15
© 2017 SPLUNK INC. Tom Andre Skar | IT Operations 23 RD NOV 2017 | STOCKHOLM

SplunkLive! Stockholm 2017 - Norsk Tipping Customer Presentation

  • Upload
    splunk

  • View
    122

  • Download
    4

Embed Size (px)

Citation preview

© 2017 SPLUNK INC.

Tom Andre Skar | IT Operations

23RD NOV 2017 | STOCKHOLM

© 2017 SPLUNK INC.

▶ Norsk Tipping and my role

▶ How we started with Splunk

▶ Splunk at Norsk Tipping

▶ What’s next

Agenda

© 2017 SPLUNK INC.

3

My Background and Role

▶ IT Operations

▶ Splunk since early 2016

▶ Splunk ITSI

▶ Favorite Splunk tee-shirt tag line:

▶ “Finding your faults, just like mom.”

© 2017 SPLUNK INC.

4

Norwegian State Lottery

▶ 400 employees

▶ 2.400.000 customers

▶ 34 billion nok turnover

▶ 5 billions nok generated for good purposes

▶ 2000 servers

Norsk Tipping is assigned by the government to offer

games that create excitement and entertainment within

responsible limits, with the profits going to good causes

© 2017 SPLUNK INC.

5

Lotteries Scratch Sport VLTs Interactive

© 2017 SPLUNK INC.

6

Splunk at Norsk Tipping today

▶ Splunk Enterprise 7.0

▶ Splunk ITSI 3.0

▶ 160GB license

▶ 800 forwarders

▶ 450 entities (ITSI)

▶ 150 services (ITSI)

▶ 800 000 events per minute

© 2017 SPLUNK INC.

7

How We Got Started

▶ DDOS attack in 2012

▶ 3.5mill lines of log in seconds

▶ Splunk could predict and compare next hour sales

Splunk 100GB License

May 2014

Splunk 160GB License

October 2017Splunk ITSI

March 2017

© 2017 SPLUNK INC.

8

Splunk Success

▶ Business insight

▶ Presentation, report, dashboards

▶ Data sources

▶ Easily learned

© 2017 SPLUNK INC.

9

Why Splunk ITSI

▶ Situation: Operations Center is missing out. Key business events that should have been discovered are reported by customers.

▶ Wanted: A tool that could give us service based monitoring and the ability to be proactive

▶ Enter: Splunk ITSI

And dedicated resources

© 2017 SPLUNK INC.

10

Splunk ITSI

▶ Situation: Struggling with event fatigue and false positives - “fire fighting”

▶ Wanted: Reduce false positives and act on events that count. Be proactive!

▶ Enter Splunk ITSI:

▶ Notable Event

▶ Thresholding

▶ Anomaly Detection

© 2017 SPLUNK INC.

11

Splunk ITSI

▶ Situation: With hundreds of applications and microservices – not knowing business impact and dependencies are challenging

▶ Wanted: Show impact and dependencies of an outage

▶ Enter Splunk ITSI:

▶ Service Analyzer

© 2017 SPLUNK INC.

12

Splunk ITSI

▶ Situation: Manual log analysis to identify problem we were struggling with. No standard logging.

▶ Wanted: To reduce the Mean Time To Identify and standardize logging to meet KPI easily

▶ Enter Splunk ITSI:

▶ Deep Dive

▶ KPIs

© 2017 SPLUNK INC.

13

What’s Next

© 2017 SPLUNK INC.

1. Dedicate resources

2. Know your data

3. Business insights

4. Operational intelligence

Key Takeaways

© 2017 SPLUNK INC.© 2017 SPLUNK INC.

THANK YOU