22
Search | Discover | Analyze © 2013 LucidWorks, All Rights Reserved Introducing the LucidWorks App for Splunk Enterprise Will Hayes Chief of Products, LucidWorks December 18, 2013

Introducing LucidWorks App for Splunk Enterprise webinar

Embed Size (px)

DESCRIPTION

LucidWorks App for Splunk Enterprise is the first of its kind, specifically designed to allow companies to analyze and manage the health and availability of their Solr deployments in Splunk software. The solution integrates multi-structured data indexed by Solr directly into Splunk® Enterprise, giving system administrators the ability to look at the intersection of documents, customer records or other unstructured data sources as they relate to machine data. This enables companies to optimize their Solr applications, glean insights from search and usage patterns and spot security concerns to improve end user experiences and derive more business value from data-driven applications. This webinar will explore the features of the App, and provide attendees with valuable information on the following key components: Solr Monitor: Monitor the health and availability and utilization of LucidWorks and/or Solr deployments with pre-defined data inputs, dashboards and reports Search Analytics: Perform user behavior and click-stream analysis with pre-built search analytics reports and fields NoSQL Lookups: Using Splunk’s lookup facility enrich your Splunk reports with data of any structure using Solr’s fully indexed and searchable NoSQL-datastore Search Time Joins: Join Splunk data with human generated and other unstructured data sources stored in Solr at search time for developing data-driven applications

Citation preview

Page 1: Introducing LucidWorks App for Splunk Enterprise webinar

Search | Discover | Analyze

© 2013 LucidWorks, All Rights Reserved

Introducing the LucidWorks App for Splunk Enterprise

Will HayesChief of Products, LucidWorksDecember 18, 2013

Page 2: Introducing LucidWorks App for Splunk Enterprise webinar

2

• Prior to LW, spent 8 years at Splunk, employee #9ish (held various roles Engineering, Business Development, Solutions)

• 15 years developing data driven apps and solutions

• Proud Search Snob!

Today’s Presenter

Chief of Products at LucidWorks

@iamwillhayes

Page 3: Introducing LucidWorks App for Splunk Enterprise webinar

3

• About LucidWorks

• LucidWorks for Splunk Enterprise Deployment Architecture

• LucidWorks for Splunk Enterprise Overview

• Example Use Cases

• Demo

Agenda

LucidWorks App for Splunk Enterprise

Page 4: Introducing LucidWorks App for Splunk Enterprise webinar

4

Our Mission

Enable Smarter Data Driven Applications Through the Power of Search

Page 5: Introducing LucidWorks App for Splunk Enterprise webinar

5

Techniques such as relevancy, recommendations, result ranking and personalization greatly enhance enterprise and consumer applications:– Consumer Websites– Knowledge Management– Cyber Security– Fraud Detection– Governance and Compliance

Data Driven Applications

Data Driven Applications deliver contextually relevant information when it’s needed

Page 6: Introducing LucidWorks App for Splunk Enterprise webinar

6

• Founded in 2007 to be the go-to-company for Lucene/Solr expertise• 300+ customers (many Fortune 500)• 30% of the Apache Lucene/Solr committers contributing over 50%

of dev• Creators of industry’s first enterprise grade search product built on

Lucene/Solr

Who is LucidWorks?

Commercializing and Extending Industry Leading Open Source Search

100’s of Billionsof documents

searched

4,000+Enterprise

applications

200%Growth in

recurring revenue

Page 7: Introducing LucidWorks App for Splunk Enterprise webinar

7

What is LucidWorks Search?

Most comprehensive enterprise search built on an Open Core

+

+High-Performance Indexing | Powerful, Accurate & Efficient Search AlgorithmsRanked & Field searchingFlexible faceting, highlighting, joins and result groupingPluggable ranking models

Advanced Full-Text Search CapabilitiesOptimized for High Volume Web TrafficStandards Based Open Interfaces - XML, JSON and HTTPComprehensive HTML Administration InterfacesServer statistics exposed over JMX for monitoringLinearly scalable

Entity ExtractionUser Interface for customizationConnectors & CrawlersCluster installerBusiness RulesRelevancy WorkbenchTime to Value

LuceneAll built on Java

Page 8: Introducing LucidWorks App for Splunk Enterprise webinar

8

60k - 100k downloads per month

Over 300,000 production deployments

What is Lucene/Solr

is a library that delivers robust full-text indexing for

unstructured data

provides a search server exposing a variety of features and APIs:

• Distributed shared architecture with real time replication

• Most advanced querying capability for both structured and unstructured data

Page 9: Introducing LucidWorks App for Splunk Enterprise webinar

9

The Solr Data Store provides:– Distributed shared architecture with real time replication

– Schemaless support and incremental field updates

– Schema updates without re-indexing

– Most advanced querying capability for both structured and unstructured data

Fully Indexed and Searchable NoSQL Store

The Search First NoSQL store

Page 10: Introducing LucidWorks App for Splunk Enterprise webinar

10

Reference Architecture

SystemManagem

ent

Installation

Administration

Monitoring

Configuration Mgt.

Service Management

Data Management

ZooKeeperMapRSearch

IndexesSearch Logs

Big Data File System

› Analytics› Classification/Machine Learning› Natural Language Processing› Key Workflows (bulk loading, log analysis, common

metrics)

Search – Discovery – Analytics EngineContentAcquisitio

n

Enterprise Repository

Social Media

MongoDB

Databases

HDFS

Cloud

Push

Uniform REST API

Page 11: Introducing LucidWorks App for Splunk Enterprise webinar

11

What is Splunk?

The Platform for Operational Intelligence

Page 12: Introducing LucidWorks App for Splunk Enterprise webinar

12

Reference Architecture

The best of both worlds

LucidWorks App for Splunk Enterprise Search logs collected from lws server

Perf counters Collected using REST

Reports generated leveraging data from Splunk + LucidWorks/Solr

Page 13: Introducing LucidWorks App for Splunk Enterprise webinar

13

The LucidWorks App for Splunk Enterprise

Multidimensional Data Analytics and Document Search for Splunk

Solr MonitorMonitor the health, availability and resource utilization Solr deployments with pre-defined data inputs, dashboards and reports.

Search AnalyticsPerform user behavior and search usage analysis with pre-built search analytics reports and field extractions.

NoSQL Data Joins and Document Search

Splunk’s lookup facility, enrich your Splunk reports with data of any structure using Solr’s fully indexed and searchable NoSQL-datastore.

Multi-Dimensional Data AnalysisJoin Splunk data with multiple

unstructured data sources stored in Solr at search time for developing powerful

data driven applications.

Page 14: Introducing LucidWorks App for Splunk Enterprise webinar

14

Solr Monitor

Page 15: Introducing LucidWorks App for Splunk Enterprise webinar

15

Solr Monitor

Page 16: Introducing LucidWorks App for Splunk Enterprise webinar

16

Solr Monitor

Page 17: Introducing LucidWorks App for Splunk Enterprise webinar

17

Solr Monitor

Page 18: Introducing LucidWorks App for Splunk Enterprise webinar

18

User Behavior - Search Analytics

Page 19: Introducing LucidWorks App for Splunk Enterprise webinar

19

Corporate Compliance – Multidimensional Analysis

Web Access Logs in Splunk show search

Correlation and Enrichment Powered by LucidWorks

Page 20: Introducing LucidWorks App for Splunk Enterprise webinar

20

Document Search - E-mail Messages and Attachments

Page 21: Introducing LucidWorks App for Splunk Enterprise webinar

21

Demo

Demo!

Page 22: Introducing LucidWorks App for Splunk Enterprise webinar

22

• Visit the Solr Marketplace: – lucidworks.com/marketplace

• Request a detailed demo:– [email protected]– 650-353-4057 x171

Take the Next Step

@LucidWorks LucidWorks.com/facebook