While at Cisco GSX, I ran into Travis Kane (a.k.a. Trav) over at the AWS booth. He has built a hands-on workshop that steps you through the technical bits of setting up Amazon S3 with Splunk Federated search so that you can search data in-place without bringing it to Splunk. In other words, we’re bringing Splunk to the data rather than bringing the data to Splunk!

Transcript

Auto-generated captions, lightly cleaned. Speakers are not separately labeled.

Hey everybody, we’re out here at Cisco GSX and been talking to Trav here about Amazon and federated search and you have a whole workshop that you put together about doing all this. Can you tell me what went into that workshop? >> Yeah, sure Jason. So one of the challenges with federated search for Amazon S3 for Splunk is understanding the Amazon side of that fence. So you need to know things like Athena blue how they interoperate with S3 in that way to make it an effective use case for a Splunk user. So I built this workshop up where customers or users of Splunk can go into the platform actually configure all the Amazon bits to really get hands-on and how to actually effectively use that platform for its most intended purpose of those use cases. So you’re probably wondering how do we actually use this workshop? It’s free to anyone who wants to use it but you got to hit up your Amazon SA. they can uh spin it up for you and we can spin up the splunk side and actually get hands- on. Probably takes about 2 to three hours actually. So, it’s very detailed, very hands-on. >> Yeah, that’s really cool because I’ll steal a line that we learned this week is it’s no longer bring your data to Splunk. We’re bringing Splunk to the data where it lives and this workshop really stepped you through hands-on how to do that, right? >> Absolutely. Yeah. So, you really get hands-on in there. You get an Amazon console, you get a Splunk console, you get to configure the Amazon S3 connectivity into there as well. I get to run some searches based on actual what I think would be good use cases on typical types of sources. Uh most customers are trying to understand what’s the best type of data source that be applicable to federated search >> and so we actually step through that in the workshop as well. >> Right. And so contact your Amazon SA contact your Splunk essay. How do you do this? >> Yeah, definitely. So um on the Amazon side, so it’s in their their sort of workshop platform called workshop studio. So hit up your Amazon SA. uh they have access any SA has access to that platform and then head up the Splunk side or if you even have a Splunk instance already with federated search enabled you can just join them together with the workshop all the steps are on Amazon workshop side so otherwise head up a splunk person they can spin up one for you as well fantastic thanks so much thanks [Music]