SplunkLive! Utrecht - KPN

15
Bringing IT Operational Intelligence to KPN [email protected]

Transcript of SplunkLive! Utrecht - KPN

Page 1: SplunkLive! Utrecht - KPN

Bringing IT Operational Intelligence to KPN

[email protected]

Page 2: SplunkLive! Utrecht - KPN

KPN OverviewImprove the quality of our services using the right tools

GoalsKPN Largest Dutch Integrated Service

Provider. 14,077 Employees Only Dutch Telco able to offer a wide

range of ICT services.

Page 3: SplunkLive! Utrecht - KPN

Our team within KPN Improve the quality of our services using the right tools

GoalsKPN Part of Business Operations –

Business Continuity & Improvement

35 Team members

5 members for Operational Analytics

Page 4: SplunkLive! Utrecht - KPN

My Background

GoalsGoals

The city I call home : Enschede

Age : 30

Working @ KPN since : 2011

Before KPN : IT Consultant for a outsourcing company.

Page 5: SplunkLive! Utrecht - KPN

How we got startedKPN’s Fast Forward program

Goals

KPN Started Fast Forward in 2015.

Fast Forward is meant to improve turn around times & automate simple and complex operations.

Datalake was a part of the Fast Forward Program.

Page 6: SplunkLive! Utrecht - KPN

Raising the barTaking successful strategy to the next level

InnovateGrow

Simplify

Strengthen

Digital & simple service and delivery

Converged Telco & IT services

Excellent user experience

Flexible & simplified networks and operating model

Best-in-class secured integrated networks

Applying innovative technologies

Commercial

Operational

SIMPLIFY GROW INNOVATE

Page 7: SplunkLive! Utrecht - KPN

How we got startedDatalake

Goals

Situation Struggles Wanted Fast Forward needed

to implement a centralised datalake for all Operational Data.

Preferably based on HADOOP

Data across different tools.

Operational Reporting not standardized.

Splunk used as a tool for capacity management on one platform.

Centralised datalake based on HADOOP so all Operational Analytics can be done from a central place by all teams within Business Operations

Page 8: SplunkLive! Utrecht - KPN

How we got startedFirst design

Goals

Situation Struggles Wanted Hadoop as central

platform Flexibel

Not realtime

Multiple components to manage

Pro’sSituation

Con’s

Page 9: SplunkLive! Utrecht - KPN

Enter Splunk Enterprise @ KPN

Goals Single platform to

manage. Ease of use. Scalability. Realtime.

Licensing

Pro’s

Con’s

Page 10: SplunkLive! Utrecht - KPN

Tooling & Automation EcosystemA high-level overview

JENKINS BEAKER VMPOOLER vCenter

Master

AgentsVERSIONCONTROL

Operational Intelligence

Sync

Web Hook

Data

Customer Teams

InfrastructureTeam

Module DevTeam

PuppetDB

FEEDBACK

Automated Testing

Repo

Page 11: SplunkLive! Utrecht - KPN

Operational Intelligence with SplunkKnowledge is power

Nodes Platforms Applications Modules Module versions Puppet run info Nodes in NOOP mode Puppet facts Configuration Changes GitHub commit details Capacity Management Patch Management Compliancy Real Time Troubleshooting

Dashboard

Page 12: SplunkLive! Utrecht - KPN

Current state and lessons learned

Current State

Technology 50 Billion events……and counting! 60+ Sources 1 Million+ page viewsPeople

250 active users 27 Custom KPN apps 579 Dashboards Our apps and dashboards

provide +- 1500 people with insights

Lessons Learned

Prepare a well designed and structured POC.

Start with a well designed Splunk architecture.

Be prepared for a major demand for insights!

Page 13: SplunkLive! Utrecht - KPN

Whats next!Strengthen and improve

Roadmap Items

Infrastructure Currently migrating to a scalable indexing cluster and

searchhead clusters.

Analytics Improve Splunk integration Expanding the scope to different parts of KPN.

Collaboration Integrate with our other tools such as Jira and HipChat.

Page 14: SplunkLive! Utrecht - KPN

Top Takeaway

Stop over planning, Start Splunking!

Focus on quick wins to show what you can do with Splunk

If you want to be an engine for change make sure you’re a diesel!

Page 15: SplunkLive! Utrecht - KPN

Thank you! Questions?

And please join the official splunk usergroup @ usergroups.splunk.com