Given Splunk Enterprise is a flexible operational intelligence platform, our users adopt it in various forms: from using it as a cloud service with Splunk Cloud, to deploying it on-premise in their own datacenter, or in their own cloud environment such as AWS.
Since Splunk is about turning machine data into valuable insights in as little time as possible, we always strive for that speed element in all aspects of our product usage:
“80% of my time used to be spent on setting up Splunk, now I spend 80% of my time getting value out of Splunk”
Abdallah Mohammed,
Data Architect, Intuit CTO Dev
In that same spirit, we’re delighted to announce the release of Splunk AWS CloudFormation templates as a friction-free self-service tool for fast Splunk deployment in the cloud.
Conventionally, deploying a self-managed distributed Splunk cluster requires advanced Splunk administration & deployment knowledge in addition to DevOps resources. With Splunk AWS CloudFormation, any Splunk user can now deploy a pre-configured Splunk distributed cluster in their own AWS environment in matter of minutes, not hours or more. More specifically, in less that 30 minutes, any individual or company with an AWS account can create a complete infrastructure equivalent to the one shown in the diagram below which depicts a dedicated virtual private cloud with a Splunk cluster:
Abdallah Mohammed, a Data Architect at Intuit, leverages Splunk AWS CloudFormation for internal Splunk deployments within the CTO Dev organization which drives Intuit’s technology principals and shared assets across Business Units including Small Business Group and Consumer Tax Group. “80% of my time used to be spent on setting up Splunk,” said Mohammed, “now I spend 80% of my time getting value out of Splunk by building data models, searches & dashboards. What used to take days to get all configured, now I can do in few minutes with Splunk [AWS] CloudFormation”.
Splunk CloudFormation templates can be found on GitHub.
To get up and running with your own Splunk cluster, follow the simple step-by-step guide using an existing AWS account. Here are the main templates (Click on template link to launch it directly in AWS CloudFormation):
You can use either a simple push-button form (shown below) through AWS CloudFormation console, or the command line via AWS CLI if that’s your preference. Either way, you can change a few parameters to customize your deployment, in particular :
Splunk AWS CloudFormation templates are provided by Splunkers for Splunkers. It is not a supported product or service, rather an open source technical enablement piece. So we encourage you to extend these templates any way you see fit, and leave us a note below on how you’re using them. There’s an increasing list of requested features…What feature would you like to see?
----------------------------------------------------
Thanks!
Roy Arsan
The Splunk platform removes the barriers between data and action, empowering observability, IT and security teams to ensure their organizations are secure, resilient and innovative.
Founded in 2003, Splunk is a global company — with over 7,500 employees, Splunkers have received over 1,020 patents to date and availability in 21 regions around the world — and offers an open, extensible data platform that supports shared data across any environment so that all teams in an organization can get end-to-end visibility, with context, for every interaction and business process. Build a strong data foundation with Splunk.