Splunk jumped back into the cloud and machine learning pool this week with a cannonball of new capabilities to Splunk Cloud and Splunk Data Stream Processor (DSP) as well as other updates to the core Splunk platform that aim to strengthen real-time stream processing. 

"It is now more apparent than ever that cloud is an essential element needed for businesses to continue to operate and grow," said Josh Klahr, Splunk's VP of product management.

With the updates, Splunk intends to provide developers and IT leaders a unified set of tools to monitor and observe data in real time regardless of the infrastructure or data volume. 

According to Gartner research cited by Splunk, more than 75% of global organizations will be running containerized applications in production by 2022. That number is fewer than 30% today. Moreover, IDC expects SaaS-based offerings in application performance management to grow at triple the rate of on-premises services during the next five years.

The move to containers, Kubernetes, and microservices is filled with as many advantages as it is rife with challenges. A particularly stubborn challenge is the shift away from traditional monolithic methods of monitoring to an infrastructure on which applications run in dynamic environments. 

And this transition to cloud-native environments means there is a much larger volume of data to make sense of – and that’s good news. Data has the potential to be one of the most valuable assets to an organization – if  it knows how to understand and leverage the power of that data. 

That’s where artificial intelligence (AI) and machine learning (ML) come into play.

Splunk Cloud

Managing multiple data centers had heads spinning long before the spread of COVID-19 and the resulting global public health guidelines forcing people to work from home. Shoring up distributed computing complexity is an important task for the cloud ecosystem, but not the only one that continues to hinder broader deployments. 

"COVID-19 is accelerating existing trends and transformation already in flight," Klahr said. "Data volume and velocity was already on the rise, but its pace will likely accelerate, making it critical that organizations are prepared for an influx of new data."

While AI and machine learning probably won't completely take over the world within the next five years, Splunk made moves in that direction with updates to its Machine Learning Toolkit (MLTK). New to the MLTK is a simplified, customizable interface, visualization capabilities, and a new family of Smart Assistants offering step-by-step guided workflows. Version 5.2 aims to make the tool accessible to a broader audience. 

The vendor introduced Splunk IT Service Intelligence (ITSI) 4.5, a centralized framework for monitoring and investigation with increased capacity for service and event management to support large deployments. ITSI 4.5 aims to support customers moving to multiple data centers in the cloud and “embrace their growing data sources.”

Data-to-Everything Update

Splunk also strengthened the streaming capabilities of the Data Stream Processor (DSP) tool on its Data-to-Everything Platform. DSP is a real-time stream processing product that continuously collects high-velocity, high-volume data from diverse sources, uses this data to provide insights, and then distributes results to Splunk or other destinations typically within milliseconds. It can also mask sensitive data to protect critical information that could impact a business. 

Splunk says DSP 1.1 gives users advanced control, visibility, and insights with the ability to collect data in a single, unified location. Once the data is collected and stored, DSP leans on its acquired SignalFx technology that uses a combination of AI and ML to connect the dots and drive relevant information to the surface, thus allowing DevOps teams to spend less time searching for the source of the problem.

The vendor says the newly added masking capability enables organizations to conceal customer or sensitive information on the stream and then route data to different locations within their organization with data guarantees.