Skip to main content
 
Splunk Lantern

An introduction to the Splunk Success Framework

 

Learning how the Splunk Success Framework (SSF) is organized can help you identify the parts of the framework that apply best to you and your organization. All of the best practices in the SSF are modular, so you can apply them any time, according to your needs and priorities.

The Splunk Success Framework (SSF) first introduces you to some Fundamentals -  best practices that help you ensure success from the start.

It then takes you on a journey through four Functional areas - Program, People, Platform, and Data.

It also gives you guidance that aligns to your Adoption level, whether you're looking to implement standard, intermediate, or advanced best practices.

Fundamental best practices

clipboard_efefc543d33c9d52bba453f4e89aa5460.png

Fundamental best practices are decisions, agreements, and success criteria that establish the purpose, goals, and ownership of your Splunk implementation. These tactical decisions provide clarity and accountability that are essential elements of a successful deployment. The Splunk Success Framework lays out four fundamental best practices:

The fundamental best practices set expectations with stakeholders and ensure that your Splunk implementation stays on track and can grow and expand along with your needs. 

Functional areas

clipboard_e7c07456be2b4f01b21e6e89083d67280.png

Best practices for implementing Splunk are organized into four functional areas:

  • Program Management. Best practices for program management support how you conduct your Splunk implementation to drive adoption and realize maximum value from your Splunk deployment.
  • People Management. Best practices for user management enable users and teams by using learning incentives and role-based access to features and data.
  • Platform Management. Best practices for platform management support the availability, scalability, and maintainability of your Splunk deployment.
  • Data Management. Best practices for data lifecycle support efficient data management practices and generate effective use cases that are tightly aligned to data.

Adoption levels

Screenshot 2023-10-11 at 2.33.49 PM (1).png

The Success Framework defines four adoption levels that apply to the functional best practices: foundational, standard, intermediate, and advanced. The adoption levels classify the best practices according to the level of effort needed to meet your priorities, needs and goals for each activity.

  • Foundational. Best practices that establish functional groundwork for a Splunk environment with essential configurations and basic optimizations.
  • Standard. Best practices that establish the basis for an optimally performing Splunk environment with established configurations and practices.
  • Intermediate. Best practices that offer more control for results that you can tailor to how you organize your Splunk implementation.
  • Advanced. Best practices that suggest configurations and optimizations to grow and expand your Splunk implementation.

Each functional area has an overview page that lays out best practices appropriate to your adoption level.

Adoption levels can grow with you. For example, when you start out, you may have a moderate sized team and a few core use cases on established systems. You might benefit from putting some standard and intermediate-level best practices in place. You could also apply a few advanced best practices in areas where you already have strong practices in place.

Terminology

The Splunk Success Framework uses the following terms:

  • Splunk deployment. A Splunk deployment refers to Splunk software that has been installed and configured on a system and is accessible to at least one user and data source.
  • Splunk environment. A Splunk environment refers to the equipment that hosts your Splunk software. For on-prem Splunk Enterprise deployments, this is the hardware, virtual machines, and operating systems upon which your Splunk software is deployed. For Splunk Cloud Platform deployments, this is the service hosted by Splunk.
  • Splunk implementation. A Splunk implementation refers to your Splunk deployment and Splunk environment (platform), the team of people that use and support Splunk software (people), the data and use cases you use Splunk software and solutions to address (data), and the processes your community of users follow to deploy, use, maintain, and grow an organization's use of Splunk software and solutions (program).

unnamed (33).png

Helpful links to Splunk resources

Here are links to other helpful Splunk resources. At this stage, you might also want to check out Splunk Validated Architectures. These are proven reference architectures for stable, efficient and repeatable Splunk deployments that ensure that your initial deployment is built on a solid foundation.

clipboard_e1da038b0cde9e7ad45d589d4f0b95f9f.png 

Splunk Go - Resources for Your Success

Learn

Blog.png

Blogs

Read and subscribe to one of our many blog categories.

Customer Stories.png

Customer Stories

Learn how customers are utilizing Splunk through case studies, stories, press releases, and presentations.

Documentation.png

Documentation

Explore guides on Splunk products.

Quick Reference.png

Quick Reference Guide

Find fundamental search concepts, commands, functions, visualizations, and dashboard concepts.

Search Tutorial.png

Search Tutorial

Run searches, save reports, and create dashboards.

Splunkbase.png

Splunkbase

Find an app or add-on for almost any data source and user need.

TechTalks.png

Tech Talks

Watch technical deep dives live or on demand to learn how to get the most from your data.

Training.png

Training and Certification

Learn your way around the Splunk Platform and become a certified Splunk Ninja.

Get Help

Answers.png

Answers

Get answers to your questions from Splunk know-it-alls. Or share what you’ve learned.

Developers.png

Developers

Optimize productivity and write great code using any technology platform, language, framework, or approach.

OnDemand.png

OnDemand Services

Utilize experts to help answer specific questions on predefined tasks.

Service Offerings.png

Service Portfolio

From getting started to modernizing to unlocking additional value, Splunk Services experts can help.

Announcements.png

Product News & Announcements

View latest news and announcements about Splunk products.

Slack.png

Slack Workspace

Chat with other Splunk users, get help, and help others.

Support Portal.png

Support Portal

View entitlements and licenses, submit and manage cases, and access OnDemand services.

UserGroups.png

User Groups

Connect with like-minded people who are passionate about Splunk technology.