-
hello and welcome to the advanced Funk
-
dashboard in Showcase with me Dan
-
Gray I'm a qualified to blun architect
-
with some oford Associates I've been
-
working here for a year now and prior to
-
that I was in the Raw na for eight years
-
where I worked as a computer network
-
analyst so who are
-
sum specialist in everything Splunk and
-
we are an elite partner for licens and
-
Professional
-
Services uh we also offer workshop and
-
webinars such as this and if you're a
-
customer of ours you have access to the
-
dedicated technical support
-
l so what's the agenda of this webinar
-
so we're going to learn to make smart
-
and interactive dashboards of real data
-
are repealing uh that will help us
-
graphically illustrate our it operations
-
data using complex graphs and CHS but
-
really what we're going to do is we're
-
going to make simple effective
-
dashboards that communic
-
what you want to communicate across to
-
the end
-
user we're going to try and take
-
dashboards from this which is uh an
-
example of a bad dashboard that I've
-
made uh it's very cluttered not very
-
colorful it's really unclear what's
-
going on um but first look there's some
-
information in there we can see that
-
stuff's happening actions products are
-
being viewed uh and removed from carts
-
and stuff's happening really ineffective
-
grph
-
no accesses No
-
Labels um tables are not formatted
-
correctly uh really not a good example
-
of an effective
-
communication um of the data that sits
-
behind this dashboard I'm going to try
-
and take it from
-
that so something a little bit more like
-
this um this is using the same data
-
however hopefully it's a little bit more
-
illustrative of what's going on um we've
-
got revenue we've got graphs we've got
-
tables single value figure
-
um and a bit of color in there that
-
makes it a little bit more
-
digestible but before we are able to
-
make a dashboard we have to get started
-
with smunk if you've never used smun
-
before it's really straightforward to
-
get going head to the website and make
-
an account download the latest version
-
of SP Enterprise install it and then add
-
data and Away you go um when I say Ad
-
data anything that's human readable spun
-
can ingest and make sense of um whether
-
that's the logs from your own PC that
-
you're logging in or um you can get data
-
sets online such as uh the New York taxi
-
companies they' publish uh information
-
about taxi Journeys uh Eve online the
-
computer game you can get uh data dumps
-
from activities that have happened in
-
the game to help you um play around with
-
Splunk if you've not got access to um a
-
large computer network or or another
-
data source there's stuff resources out
-
there online where you can take data and
-
and get it into spun and then start
-
learning and playing around with
-
it once you've installed Splunk this is
-
what you'll be faced with um this is the
-
homepage looks a little bit different in
-
Version 9 um but all the same features
-
are there product tours uh really
-
straightforward navigation through the
-
guies of whichever product you've
-
downloaded adding data the most
-
important button um this is where you
-
really start
-
getting anything out of Splunk is by
-
adding different data sources as I said
-
it has to be human readable um but you
-
can take Network information logs events
-
and
-
metrics um Splunk apps that will take
-
you to Splunk base a website it's a
-
repository of apps uh and in in Splunk
-
apps means um a bundle of configuration
-
files
-
um there are apps for for numerous
-
different products um
-
any if you want to ingest a data source
-
the first place to look is on spun base
-
and see if someone's done the hard work
-
for you
-
already and then finally Splunk docs
-
it's the documentation for Splunk um
-
really well uh
-
maintained uh organized and makes sense
-
if there's uh something that you'd like
-
to do in Splunk it's very likely that
-
you'll be able to find out how to do it
-
by looking through the SP
-
documentation but this webinar is about
-
dashboards so how do we make a
-
dashboards so click on um the dashboard
-
button primarily and then next button
-
you'll click is create dashboards and
-
you will be faced with this P popup
-
here this is where you set the
-
parameters for the dashboard you're
-
making so um things that you need to
-
fill in um are the the dashboard title
-
the permissions whether they're using
-
classic dashboards or dashboard
-
studio in this webinar we'll be using
-
dashboard Studio
-
um classic dashboard and dashboard
-
Studio have different
-
functionalities um dashboard Studios the
-
newer version the newer offering by blun
-
and they're working to catch up with
-
some of the functionality from classic
-
dashboards um dashboard Studios also has
-
extra functionality that you can't get
-
in classic dashboards and as I said this
-
webinar will be using dashboard studio
-
so we'll see some of the functions and
-
uh settings and stuff that we can use
-
that are exclusive to dashboard
-
studio uh and finally absolute or grid
-
uh uh layout mode what that means will
-
be really much more obvious once we get
-
into editing the dashboard um but as it
-
says there if you choose absolute layout
-
you get full control of where you want
-
to place your panels whereas grid um
-
snaps to
-
location but before you do that start
-
with a
-
plan uh before making any dashboard you
-
want to go to your end user recustom
-
customer or if it's working on your own
-
behalf have a good think about what you
-
want this dashboard to show um this is a
-
really quick one that I knocked up in
-
Microsoft Paint um however this is the
-
sort of thing that I'd like to receive
-
from a customer at this point I'm not
-
particularly interested in what sort of
-
Spun queries um they want to run in the
-
background what I want to know is what
-
do they want their dashboard to show and
-
leave it up to me to figure out how to
-
to make that
-
work so on the left we have Hospital
-
dashboard um high level overview info
-
about number of patients um records
-
power and detailed View and a couple of
-
notes on the bottom make it look Sleek
-
include color coding and on the right
-
car a car factory example so if we keep
-
those two plans in our mind as we go
-
through we're going to see those
-
materialized to life as I said at this
-
point I don't want to know about the
-
data that powers these dashboards nor
-
the spunk searches that we'll need to
-
run to get it working I really want to
-
know what the customer wants out of
-
their
-
dashboard once you've got that um
-
perhaps
-
counterintuitively the first thing that
-
I suggest you do when making a a
-
dashboard is add a
-
background um the background can really
-
provide skeleton of your dashboard um
-
and it can really add context to the
-
data so here are a couple of
-
dashboards that we have uh prepopulated
-
perfectly fine dashboards not too busy
-
quite colorful um well labeled and make
-
sense but they could be taken to the
-
next level by adding a dashboard and
-
we'll see how just
-
now so here we have uh the left
-
dashboard without the u
-
background as we transition to the
-
background as we had in our planets
-
hospital um theme dashboard and we can
-
see that these lines that are connected
-
up the data these are part of the
-
background so the color lines and the
-
boxes are all part of the background
-
image um and we can really see how that
-
adds context to the data that we're
-
presenting next we
-
have um a car factory so instead of
-
um the bare panels we can we can arrange
-
those panels into uh the along the
-
background that makes sense and and at a
-
glance we can see um that this is to do
-
with production lines and where
-
[Music]
-
um where the data sits on that
-
production line so where the problems
-
may
-
occur so to do that how to add a
-
background here we have uh our view
-
after we've created a new dashboard
-
we'll be looking over here uh create a
-
background image so you can drag and
-
drop a an image file um and it will load
-
and and and be populated into your
-
dashboard or else you can add a URL
-
um out of the box there's a there's a
-
number of configured Whit list Whit
-
listed um URLs that SP will use to
-
populate backgrounds uh and those are
-
all spun
-
related if you have a website like we do
-
some for associates um you'll have to
-
whitelist that website in able to to get
-
your um image populating your
-
dashboards
-
so here I've used the URL that one of
-
the Splunk ones and um here's a good
-
point to to bring in some context to
-
this webinar we'll be using data that's
-
themed around a company called butterup
-
games this is the butterup games U
-
background but Cup games sell all sorts
-
of different things um nerdy apparl
-
games and things associated with those
-
um and we'll see the theme of that as we
-
go through the dashboard
-
uh so we've added the background and we
-
can see now that skeleton of of what we
-
want our dashboard to look like um it
-
will help in when we're arranging our
-
panels um where we want to put
-
them so how do we add our panels um well
-
the first thing to think about is the
-
best way to visualize the data that you
-
are trying to present whether that's
-
going to be a pie chart or a table or a
-
barop the location of panels and
-
orientation of panels those go Ahad hand
-
in hand um you want to try and tell a
-
story a logical story in your in your
-
dashboard um try and keep related things
-
nearby and make it simple for the user
-
to follow uh very importantly don't
-
overload with
-
information so how do we add a panel so
-
there's a few different ways you can do
-
it directly from the dashboard but in
-
this case we are doing it from a search
-
we've run so search is not
-
the um the topic of this webinar so we
-
won't dig too much into the search that
-
we have run suffice to say that I've run
-
a search here in Splunk and presented um
-
and ended up with a table so what you
-
need to do is you save
-
as over here and say it as an existing
-
dashboard and then simple as find your
-
uh dashboard make sure it's
-
ticked give it a panel title it's there
-
as optional uh it's definitely best
-
practice to give an a panel title that
-
really explains what that panel's going
-
to
-
do and then press save to dashboard and
-
there we
-
are we've added our first panel to our
-
dashboard um it's fine we can see there
-
we've got products we've got purchases
-
and the revenue that we're generating
-
off those
-
products um but we might be able to
-
improve it by using a
-
few uh formatting options so there's
-
loads and loads of formatting options
-
when you come in to make a panel and
-
dashboards themselves for that matter
-
some of them are on the screen now and
-
when we go to the live portion of the uh
-
of the webinar where I go into some
-
different dashboards we'll have a look
-
at some of the formatting options there
-
um but for this
-
case here's the same table after using
-
some formatting
-
options um I've used color for the for
-
the purchases to illustrate whether um
-
those are good numbers or bad numbers uh
-
and then added a couple of pound signs
-
there as well just to to show that
-
that's
-
um
-
money next um adding more panels so the
-
different types of panels that you can
-
add some of the different format and
-
options um choose your visualizations to
-
suit the data panel titles don't forget
-
those chart type and the time range
-
picker that will show you how far back
-
in time you want your dashboard to look
-
and drill Downs is an advanced or a more
-
advanced formatting option where
-
you can set the behavior if you click on
-
each panel what that behavior will do
-
we'll talk about that more in a
-
minute so I've just trucked a new panel
-
um this time a pie
-
chart continue to add panels to our
-
dashboard
-
um a few different visualization types
-
now we've got tables we've got pie
-
charts and we've got a stacked car chart
-
uh and finally down there on the bottom
-
right a single
-
value
-
uh don't forget to save your dashboard
-
as you're going through as we can see
-
there success dashboard saved um make
-
sure you save your dashboard as you go
-
along because if you navigate away from
-
it you might lose your
-
progress here we've added an image um of
-
the sum logo because I wanted to
-
illustrate um the drill down mechanic
-
that you can add to a
-
dashboard so how do we do that so we
-
click on the the image in this case or
-
um the panel or the object within the
-
dashboard and on the right hand side
-
you'll get a an options thing to
-
configure your um object and in our case
-
we're going to add a drill down so there
-
we go drill down settings add a drill
-
down um and then you've got onclick
-
options so there's stuff such as link to
-
another
-
dashboard uh link to a search um and you
-
can decide whether you want that in a
-
new tab all the tab that you're already
-
in um in our case we're going to link to
-
a custom URL so I've linked it there to
-
uh the summerfood website so when the
-
end user is using this dasboard if they
-
click that image they will navigate to
-
Summerford Associates
-
website I'll move on over now to the
-
live portion of the demo in which we're
-
going to have a look at three different
-
demo environments that we've spun up in
-
Splunk that are populated with fake um
-
fake
-
data but there's a there's a number of
-
dashboards that we can have a look at
-
and we'll see um some of the good and
-
bad points of those
-
dashboards so the first one I've clicked
-
into here Financial crime is the theme
-
of this
-
dashboard
-
um this is the what I would say the
-
executive summary page of this uh this
-
environment so the control room as it's
-
called um here we have uh a number of
-
panels uh that are well uh labeled so we
-
can kind of tell what's going on at a
-
glance we can see different accounts
-
there that are important um and a number
-
of different
-
visualizations in these environments
-
that spun's been up as demo sometimes
-
they use um use a visualization that
-
might not be the most uh applicable to
-
the data but mainly because they want to
-
just show off some the different uh
-
visualizations that are
-
possible uh but all in all not a bad
-
dashboard I would say at the top here we
-
could probably use a bit of color number
-
of potential account takeovers um 21 is
-
that good is that bad not too sure and
-
again they could have had trend lines
-
are we going in the right direction or
-
or or bad Direction um for this one I
-
wanted to show pretty sure they've added
-
uh the drill down so that's going to
-
open in a new tab it'll bring us to the
-
account takeover
-
dashboard um
-
enabling the analysts who who will be
-
using this to to dive deeper into the
-
account takeovers happening in this
-
environment again um lots of high level
-
stats across the top are they good are
-
they bad it's not clear whether
-
858 is a is a good number or a bad
-
number so they could have a bit of color
-
there and again a trend
-
line um here's one that we haven't
-
touched on yet mapping um you can add
-
maps to SL different types of maps
-
chloropleth
-
maps is this one and you can see
-
[Music]
-
there it's connections from Risky or
-
unusual countries so in your business if
-
you're expecting everyone to log in from
-
the UK or perhaps America and you're
-
getting a bunch of um loging attempts
-
from China that's probably suspicious
-
maybe something to have a look
-
at uh as we scroll down it's quite a
-
large dashboard but this I would expect
-
would be more for the analyst who's
-
actually working on it rather than
-
someone uh looking for a high level
-
overview we move on to
-
um the transaction fraud
-
page here we are again yeah so similar
-
sort of thing high level stats at the
-
top followed by uh a number of different
-
visualizations chart here with a trend
-
line on
-
um good use of different colors I
-
suppose the one I really wanted to show
-
off on this this one was the risk model
-
clustering
-
um takes a little while to load and
-
we'll see why once it actually
-
loads uh this I think in my opinion is
-
trying to be too clever um looked really
-
cool we have a 3D model of a of a risk
-
model that's moving in through 3D space
-
so there's there's a third access to
-
axis to this graph and as I said it
-
looks super cool it's different colors
-
and different things but it's not clear
-
to me at all what this graph is trying
-
to convey so um I guess the point I'm
-
trying to make there is make sure that
-
your end user understands don't go for
-
call points make sure that the end user
-
understands what which one I get
-
across they jump out of the financial
-
crime now into a to a separate
-
environment
-
um back to butterup games this is a
-
really good um example of a dashboard
-
actually very impressed with this
-
one the reason I set this um environment
-
up is because it had a really good
-
dashboard and a really bad dashboard um
-
but they've removed the bad dashboard
-
and they've left the good dashboard so
-
we'll give them some points and and tips
-
um or we'll talk about it a little bit
-
um it's not too busy this is the
-
entirety of the dashboard really good so
-
we can see customer locations it's
-
really obvious from uh the panel title
-
and the and and and the map what's going
-
on here um and then again really
-
straightforward use of
-
color the top country um and as you
-
click through it goes from yellow
-
through to red and the best thing about
-
this dashboard here is this um panel
-
here so they've used this panel as a as
-
a way to has a token through to the
-
graphs below so it's not really obvious
-
because the numbers don't jump around
-
too much um but as you click on each of
-
these
-
um operating systems the graphs below
-
change so to to reflect only that um
-
operating system so we can see here
-
Windows customers um have this level of
-
spending versus Linux customers
-
who have that level of spending um it's
-
a really cool Advanced feature um of the
-
dashboard using the panel to pass a
-
token through Pass information down to
-
other panels in the dashboard and act as
-
a as a very fancy filter so reset it
-
there back to
-
all the other dashboard in this
-
environment is the site status dashboard
-
again really impressive with really
-
impressed with this one um green and red
-
truly we know what those signify uh
-
green is good and red is is is bad um
-
again not too busy this is the entirety
-
of the dashboard here so we can see that
-
the site status um well we can see the
-
site status at a really quick glance um
-
successful versus unsuccessful and then
-
we can see the types of errors here that
-
are uh being reported and we can see
-
again the use of color that the very
-
deep red uh indicates that it's more
-
severe so again very effective dashboard
-
here simple use of color uh simple
-
number of panels even I as a non-web
-
developer can see that uh what's going
-
on
-
here and what's good and what's
-
bad uh the final dashboard that we're
-
going to have a look at or the final
-
environment that we're going to have a
-
look at is the infos SEC application and
-
the series of dashboards that I built in
-
there the infos app is a free app that
-
you can download from splint base uh as
-
I said before apps there a bundle of
-
configuration files that come
-
prepackaged along with a bunch of
-
dashboards and searches that that power
-
those dashboards um you can download
-
this from splint base for free all you
-
need to provide is the data to power
-
these dashboards and it will work just
-
as we're going to have a look
-
at the first one we're going to take a
-
look at is the executive view here we
-
can see a very high level view uh of
-
what's going on in this environment
-
story of this environment is that this
-
this network has been attacked now has
-
on it we can see here from across the
-
top uh red and blue uh attacks being
-
stopped and malware that has been
-
blocked in the last 24 hours and the
-
number of devices protected on the right
-
uh this dashboard is not very
-
interactive and I think that's probably
-
a designer's deliberate Choice um
-
because it's designed for the executive
-
view exactly as it says
-
um and you don't want to over that you
-
want to keep it very high level make it
-
very clear uh what's going on so that
-
the decision maker can make the decision
-
they need to
-
make next we'll take a look at security
-
posture a little bit more detailed uh
-
lots of different visualizations in this
-
one again the use of color they've used
-
red and blue here
-
um these are showing up as red because
-
considered as bad um if the the number
-
was different
-
it wouldn't be red and you can configure
-
those thresholds however you'd
-
like um like I said number of different
-
visualizations bar charts and graphs
-
here we don't have so much information
-
in this because it's a demo environment
-
it's just been spin
-
up
-
um going through to uh the network
-
traffic dashboard this is a good one to
-
look at um this is the one that really
-
tells the story of this
-
environment number of different tables
-
and different visualizations with
-
effective color format
-
in um this is the panel of Interest I
-
wanted to show for this demo using these
-
um boxes here we can filter to different
-
things and there's a nuer numerous
-
different ways to do that we can type
-
right in there currently populated with
-
an asteris which is the Wild Card
-
character for Splunk which means
-
everything um or we can click down in
-
this table here click on bit torrent and
-
that will populate the filter here at
-
the top and then we'll see all of the
-
hosts and information specific to the
-
bit torran um
-
app we can see here uh not important for
-
this time but what we can see is that
-
there's a number of hosts that have been
-
using bit torrent and accidentally
-
downloaded some
-
malware um but from the dashboarding
-
point of view we can see the different
-
sort of panels and formatting options
-
and the different ways to add different
-
filters um and how to populate those
-
filters by using the drill down
-
actions next one I wanted to take a look
-
at is under the advanced uh threats Tab
-
and network
-
anomalies this panel uh down at the
-
bottom is one of my favorite panels that
-
I get to show off because it
-
shows as it
-
loads access anomalies rather because it
-
shows uh one of the real powers of
-
Splunk it's taking information from
-
disperate data sources and giving you
-
conclusions that you might not have been
-
able to find if you were um operating in
-
data signers so here we have
-
geographically improbable
-
access um we can see here that the user
-
eford was in the city of gizer in Egypt
-
and then a very short time later he was
-
in Japan um just for a bit of
-
information a bit of fun you can see
-
there the speed at which he may have had
-
to travel to to make that condition true
-
he'd have to have moved around the world
-
at uh 1,281 miles hour and
-
Splunk is flagging up that it's very
-
improbable that this one guy is in these
-
two places at such close um period of
-
time and what I said about bringing data
-
together and not keeping it in silos so
-
in one um data repository you have the
-
fact that efield has logged in uh and in
-
another data C you have geographic
-
information and you stick those two
-
together and you can see here that this
-
guy is probably not withen around the
-
world like Superman and you may have uh
-
the indications of a compromise of this
-
account um that's all I wanted to show
-
in in the infos SEC application so we'll
-
go back to the PowerPoint
-
um so last thing I wanted to speak about
-
is the upcoming events um sum food are
-
always running workshops and events if
-
you want to find out what's coming up uh
-
navigate over to the website and have a
-
look um suit associates.com SL events
-
and we can see here the specific Splunk
-
events but we do do um events and other
-
Technologies too uh check out all the
-
upcoming webinars and workshops that
-
we're
-
hosting and if you want to join uh just
-
click on the register button and
-
sometimes you even get a little uh
-
goodies if you
-
join if you have any questions please
-
feel free to uh email info suf
-
associates.com that's questions about
-
Splunk or dashboarding specifically but
-
also any wider questions about sumed and
-
spun in
-
general thank you for attending this
-
webinar uh it's been a pleasure to speak
-
to you about dashboarding hopefully you
-
learn something and uh for now
-
goodbye