 9 16

Performance Windows Event log input: 1 Channel Indexing Time for 300K events Input Thruput (Avg eps) Splunk Enterprise 5.X 250 seconds 1200 Splunk Enterprise 6 130 seconds 2300 64 Channels Indexing Time for 300K events Input Thruput (Avg eps) Splunk Enterprise 5.X 270 seconds 1083 Splunk Enterprise 6 50 seconds 6000 17

Performance Perfmon: 100 CollecSons (1 counter) Interval 1 sec Splunk- perfmon CPU Splunk- perfmon Memory Splunk Enterprise 5.X 1.44 18.85 MB 98.83 Splunk Enterprise 6 1.60 18.32 MB 100 Input thruput (eps) Processor, Physical and Logical Disk and Memory objects (60 sec collecson interval, 10 sec sampling) Splunk- perfmon Avg. CPU Splunk- perfmon Avg. Memory Splunk Enterprise 6 UF 0.039 5.34 MB - - Splunk Enterprise 6 UF with 0.026 5.35 MB 5.9953 Sampling Avg samples per interval (expected 6) 18

MicrosoC Apps

MicrosoC ApplicaIons! New combined app in development Exchange, AD and Windows Customizable install experience In- app customizaion for building custom dashboard! Azure DiagnosIcs storage app Published! SQL server app Published! Sharepoint app Private beta 20

Demo MicrosoC App

Summary

Summary! Download and install Splunk Enterprise 6 and explore the windows inputs! Call to AcIon : Contact MicrosoC@splunk.com to be part of the MicrosoC App beta program! Call to AcIon ParIcipate in ODBC driver private Beta! Contact devinfo@splunk.com for access 23

Next Steps 1 2 3 Download the.conf2013 Mobile App If not iphone, ipad or Android, use the Web App Take the survey & WIN A PASS FOR.CONF2014 Or one of these bags! Go to Remote Data CollecSon and Forwarder Management with Splunk Enterprise Room: Nolita 2, Level 4 Today, 11:30-12:30pm 24

AddiIonal Resources Related.conf sessions! Splunk Apps for Monitoring MicrosoC based Infrastructure: Now and What's Coming Nolita 2 10/1 10:15 11:15! Deployment Best PracIces for Splunk Apps Monitoring MicrosoC based Infrastructure Brera 2 & 3 10/2 10:15-11:15! Technical Deep Dive: ODBC driver for Windows Brera 6 10/3 13:45-14:45 Visit the MicrosoC Booth Talk to the experts! 25

Thank You!