2024 State of Observability with Splunk’s Cory Minton
Cory Minton, Field CTO of Splunk, shares insights on his security background and the importance of system improvements. He discusses the 2024 State of Observability report, highlighting AI’s growing role in enhancing observability and security. Corey addresses challenges such as alert fatigue and emphasizes the benefits of agentic AI in automating tasks. He encourages viewers to explore the report and stay informed about Splunk’s advancements.
Transcript
This is Textron tv. Hey everyone. Welcome back here to techron tv.
I'm really happy to have this next guest on. His name is Corey Minton. Corey is Field CTO for our friends at Splunk.
Hey, Corey, welcome to Techstrong tv, man. It's great to have you on, Man. I am, uh, I'm very excited to be here.
I've been a fan for long time. Bumped into you con at conferences over the years. Yeah.
And frankly, just, uh, just glad to chat with you today. You know, I, I was taping tech drunk gang this morning and someone said, was it broke? Because, you know, we're always trying to fix things.
And I said, you know, of course, because that's what it people do. We like to fix things. I said, unless my security friends, we like to break things, then fix them so that they're better than they were before.
But that's what security people do. And, and if you don't understand that about security people, that's why you're not in security. Um, you know, people don't get that sometimes.
I mean, totally. I mean, at a high level, Corey, when you and I got into security, you didn't go to college for a cybersecurity degree or, or these things. Right.
You got into it because you like to break things and fix 'em, and that's we what we did. That's the best way to learn. Build your lab and break things.
Learn how that broke. Absolutely. There's gotta be somewhere in here.
But anyway, um, Corey, you know what, but that's actually a good segue. Let's do, give us a little bit about your journey into, you know, security and, and being here is Field TO Splunk. Yeah.
That's fantastic. Thanks. Thanks again.
Yeah. My journey is kind of, um, you know, I've had a lot of fun and I candidly have the most fun job, I think within the company as field CTO. It's my job to talk with our customers on a daily basis, share with them where we're making investments in our products and our technology and our capabilities, and then hear from them directly, like, Hey, is this the right strategy?
Are we solving the right problems? And taking the feedback on where we can improve, where we can do better. Taking that back and being a liaison to our, our product and technology engineering organization.
And so it's, it's a fantastic gig. I have lots of great opportunities to hear from customers, and that's my favorite thing is like being in the real world, understanding at the front lines what's happening. Um, but prior to that, I've been at Splunk for almost five years.
I've been a Splunk customer and partner before that for nearly a decade. Um, built a practice at, uh, EMC and Dell Technologies to help customers deploying Splunk and other large scale ai, big data systems over the years. And have really just been a tinkerer and a consummate student of, you know, what's happening in the space of, you know, big data, AI and machine learning.
And now given the, the transformational nature of what's happening for so many enterprises today, that that experience has been, you know, super helpful. And it's been, um, kind of helping me form and shape some hopefully strong opinions on where I think we can make investments and continue to drive our customer success forward. Absolutely.
You know, believe it or not, I still remember, like, when I first became aware of Splunk, Jesus, it's gotta be 2005, 2006, maybe 2004 in that range, and they had really good T-shirts. It was, they would just play black T-shirts, but with really cool sayings on 'em Mm-Hmm. You know, that that was Splunk for me, but then that wasn't enough to get me to the booth or whatever.
Right? Mm-Hmm. But then to understand what the product does, I'll never forget, I came home, came back from whatever show we were at, and I said, man, that's a company I'd love to invest some money in.
Because it was just like, you know, the ability to just capture anything and everything Yeah. Was back then, right. That was pretty radical.
Yeah, it was radical. It was, of course. I was gonna say, one of the things that we, that we struggled with whenever I became a customer was just that like, large scale distribution of That's what I was gonna say, That like, especially, you know, in the early days, I think Splunk's, you know, their core mission was really on that.
Like, how do we deal with that traditional architecture of, you know, a lot of times three tier, but things in our data centers, how do we, you know, instrument the infrastructure and so that we can kind of understand what's happening at the application layer And that solving that problem at the scale that we were solving, it was a challenge. And so I think that's where Splunk's, like in the early days you talked about was, was really interesting. It was like, Hey, we have this really interesting way where you can instrument anything.
You have this unique way where you lay data out where you can ask kind of any question, and you're not bound by some particular schema that so many of us are used to in that, you know, data warehouse world where you have to structure all your questions before you lift your data. And it really just became this tool that you could do so much with. And what, what happened for, you know, a number of years is it was like we were burgeoning and kind of figuring out like, what are all the interesting use cases?
And really over the last decade, it's become like abundantly clear that the majority of our Splunk customers use us for either security, right? Security is a fantastic data problem to go solve on large scale amounts of distributed systems. And then really on this observability space of, and observability meaning, you know, bringing visibility to applications run in our own data centers or in the cloud, or in the mix in between.
And that's really where this, this report, this state of state of observability report comes from, is like, Hey, we're trying to get a grasp on what's, what's challenging the world of observability? What are the, the things that good observability practices have in common so that we can all learn together from them? And then what are those key areas of investment where, hey, if you have a platform like a Splunk, you know, then what are those areas where the, the real leaders are doing like great things in terms of return to investment and, uh, you know, efficiency enhancements.
So it's been a, it's been a fun ride and we've got a fantastic, uh, kind of year or two ahead of us, especially with the, uh, the fantastic Cisco acquisition. So Yeah, I mean that, you know, so Cisco beat me to buying Splunk, but I probably wouldn't have come up with the 30 something billion anyway, or whatever it was. So yeah, More power to 'em.
But, you know, all kidding aside, people at first were like, wow, Cisco bought slug Splunk, is it gonna be part of their security deck? And they, you know, Cisco, obviously we, those of us in the security space know this goes, you know, gone through some changes in their security division. A lot of folks I know came over from the duo acquisition, which, you know, was the big acquisition until Splunk, um, have moved on.
Uh, or was there other, you know, observability is more that security, right? Kind like macaroni or spaghetti's macaroni, but not all macaroni is spaghetti. Um, so, and you know, look, anytime you get an acquisition, there's always some eggs broken making the omelet.
Talk to us about, you know, what's been your experience that, what do you think we can expect from this Splunk, Cisco, you know, marriage? Yeah, I think it's gonna be a fantastic one. I think the, there's been leadership, uh, changes that I think that, that give very good indication that Cisco wants to treat the Splunk acquisition with, you know, great respect for who Splunk has been and our history and the things that we're great at and how do we, uh, you know, bring that value to life in across the Cisco portfolio.
And so having folks like, you know, who Gary Steele who was the CEO of, you know, of Splunk comes in as now the president of all go to market, gar go to market operations for, you know, Cisco says that, Hey, we, we think that that's a leader that knows how to build businesses that are scalable and solving enterprise challenges. If you look at the ways that we've integrated our security and engineering, our security and observability teams to make sure that there is, you know, we're picking the best capabilities from the platforms and we're learning like what are those key features across, you know, let's say the observability tools that were existing acquisitions for our existing products within Cisco. What can Splunk learn from those products?
How can we integrate best with them? And what we found is that there's just this like great synergy between what we all do and what we do well, while there may be some products that do some similar things, most of what we found is that it's different customers who use them. And there's some, some reasons why you would choose one versus the other.
And so what we're really focused on is how do we help, you know, customers who've made investments, extract the most value, get the most, you know, uh, efficiency from their use cases when they do have investigations that may span across platforms, how do we integrate them so it's seamless and smooth and highly efficient? So we keep people out of the business of, you know, big war rooms and these, you know, this awful situation when something bad happens. Like, let's give 'em the data, let's give 'em the tools, the, the intelligent navigation.
How do we use AI assistance to drive them forward to, to make them more effective? It's really been the focus. And so I, I see I'm excited to be here.
I'm, um, I'm really excited about the investments that Cisco is making in Splunk. The things that people like Chuck, the CEO of Cisco have said around how we're gonna do this differently. We're gonna, we're gonna make this a great, um, experience.
He actually talked about it in some of our, um, our executive round tables during our last user conference. He is like, we told the board of directors we're gonna take some time on this one and really make sure we do it right. So I think it's that thoughtfulness from the top and the synergy that exists between our products and the ways that we've brought together those engineering teams.
I'm just seeing customers be one very bullish and excited about it, and they're just asking for more. They just continuously say, Hey, how can you help me get the most from this? And so I think what Cisco brings in terms of the, you know, that amount of telemetry data that's now a new source that maybe Splunk hasn't had as much unique access to, just means that customers are gonna get even more value from Splunk going forward.
Excellent, man. Yeah. Hey, we we're gonna run outta time, so I wanna make sure we, we get onto this report.
So, Splunk's state of observability report 2024, you guys have been doing this report for a number of years now. We've been covering it. Um, you know, in many ways, 20, 24 reports as we come to the end of the year is kind of the year where we're seeing AI have a real effect.
It's not, Yeah, It's not in full effect. There's still plenty of hype out there, but it's real enough where it's having effects. I'm wondering, I mean, when you look at the report, Corey, what jumps out at you is kind of being really kind of important.
Yeah, so I mean, for those, for a little bit of background, this state of observability report, this is our fourth one that we've done our fourth annual report when we plan to continue to invest in this report. And it's, it's really a survey of about 1800, you know, IT operations, um, observability, software engineering, software development team folks where we go out and have conversations with them about, you know, what are they having success with, what are the challenges that they're facing? And, you know, kind of assessing them on their effectiveness and where they kind of fit on this maturity spectrum of having, you know, really a world class observability organization.
And what STEM out to me is one, yes, AI is still very much one that teams are looking for, how do I apply it really intelligently, but with some caution on, you know, I wanna make sure that I keep a human in the loop. I don't want to turn over too much to ai. But I think it's also an area where what we're hearing is that AI is becoming a new digital service that, you know, organizations need to bring observability and security to it.
So I think it's, it's really an interesting space. I think some of the big ones for me, I think in terms of key metrics and, you know, that, that I think folks will be interested in is, and one is, you know, anytime you're investing in software, you're doing so, 'cause you're trying to buy an outcome, right? You're trying to get some outcome that's harder to get, that's hard to do on your own.
6 XROI on their investments and observability tools. And that means that they're seeing that if you do observability well, you connect real visibility to the business and how those underlying applications and the process of bringing those applications to life, you start to really understand that business context. And that's a powerful differentiator, I think, in the market is that when you don't just understand what's happening in my cloud environment, but actually how is those underlying technical services and how are those services affecting my revenue generating customer facing applications in meaningful ways?
And how am I avoiding that downtime and how am I getting my teams focused on the power, the really important stuff? Like, that's one of the other, I keep finding, like, people say like 57% of folks that we have, that we had res our respondents said that they're struggling with alert fatigue. Like people are just getting overwhelmed by the amount of data and these alerts that are happening.
And so they're, you know, you talk about ai, that's one of the best areas that we're seeing return on investment is how do I use AI tools to correlate and bring context to 'em and get focused on the right stuff. Yeah. I mean, look, this has been a problem, you know, the desensitization and vulnerability data since I was selling vulnerability data in 2003, right?
But back then it was job security, right? You'd get, you know, you'd deliver a yellow page, people don't remember what Yellow pages were, but you deliver a yellow pages size, you know, vulnerability report, dump it onto some security network guy, and he'd spend all year, you know, fixing what he could, not fixing what he couldn't, you know, by the time he was almost at the end, it was time for a new report. You know, and it, the kind of job security, of course, it's much different.
You mentioned ai. I think one of the things we're seeing Corey, and I'm interested is agentic, so-called Agentic ai, right? We have all these agents that will do a lot of this for you, right?
You can have an agent that finds vulnerabilities, an agent that fixes vulnerabilities, an agent that manages those agents, right? And, and, and so on. How does that play into Splunk's plans?
Kinda, you know, everybody wants to use ai, but is that kind of, you see that coming? Yeah. I think that the desire for AI to accelerate outcomes is kind of a universal goal in the, you know, in, in enterprise software.
It's like, how can I leverage the, you know, amazing amounts of research that have been done in frontier and foundational models. How do I bring that into my product in meaningful ways that at the end of the day just brings customers what they expect from us even faster? And so we've had, we've been on a journey one, I'll tell you, like, I think of, I think of AI in two ways, at least in terms of like where Splunk is working with customers.
I think one is, um, you know, how are you bringing observability to the enterprise AI applications you are developing? So are you instrumenting those well so that you can understand cost, performance, utilization, usage across the enterprise for the purpose of solving things like, you know, traditional observability problems of are they performing as they should, right? Are they performing as expected?
How much am I spending on the development and running of these kinds of applications? So that's one area that is ripe with opportunity. I think lots of organizations are trying to figure out, how do I secure those applications?
How do I bring modern observability to them? And that's one, we've got lots of fantastic customers doing interesting things with open telemetry, which is a really a bedrock for or finding across observability. That's a key capability is like standardizing your, develop your instrumentation methodology on open telemetry.
And even in the AI stack, that's a, that's a big deal. We've seen that 72% of the leaders in that observability space have standardized on Tel. And I think that's true as we look at the current and next generation applications that are gonna be deployed in the enterprise.
That's like, that needs to be a standard. The other way I'd say it is like, we're manifesting AI in our products, much like, you know, other organizations are thinking about it, and we're doing so in a, in a thoughtful way. We wanna make sure that they're, you know, domain specific.
Like, we're not gonna make a, you know, cat image generator. We're gonna make security tools and observability tools, you know, people who maybe want you to do that. You know, it's outside of our bailiwick.
Like that's not what No, I get it. So we're trying to focus on what they, you know, what they, they know us to be great at. And so it's really around security and observability, you know, AI capabilities.
We've been shipping a lot of machine learning and what we call foundational AI in the product for years to help extract, you know, signals from non-human scale data sources, right? That's been Splunk's superpower. Where we're investing now in some of the AI that we think is next is really in this AI assistant concept, which is like, how do I build AI assistance to go meet my analyst where they are, meet my SRE in the tasks that they typically end up in Splunk for, right?
Am I having a latency in an application? Am I having carts being, you know, abandoned for some, you know, end user per, you know, uh, experience problem? How do I bring AI to say I can identify and alert against what's happening and I get focused on, and then I use an assistant to say, here's the way to go solve those problems, right?
Here's the next best action to take. And so we started with an AI assistant for SPL, which is, Hey, how do you ask questions and Splunk more effectively have an AI do natural language transition? And then over the next year you'll see us releasing these, these assistants in our core products, in our security products, in our observability products.
They'll accelerate the outcomes. And that's really the goal is at the end of the day, it's like, how do I get them moving through an, you know, an investigation faster? And we actually had a, one of our customers in our private preview experience, they did an AB test where they actually had, um, uh, two groups working on solving a, you know, like a scenario where there was a latency in an application and in the AB test, the team that they gave them access to the observability assistant, they solve the problem 75% faster than the team without, without the AI assistant.
And to me, that's like the aha moment that you really, that, that folks want to see, which is, can the AI accelerate my outcome? And that's, it's pre proved it. You can.
And so the early adoption is, has been really encouraging, and I think that we're just gonna see more excitement build as those products, you know, mature and the applications get more focused. Um, and then, yeah, I think agen AI is part of it. We'll, you know, we'll be, we'll be building agen AI in ways that just makes sense.
Like just is it, can we figure out a way to use it in a security observability context to derive an outcome, then Absolutely. Hey, we're, I wanna just mention for anyone who wants to maybe go download the report mm-Hmm. com/ian US campaigns slash state ofer state dash of dash observability html.
An easy way is probably just Google Splunk's 24 24 State of observability report. Right. You can get it there.
Corey, thanks for coming on here, man. Now that you've been here, don't be a stranger. I would love to.
Right. Splunk's always got something cooking. com or cloud native now, or even our AI ITSM and, uh, digital transformation sites.
We're always covering Splunk. So come on back here and keep us posted. Okay, Sounds great, man.
Appreciate the time today. Appreciate your time. Appreciate your time.
Cory Minton Field CTO for Splunk here on the Splunk State of Observability report 2024. Go check it out. We're gonna take a break on Tech Strunk tv, tech Sunk tv.
We'll be back in just a moment.