What s new in Machine Learning across the Splunk Portfolio

Similar documents
Using the Splunk Machine Learning Toolkit to Create Your Own Custom Models

Building ML Solutions using MLTK

WHITE PAPER SPLUNK SOFTWARE AS A SIEM

Going into the future with Splunk

Automation of Event Correlation and Clustering With Built-In Machine Learning Algorithms in Splunk IT Service Intelligence (ITSI)

TransUnion and a Time Traveling DeLorean

Physical State Analytics with Machine Learning

Splunk App Lifecycle Management

Condition-Based Maintenance In The German Public Rail Transportation System

An Introduction to Splunk IT Service Intelligence (ITSI)

Triggering Alerts with xmatters and Achieving Automated Recovery Actions from ITSI

More information for FREE VS ENTERPRISE LICENCE :

AI AND MACHINE LEARNING IN YOUR ORGANIZATION GET STARTED AND REAP THE BENEFITS.

Using Splunk for Retail Banking Cross Channel Fraud Analysis, Detection and Investigation

ITSI in the Wild. Why Micron Technology chose ITSI and lessons learned from real world experience. Mike Scully IT Area Lead Joe Trimmings IT Area Lead

Large US Bank Boosts Insider Threat Detection by 5X with StreamAnalytix

Bots, Outliers and Outages

Drive more value through data source and use case optimization

Achieve Operational Efficiency in Car Manufacturing with Advanced Analytics

Splunk Discovery Day Moscow

SAP Predictive Analytics Suite

Multi-Tenancy: Achieving Security, Collaboration, And Operational Efficiency

Working with Splunk Cloud

Ensuring Customer Satisfaction Through End-To-End Business Process Monitoring

ITSI at. Securing sustainability of competitive business services with ITSI. Eduard Lekanne IT Operations specialist VP, Manager Monitoring Services

Splunk This! - Bringing Natural Language Processing To Splunk

Monitoring End User Experiences With Splunk and New Relic

Savvius and Splunk: Network Insights for Operational Intelligence

Industry 4.0 and Smart Factory Smart Factory Toolkit. Smart Factory Toolkit Demo

Payment Cards and Risk

C3 Products + Services Overview

Easy Ride. How to Collect Tolls While Keeping Drivers Happy

Fun with Analytics. Marcello Lino SVP, Security Analytics Engineering James Sullivan VP, Security Analytics Engineering. Sep/2017 Washington, DC

GETTING STARTED GUIDE GETTING STARTED WITH SPLUNK FOR MONITORING AND DIAGNOSTICS

Splunk ITSI as a Foundation for ITOA

Secure information access is critical & more complex than ever

Machine Learning For Enterprise: Beyond Open Source. April Jean-François Puget

Data Science, realizing the Hype Cycle. Luigi Di Rito, Director Data Science Team, SAP Center of Excellence

Azure ML Studio. Overview for Data Engineers & Data Scientists

Oracle Stream Analytics

Efficiently Develop Powerful Apps for An Intelligent Enterprise

IBM Security Investor Briefing 2018

WHITE PAPER THE PATH TO OPERATIONAL INTELLIGENCE

Oracle Management Cloud

Integrating MATLAB Analytics into Enterprise Applications The MathWorks, Inc. 1

This document (including, without limitation, any product roadmap or statement of direction data) illustrates the planned testing, release and

How We Deliver First Class Digital and Services to Our Customers Thanks to Splunk

run() ANP104 Massive Predictive Analytics

Databricks Cloud. A Primer

VULNERABILITY MANAGEMENT BUYER S GUIDE

Cloudera Data Science and Machine Learning. Robin Harrison, Account Executive David Kemp, Systems Engineer. Cloudera, Inc. All rights reserved.

Efficient Troubleshooting Using Machine Learning in Oracle Log Analytics

Intel Public Sector 3

CASE STUDY Delivering Real Time Financial Transaction Monitoring

Business Value Delivery

Einführung in Amazon Machine Learning

SAP Predictive Analytics Hands-On. Andreas Forster December 2015

MANAGEMENT CLOUD. Leveraging Your E-Business Suite

Managing Identity Applications, Securing Databases with Oracle Management Cloud

An all-in-one risk management platform delivering fraud detection, transactions screening and customer due diligence capabilities

SIMPLIFYING BUSINESS ANALYTICS FOR COMPLEX DATA. Davidi Boyarski, Channel Manager

Machine Learning and Data Science for Performance and Quality Engineering. Gopal Brugalette Principal Software Engineer SAP Concur

Microsoft Azure Essentials

Developing Prognostics Algorithms: Data-Based and Model-Based Approaches

Operational Intelligence in Industrial Environments

C3 IoT: Products + Services Overview

Managing Identity Applications, Securing Databases with Oracle Management Cloud

WHITE PAPER EMBRACING THE STRATEGIC OPPORTUNITY OF IT

Predictive Analytics Reimagined for the Digital Enterprise

Oracle Management Cloud. The Next Generation of Systems Management

AXON PREDICT ANALYTICS FOR VXWORKS

EMBED ANALYTICS EVERYWHERE Tomáš Jurczyk

Turn predictability into productivity.

Splunk IT Service Intelligence

Transforming Analytics with Cloudera Data Science WorkBench

How it really works! Advanced streaming and edge analytics methods in industry 4.0 Dr. Nicole Tschauder, SAS DACH Industry of Things World 2018,

Control Anything. Gain Insights. Connect Things. Action. 10% of the data on earth will come from IoT by B connected devices by 2020

Evaluation of Machine Learning Algorithms for Satellite Operations Support

Data Analytics for Engineers

SAS Machine Learning and other Analytics: Trends and Roadmap. Sascha Schubert Sberbank 8 Sep 2017

Intel s Machine Learning Strategy. Gary Paek, HPC Marketing Manager, Intel Americas HPC User Forum, Tucson, AZ April 12, 2016

Pushing Configuration Bundles in an Indexer Cluster. Kartheek Kolla Software Engineer, Splunk Meema Esguerra Software Engineer, Splunk

Week 1 Unit 4: Defining Project Success Criteria

SAP Enterprise Threat Detection Overview & Roadmap. Martin Plummer, SAP SE November 2016

Monitoring mit modernen Cloud Services - Wo ist die Nadel im Heuhaufen?

Datameer for Data Preparation: Empowering Your Business Analysts

Microsoft Analytics: The Next Wave. Simon Lidberg Benjamin Wright-Jones Data Insights Center of Excellence

Hortonworks Connected Data Platforms

Asset Avatars. Get a 360-Degree View of Your Assets. By Hitachi Vantara

Advances in PI System Streaming Analytics and Other External Calculation Engines

Roadmap & Timelines & Solution Overiew SAP Asset Strategy & Performance Management

Who is Databricks? Today, hundreds of organizations around the world use Databricks to build and power their production Spark applications.

HP Operations Analytics

Forecasting in SAP Integrated Business Planning Webinar

Data Analytics with MATLAB Adam Filion Application Engineer MathWorks

PREVENT MAJOR DATA BREACHES WITH THREAT LIFECYCLE MANAGEMENT Seth Goldhammer, Senior Director of Product Management at LogRhythm

Managing Data in Motion with the Connected Data Architecture

Patrick Nicolet Automation

2 Analytics Reinvented

Digital Wind Operations Optimization from GE Renewable Energy. Enhance the performance and efficiency of your people and machines to drive outcomes

Transcription:

What s new in Machine Learning across the Splunk Portfolio Manish Sainani Director, Product Management Bob Pratt Sr. Director, Product Management September 2017

Forward-Looking Statements During the course of this presentation, we may make forward-looking statements regarding future events or the expected performance of the company. We caution you that such statements reflect our current expectations and estimates based on factors currently known to us and that actual events or results could differ materially. For important factors that may cause actual results to differ from those contained in our forward-looking statements, please review our filings with the SEC. The forward-looking statements made in this presentation are being made as of the time and date of its live presentation. If reviewed after its live presentation, this presentation may not contain current or accurate information. We do not assume any obligation to update any forward looking statements we may make. In addition, any information about our roadmap outlines our general product direction and is subject to change at any time without notice. It is for informational purposes only and shall not be incorporated into any contract or other commitment. Splunk undertakes no obligation either to develop the features or functionality described or to include any such feature or functionality in a future release. Splunk, Splunk>, Listen to Your Data, The Engine for Machine Data, Splunk Cloud, Splunk Light and SPL are trademarks and registered trademarks of Splunk Inc. in the United States and other countries. All other brand names, product names, or trademarks belong to their respective owners. 2017 Splunk Inc. All rights reserved.

Agenda Machine Learning Overview Splunk Machine Learning Toolkit (MLTK) Overview What s New in Machine Learning Toolkit? What s new in IT Service Intelligence ML? Splunk User Behavior Analytics (UBA) Overview What s new in UBA 4.0?

Machine Learning Overview

Machine Learning A process for generalizing from examples Examples A, B, # A, B,... a X past X future like with like X predicted X actual >> 0 (regression) (classification) (forecasting) (clustering) (anomaly detection)

How Machine Learning is surfaced across the Splunk Portfolio CORE PLATFORM SEARCH + Smarter Splunk PACKAGED PREMIUM SOLUTIONS ITSI, UBA MACHINE LEARNING TOOLKIT Platform for Operational Intelligence

Machine Learning Process Collect Data Deploy Clean / Transform Evaluate Explore / Visualize Model

Machine Learning Process with Splunk Collect Data Alerts, Dashboards, Reports Deploy Clean / Transform props.conf, transforms.conf, Datamodels, Splunkbase Evaluate Splunk Machine Learning Toolkit Model Pivot, Table UI, SPL Explore / Visualize

Splunk Machine Learning Toolkit platform extensions and guided modeling dashboards

Splunk Machine Learning Toolkit extends Splunk with new tools and guided modeling Assistants: Guide model building, testing, & deployment for common tasks Showcase: 25+ interactive examples from IT, security, business, and IoT Algorithms: 30 standard algorithms plus an extensibility API SPL ML Commands: New commands to fit, test, and operationalize models Python for Scientific Computing Library: 300+ open-source algorithms

Machine Learning Toolkit Customer Use Cases Reducing customer service disruption with early identification of difficult-to-detect network incidents Minimizing cell tower degradation and downtime with improved issue detection sensitivity Speeding website problem resolution by automatically ranking actions for support engineers Ensuring mobile device security by detecting anomalies in ID authentication Entertainment Company Predicting and averting potential gaming outage conditions with finer-grained detection Preventing fraud by Identifying malicious accounts and suspicious activities Improving uptime and lowering costs by predicting/preventing cell tower failures and optimizing repair truck rolls

What s New in MLTK? since last.conf

Detect Numeric Outliers improvements Preprocessing / Data Prep Model Management ML-SPL extensibility API Spark Support (private limited beta) New algorithms: ARIMA supported in Forecasting Time Series Assistant ACF & PACF Gradient Boosting Classifier & Regressor Load Existing Settings is per-user What s New (since.conf 2016) Downsampled Line Chart supports drilldown

Detect Numeric Outliers split-by support

Detect Numeric Outliers data distribution viz

Preprocessing build a pipeline of data prep In Predict Numeric, Predict Categorical, and Cluster Numeric assistants

Model Management (coming to MLTK 3.0) Provides Role Based Access Control to models Assign permissions to models to control who has what level of access Manage models via a rich UI interface

Make more algos available to fit / apply 300+ in PSC Custom algorithms Expose new or different parameters Docs include examples Correlation Matrix Agglomerative Clustering Support Vector Regressor Savitzky-Golay Filter Use in your apps / dashboards / etc.! ML-SPL Extensibility API featuring: primo documentation

Use your existing Spark cluster with MLTK Distributed fit on massive datasets Apply MLlib models for supported algos sfit / sapply Contact sparkml@splunk.com Spark Support private beta open now What is your use case (e.g., predicting server downtime)? Why do you want / need Spark (i.e., why isn t MLTK sufficient)?

Machine Learning Customer Success Network Optimization Detect & Prevent Equipment Failure Security / Fraud Prevention Prevent Cell Tower Failure Optimize Repair Operations Prioritize Website Issues and Predict Root Cause Entertainment Company Predict Gaming Outages Fraud Prevention Machine Learning Consulting Services Analytics App built on ML Toolkit

What s new in ITSI ML?

ITSI Smart Mode Event Co-relation and Clustering for Event Data Uses the Splunk Reverse Pyramid Clustering Algorithm to reduce noise in IT event data The algorithm extracts categorical and textual similarity from events and uses them in combination with a Service context to correlate events. Provides a UI based configuration editor that allows users to tweak parameters and tune configuration without a data scientist Not a black box explainability is built right in. All event groups created by the algorithm provide an explanation as to why events were grouped together.

Splunk User Behavior Analytics Machine Learning-based Threat Detection

Splunk User Behavior Analytics An out-of-the-box solution that helps organizations find Anomalous Behavior Risky Users Unknown Threats with the use of machine learning

Splunk User Behavioral Analytics Pillars Five Foundational Pillars Real-Time & Big Data Architecture Behavior Baseline & Modelling Unsupervised Machine Learning Anomaly Detection Threat Detection Platform for Machine Data

Network logs Identity logs Endpoint logs How Does Splunk UBA Work? Suspicious Data Movement Unusual Machine Access Flight Risk User Lateral Movement Suspicious Behavior Compromised Account Server logs Machine Learning Unusual Network Activity Machine Learning Data Exfiltration Application logs Machine Generated Beacon Malware Activity 45+ ANOMALY CLASSIFICATIONS 20+ THREAT CLASSIFICATIONS

How does UBA integrate with Splunk Enterprise and ES? Human-driven ML-driven Rules Correlations Statistics Machine Learning Behavior Analysis Risk-level Scoring Splunk Enterprise Investigate Known Threats Splunk ES Detect, Investigate & Respond Splunk UBA Detect Unknown Threats

What s New in UBA 4.0? Announced here at.conf

UBA SDK now available Proprietary logs Output from other UBA models Traditional logs Custom ML models(s) Custom Anomalies UBA Threat Models UBA Threat(s) Implement custom machine learning models to generate new anomalies and threats Custom Threat Models Custom Threat(s)

PII Masking also shipping now Obfuscate user details during investigation or hunting

Q&A Manish Sainani Director, Product Management Bob Pratt Sr. Director, Product Management