Splunk on Nutanix Clearshark Design Guide
Total Page:16
File Type:pdf, Size:1020Kb
Splunk on Nutanix ClearShark Design Guide UNLEASH THE POWER OF DATA WITH SPLUNK ON NUTANIX Simplified infrastructure management, proven performance, and fast time to value for Splunk deployments at scale. Advanced infrastructure and application automation ensure that Nutanix HCI keeps pace with growing Splunk requirements. Splunk Enterprise is the leading software platform for analyzing machine data gathered from IT infrastructure and equipment of all types. It is used widely in IT for a variety of purposes, including streamlining operations, compliance, security, and auditing. Because it operates on any kind of machine data, Splunk also has applications in industries such as financial services, healthcare, oil and gas, and manufacturing, including support for Internet of Things (IoT). Splunk lets you search, analyze, and visualize data gathered from across your IT infrastructure and your entire business, ingesting data from websites, applications, sensors, devices, and more. Once you define a data source, Splunk indexes the data stream and parses it into individual events that you can view and search. Use Cases Splunk is used for a wide range of use cases. This design guide focuses on three use cases that are widely deployed: Security, Business Analytics, and IT Infrastructure and Operations Management. Security. Enterprises increasingly rely on security incident and event management or SIEM to identify and protect against internal and external attacks. Splunk is widely used for security moni- toring, advanced threat detection, incident response, and a wide range of other security needs. Business analytics. Splunk analytics can allow you to discover, visualize, and explore business processes and customer experience data to gain greater visibility into end-to-end business processes. Splunk allows enterprises to analyze data streams to identify patterns, outliers, and trends and investigate the root cause of business problems to drive continuous improvement. Visual exploration can deliver greater transparency into critical business metrics. IT Infrastructure and Ops Management. Splunk unifies and correlates metrics and logs fora seamless infrastructure monitoring and troubleshooting experience, addressing the monitoring and observability needs of busy teams. Intelligent investigations make spotting trends and finding the root cause of server, OS, VM, cloud, and container problems easier. 2 Splunk Infrastructure Challenges As the amount of data increases seemingly without bound, the job of the Splunk architect has become more challenging. Reducing complexity, improving data security, and eliminating bottlenecks are top priorities that traditional infrastructure approaches are ill-suited to address. When it comes to analytics, the ability to extract value from data is paramount. Some data loses value quickly, making both ingest speed and processing performance critical. As the rate of data ingest grows, simply deploying and scaling resources to keep up can become painful and disjointed, limiting value gained. Splunk consists of three main components: • Forwarders. Collect data and send it to Splunk for indexing • Indexers. Ingest, index, and store the data received • Search heads. Distribute search requests to indexers Because each of these functions has different CPU, memory, and storage requirements, architecting an ideal infrastructure environment can be very difficult. Traditional approaches to Splunk and other big data infrastructure have become an impediment to continued success. Security Standards and Certifications Nutanix employs multiple security standards and validations programs. It complies with the strictest international standards, including the SP800-53 guidelines, to assure governments worldwide that Nutanix products perform as expected and work with their existing technoloy. 3 Why Choose Nutanix for Splunk? Nutanix takes the complexity out of managing infrastructure for Splunk. It allows Splunk Nutanix HCI simplifies infra- to take full advantage of server virtualization without the limitations of bare metal or structure management across virtualized solutions on traditional infrastructure, making it possible to quickly fine tune the entire lifecycle, automates the number and configurations of Splunk indexers and search heads. By ensuring data operations, and enables is accessed locally by all Splunk indexers, Nutanix eliminates the “I/O Blender” effect self-service to streamline that plagues storage systems in traditional three-tier infrastructure. Splunk operations. Splunk deployments grow rapidly as new data sources are added. With Nutanix, you One-Click Operations can start small and scale out without worrying about the bottlenecks that can occur Intelligent, one-click operations with traditional architectures: take the pain and effort out of daily activities, including soft- • Ingest terabytes of data per day. A compact 4-node, 2U cluster provides sequential ware installs, upgrades, and throughput of gigabytes per second. workload placement. Advanced analytics provide insigh into • Process millions of events. A 4-node cluster can process hundreds of thousands your Splunk environment, of events per second. giving you instant visibility into utilization, growth rates, • Scale incrementally. Start small and scale linearly as nodes are added. and other critical planning information. • Reduce TCO. Cut total cost of ownership by as much as 50%. • Shrink footprint. A good infrastructure design can reduce your Splunk footprint as much as 4x. Nutanix HCI provides linear scaling, so Splunk deployments can grow without worry. Find Out More: Each additional node delivers predictable performance to support Splunk search heads • Definitive Guide to Big Data and indexers. Because of its distributed architecture, a Nutanix enterprise cloud prevents • Nutanix Solution for Splunk one workload from starving another, allowing Splunk operations to share infrastructure • Virtualizing Splunk on Nutanix with other workloads if desired. Built-in capacity planning alerts your team proactively when additional capacity is needed to accommodate growth. 4 SPLUNK USE CASE 1: Security Information and Event Management (SIEM) Splunk provides an analytics-driven, modern SIEM solution for gathering security context in one view to facilitate rapid investigations and response. SIEM is resource-intensive and requires an experienced team to implement, maintain, and fine tune. It also requires high-quality data—the bigger the data source, the better the results. SecOps teams frequently want independent, isolated infrastructure that’s easy to manage and to scale since: • Complex infrastructure management hinders the provisioning and tuning of SIEM input. • Legacy hardware is difficult and expensive to compartmentalize for standalone deployments. Because of its built-in security and simple management, Splunk on Nutanix is the ideal platform to support SIEM, streamlining scaling and other infrastructure operations without sacrificing performance. The Nutanix architecture takes a security-first approach; built-in features deliver defense in depth so that your valuable data is always protected. Nutanix incorporates security into every aspect of the software development process, from design and development to testing and hardening. To ensure compliance, the Nutanix platform is certified under a broad set of evaluation programs. The result is a greatly reduced attack surface and safer data: • Built-in two-factor authentication, cluster lockdown, and software or hardware-based encryption • Secure installation and simplified security maintenance • Nutanix Flow for microsegmentation and enhanced network visibility • Deep integration with a broad ecosystem of security partners 5 Customers often dedicate a Nutanix cluster to SIEM for maximum isolation of critical security Splunk on Nutanix gives processes, but you can also deploy Splunk on shared infrastructure without sacrificing security. security experts more time to spend extracting insight Deploying Splunk for SIEM at Nutanix from data. The Nutanix cybersecurity team has been running Splunk on the Nutanix platform since 2017. The Splunk environment has had to scale rapidly to accommodate growth. Ingest increased more than 10x from 2017 to 2018—to more than 1TB per day—yet the Find Out More: node count only increased 3x. • Big Data and SIEM for Federal Agencies (Webinar) Prism management enables the team to address events quickly without involving the • Essential Security Planning infrastructure team. Memory, CPU, and storage capacity can be added with just a few for Private Cloud clicks, allowing issues to be resolved in moments. • Nutanix AHV: Security at the Virtualization Layer The Nutanix presentation from Splunk .conf19 has more details. • Protect Your Apps and Data 6 SPLUNK USE CASE 2: Business Analytics Splunk can discover, analyze, visualize, and monitor event data from any source. Splunk business analytics lets you combine machine data and traditional structured data to gain greater business insight. Every business process and every line of business across an enterprise can see potential benefits. For example, a small deployment might be used to tackle an issue on a production line or for a proof of concept deployment on a factory floor. A remote deployment faces unique challenges such as scaling equipment to handle significant amounts of data in limited space in less-than-ideal conditions, that are impossible for a traditional three-tier solution to address. With advanced HCI and capacity