53
Copyright © 2015 Splunk Inc. Getting Started with IT Service Intelligence Naman Joshi Snr Sales Engineer

SplunkLive Canberra Getting starting with IT Service Intelligence

  • Upload
    splunk

  • View
    117

  • Download
    0

Embed Size (px)

Citation preview

Page 1: SplunkLive Canberra Getting starting with IT Service Intelligence

Copyright©2015SplunkInc.

GettingStartedwithITServiceIntelligenceNamanJoshiSnrSalesEngineer

Page 2: SplunkLive Canberra Getting starting with IT Service Intelligence

Agenda

2

Page 3: SplunkLive Canberra Getting starting with IT Service Intelligence

ITSICoreConcepts

3

Page 4: SplunkLive Canberra Getting starting with IT Service Intelligence

WhatisaService?

Service RequestsResponses

InITSI,aService isalogicalgroupoftechnologycomponents thatauserdeemsneedtobemonitoredtogether.

Itcanoftenbegeneralizedasa“blackbox”whichwesendrequests,andexpectresponses

4

Page 5: SplunkLive Canberra Getting starting with IT Service Intelligence

WhatisaService?

DNS RequestsResponses

TechnicalServices

Auth RequestsResponses

Web RequestsResponses

Servicescanbelowerlevel(technical)…

5

Page 6: SplunkLive Canberra Getting starting with IT Service Intelligence

WhatisaService?

DNS RequestsResponses

TechnicalServices

CustomerTransactions

RequestsResponses

BusinessServices

Auth RequestsResponses

Web RequestsResponses

SupportDesk RequestsResponses

Servicescanalsobehigherlevel(business)…

6

Page 7: SplunkLive Canberra Getting starting with IT Service Intelligence

WhatisaService?

PacketNetwork

HypervisorandHosts

RBMDBs

StorageTier

APIServices

WebServices

CustomerTransactions

Mobile

API/Middlew

are

PartnerPortal

DNS

ServicescanencompassmultipletiersoftheITdomain.Servicesmayalsodependupon otherservices

7

Page 8: SplunkLive Canberra Getting starting with IT Service Intelligence

WhatisaKPI?

DNS RequestsResponses

KPI:NumberofrequestsKPI:ErrorrateKPI:Averageresponse timeKPI:ServerCPUloadKPI:ServernetworkI/Ferrors

CustomerTransactions

RequestsResponses

KPI:NumberoftransactionsKPI:ErrorrateKPI:Averageresponse timeKPI:CountofIncidentTicketsKPI:SyntheticTransxHealth

KPIsandHealthscoresconstitutethemeansbywhichServicesaremonitored.

8

Page 9: SplunkLive Canberra Getting starting with IT Service Intelligence

KeyPerformanceIndicators(KPIs)

9

AKeyPerformanceIndicator(KPI)isaSplunksavedsearchcreatedwithintheITSIUIthathelpsmonitoraspecificfieldlikeCPU,Memory,NumberofErrors

andsoon. KPIsarecontainedwithinServices.

Page 10: SplunkLive Canberra Getting starting with IT Service Intelligence

ServiceHealthScores

10

AHealthscoreisascoreform0-100(0beingcriticaland100beingnormal)thathelpsdeterminethehealthofaService.ItiscalculatedbasedonallKPIs

importanceanditsstatus(e.g.green,orange,red),onceeveryminute.

Page 11: SplunkLive Canberra Getting starting with IT Service Intelligence

Let’sTalkEntities

11

● Entitiesaretherelevantcomponentsthatsupportaservice(oftenbutnotalwayshosts)

● Selectthecorrectentitieswithfilters,ANDs,ORs

● EntitylistcancomefromaCMDB,aspreadsheet,aSplunksearch…

Page 12: SplunkLive Canberra Getting starting with IT Service Intelligence

ServiceDecomposition

12

Page 13: SplunkLive Canberra Getting starting with IT Service Intelligence

ServiceDecompositioninITSI

13

CLICK“GlassTables”

Page 14: SplunkLive Canberra Getting starting with IT Service Intelligence

ServiceDecompositioninITSI

14

CLICK(openinnewtab)“ButtercupGamesBusiness Process(INPROGRESS)”

Page 15: SplunkLive Canberra Getting starting with IT Service Intelligence

ServiceDecompositioninITSI

15

CLICK(openinnewtab)“ButtercupGamesOnlineStore”

Page 16: SplunkLive Canberra Getting starting with IT Service Intelligence

ServiceDecompositioninITSI

16

Identifyahigh-valuebusinessservice

Page 17: SplunkLive Canberra Getting starting with IT Service Intelligence

ServiceDecompositioninITSI

17

Identifytheprocessflowandunderlyingsub-services(Web->Middleware->DB->Middleware->Web)

Page 18: SplunkLive Canberra Getting starting with IT Service Intelligence

ServiceDecompositioninITSI

18

Foreachsub-service,identifyKPIsthatwillshowhealthandstatus(Requests,responsetime,errors,OShealth…)

Page 19: SplunkLive Canberra Getting starting with IT Service Intelligence

ServiceDecompositioninITSI

19

ForeachKPI,defineaSplunksearch

Page 20: SplunkLive Canberra Getting starting with IT Service Intelligence

ServiceDecompositioninITSI

20

Page 21: SplunkLive Canberra Getting starting with IT Service Intelligence

ITSIDemo

21

Page 22: SplunkLive Canberra Getting starting with IT Service Intelligence

ServiceDecomp:TheBusinessProcesses

22

Page 23: SplunkLive Canberra Getting starting with IT Service Intelligence

ServiceDecomp:End-To-EndProcessFlow

23

Page 24: SplunkLive Canberra Getting starting with IT Service Intelligence

NewRequirements!

24

● CreateanewKPIfortheDBService:● NetworkUtilization

● Modify theExecutiveGlassTableinordertoshowofftheservicesyouslaveover

“WEonlyhaveabout15minTODOWHAT???!!???”

Thinkabouthowlongthiswouldtakeyoutoday?

Page 25: SplunkLive Canberra Getting starting with IT Service Intelligence

25

ConfigurationofDBService

Click Configure >Click Services

Page 26: SplunkLive Canberra Getting starting with IT Service Intelligence

AKPIin5minutes?Absolutely!

26

ClickNew– GenericKPI

Select DataModel● HostOperatingSystem● Network● #bytes● Next

Page 27: SplunkLive Canberra Getting starting with IT Service Intelligence

KPIsContinued….

27

SplunkBuildsSearchesforyou–OhYeah,that’shappeningJ

● Select Yesfor Splitby& Filteroptions● Select hostfor EntityLookup& Aliasoptions● Click Next

Page 28: SplunkLive Canberra Getting starting with IT Service Intelligence

AlmostThere…

28

Select● KPISearchSchedule:EveryMinute● EntityCalculation: Average● Service/AggCalculation: Average● Calculation Window: LastMinute● Click Next

● Unit:Bps● Click Next

Page 29: SplunkLive Canberra Getting starting with IT Service Intelligence

FinalSteps…

29

Setyourthresholds:● Aggregate (All)● PerEntity

● Click “Add Threshold”TWICE● MaketheNeapolitanicecreamcolors

Yellow,Green,Yellow● Dragthesliders aroundinordertoget

thecurrentdatagraphentirelyinside theGreen(normal) band

● Click Finish● Otheroptions arealsoavailable,

including adaptivethresholds andanomalydetection

Page 30: SplunkLive Canberra Getting starting with IT Service Intelligence

AdaptiveThresholds

30

WhatifyourKPIdatalookslikethis?

Page 31: SplunkLive Canberra Getting starting with IT Service Intelligence

31

AdaptiveThresholdsStaticthresholds willnotwork…

Page 32: SplunkLive Canberra Getting starting with IT Service Intelligence

32

AdaptiveThresholdsAdaptiveThresholding worksbeautifullywithcyclical(andotherdynamic)data

Page 33: SplunkLive Canberra Getting starting with IT Service Intelligence

AnomalyDetection

33

● MachineLearning

● Workswellfordatawithpatterns

● Requiressome“training”(trial&error)tozeroinonbestsensitivity

Page 34: SplunkLive Canberra Getting starting with IT Service Intelligence

ITSIDemo–Troubleshooting

34

Page 35: SplunkLive Canberra Getting starting with IT Service Intelligence

NamethatKPI!

35

FromthelistofKPIs,selectyournewone(atthebottom)● Clickonthelittlepencilnexttothename● Callit“NetworkUtilization”,

withyourusernameupfront

● ClickonSave atbottomrightwhenfinished!

Page 36: SplunkLive Canberra Getting starting with IT Service Intelligence

Let’sFixthatGlassTable

36

Page 37: SplunkLive Canberra Getting starting with IT Service Intelligence

ClonetheGlassTable

37

ReturntoSavedGlassTablespage(click onGlassTablesintheuppermenubar)

CLICKEdit for“ButtercupGamesBusiness Process(INPROGRESS)”• Select Clone• Title:Add yourusername

tothefront• Permissions:SharedinApp• Click ClonePage

• Click onyournewGlassTablefromthelist,toviewit

Page 38: SplunkLive Canberra Getting starting with IT Service Intelligence

Edit&HaveFun!

38

ClickonEdit intheupperrightcornerofyourGlassTable

Usethe“Services”panelonthelefttoselectIndividual KPIs,or Aggregate ServiceHealthScores• Choose 2KPIsfromOnline Store thatwouldbeuseful in

the“OrderProcess”section• Dragtheselectedwidgetsontothecanvas,positioning in

thegrayoval

• What’s thedifferencebetweenthe

and toolsatthetopleft?

Page 39: SplunkLive Canberra Getting starting with IT Service Intelligence

MoreFunwiththeGlassTableEditor…

39

UsetheConfigurations panelontherighttoeditaselectedwidget• Canchangethevisualization type,drilldown

behavior, andothersettings

• Youshould hitSave frequently• IwonderwhatAutoLayoutdoes?• (YIKES!)RevertAllChangesmightbehelpful

Page 40: SplunkLive Canberra Getting starting with IT Service Intelligence

Finishingup…

40

• AddaServiceHealthScorewidgetforOnlineStoreunder Buttercup

• Choose aVizTypewithasparklinegraph,thenresizetomakeitlookpretty

• Modify theCustomDrilldownactiontogotothesavedglasstable,ButtercupGamesOnline Store

• BonusPoints:Makethelabelbigger,morereadable

• Click Save• View whendone

Page 41: SplunkLive Canberra Getting starting with IT Service Intelligence

ATroubleshootingExercise

41

Let’suseITSItotroubleshootanoutage● StartatyourGlassTable,“<UserName>ButtercupBusiness Process”● CustomerCarereportsthatunhappy customersarecomplaining offailures

andlongdelayswhentryingtopurchase● Thecallsbegancominginataroundtenminutesafterthehour.● IntheupperrightcorneroftheGlassTable,changethetimepickerfromNow

toXX:10:00.0,whereXXistheappropriatehour.Forexample,ifitiscurrently14:05,setthetimepickerto13:10:00.0,thenApply

● Thisishowwecan“timetravel”backtoseeconditions ataparticularoutage– ohyeah!

Page 42: SplunkLive Canberra Getting starting with IT Service Intelligence

ATroubleshootingExercise,cont’d

42

● TheOnline Storeseemstobedegraded,justasCustomerCarereported.Clickonthewidgetunder Buttercuptodrilldown further

Page 43: SplunkLive Canberra Getting starting with IT Service Intelligence

ATroubleshootingExercise,cont’d.

43

● TheOnline StoreGlassTableshows amuchmoredetailedview,including theimpactedcustomer-facingKPIsatthefarleft(Revenue,etc)

● Basedonthisviewofalltherelevantservices,wheredoyouthink therootcauselies?

● Which serviceshouldwetroubleshoot first?● ClickonHealthwidgetforthatservice, to

drilldowntoaDeepDive

Page 44: SplunkLive Canberra Getting starting with IT Service Intelligence

DeepDive

44

● DeepDiveshowsmultiple KPIsandHealthScoresinparallel“swimlanes”.

● TheHealthScoreforthisServiceisthetopswimlane.Canyouseewhenitbeginstodegradefrom100%?

● Mousing overthispointintime,canyouspottheKPIwiththeleadingfaultindication, i.e.,whatfailedfirst?

Page 45: SplunkLive Canberra Getting starting with IT Service Intelligence

Multi-KPIAlertsandNotableEvents

45

● Click onNotableEventsReview● MultipleKPIsandHealthscorescan

becombinedinsophisticatedwaystocreateMulti-KPIalerts

● WhenaMulti-KPIalertfires,oneoftheoutcomesisthecreationofaNotableEvent

● NotableEventsallowNOCpersonnel andotherstotriageandcoordinateeventmanagementefforts

Page 46: SplunkLive Canberra Getting starting with IT Service Intelligence

ServiceAnalyzer

46

● Click onServiceAnalyzer> DefaultServiceAnalyzer

● Backwherewestarted!● Thisviewshows a“no-frills” listof

services (top)andhottestKPIs(bottom)

● Provides aquickjumping offpointintoDeepDivesandtheNotableEventsReview

● Itisuseful forNOCs andotherswhoneedahigh-levelsituationalview

Page 47: SplunkLive Canberra Getting starting with IT Service Intelligence

WrapUp- Review

47

● High-valueservicescanbedecomposed andmodeled inITSI,usingmachinedatafromtherelevantsystems

● Services andKPIs canbecreatedinminutes,withsophisticatedthresholdingtechniques todistinguish “normal”from“notnormal”

● GlassTablesallowservicehealthandKPImetricstobedisplayedinawaythatmakessensetospecificgroups, suchasExecutiveLeadership,BusinessServiceOwners,theNOC,DevOps&Others

● DeepDivesallowKPIstobecomparedside-by-sideacrossanytimerange,acceleratingrootcauseanalysisandsignificantly reducingMTTR

● Multi-KPIAlertsandNotableEventsreducealertnoise,producing actionableeventsandameanstomanagethem

● …andit’sfuntobuild!

Page 48: SplunkLive Canberra Getting starting with IT Service Intelligence

Wanttoexploreonyourown?

48

Signupforyourveryownseven-dayfreesandbox!http://splunk.com/ITSI

Thenclick:

You’llfindaSandboxGuideintheDashboards!IntheITSIappofyoursandbox, gotoSearch>Dashboards>ITSISandboxGuide

Page 49: SplunkLive Canberra Getting starting with IT Service Intelligence

NorthernCalTechTalks!MonthlyWebExSessions• TedTalk stylepresentation• Q&AChatforum

Sowhat’snextontheagenda?• April20th@10AMPST- Top5mostuseful

searchcommands.• May18th @10AMPST– SplunkforIT

ServiceIntelligence

Seemoreat:http://live.splunk.com/NorCalTechTalks

Page 50: SplunkLive Canberra Getting starting with IT Service Intelligence

50

SEPT26-29,2016WALTDISNEYWORLD,ORLANDOSWANANDDOLPHINRESORTS

• 5000+IT&BusinessProfessionals• 3daysoftechnicalcontent• 165+sessions• 80+CustomerSpeakers• 35+Apps inSplunkAppsShowcase• 75+TechnologyPartners• 1:1networking:AskTheExpertsandSecurityExperts,BirdsofaFeatherandChalkTalks

• NEWhands-on labs!• Expandedshowfloor,DashboardsControlRoom&Clinic,andMORE!

The7th AnnualSplunkWorldwideUsers’Conference

PLUSSplunkUniversity• Threedays:Sept24-26,2016• GetSplunkCertifiedforFREE!• GetCPE creditsforCISSP,CAP,SSCP• Savethousands onSplunkeducation!

Page 51: SplunkLive Canberra Getting starting with IT Service Intelligence

A flying start to Service Intelligence

Start With A problem worth solving

Collaborate with Subject Matter Experts

Design Before Configuring

Page 52: SplunkLive Canberra Getting starting with IT Service Intelligence

SignUpHere- We’reHereToHelp!Harnessthecreativityanddomainknowledgeofyourorganizationtounlockthevalueofdataandsolveanimportantserviceproblemthroughajoint

serviceintelligenceworkshopwithkeystakeholders

Definemethodsfor:

• Proactiveservicemonitoring

• Reducedriskandfailures

• Fasterissueresolution

• Increasedbusiness

performance

Whatisit?

• 1DayOnsiteWorkshop

• Tightlylinkedwithvalue

• Collaborativeapproach

• BuildyourownSplunk

ITSIGlassTable……

Page 53: SplunkLive Canberra Getting starting with IT Service Intelligence

ThankYou