Splunk® Success Framework

Splunk Success Framework Handbook

Download manual as PDF

Download topic as PDF

Welcome to the Splunk Success Framework!

The Splunk Success Framework (SSF) is a flexible system of best practices that accelerate and increase the value you derive from your data using Splunk software.

The best practices in the Splunk Success Framework include everything your organization needs to implement and maintain a thriving Splunk environment that focuses on what you want to do with your data. Whether you use Splunk Cloud, host Splunk Enterprise on premises, or have a hybrid of both, the Success Framework fits flexibly into any business model to support everything from ad-hoc searches to enterprise-wide solutions for organizations of all sizes.

The goal of the Success Framework's best practices is to achieve a successful Splunk deployment, and help people in your organization think differently about their data and its potential to enlighten. The Success Framework's best practices are designed to increase time to value, drive adoption across your organization, and enable your Splunk environment to scale flexibly as you grow.

The best practices in the Success Framework are modular. You can apply any practice any time according to your needs and priorities.

About the Success Framework Handbook

The Success Framework Handbook provides reference materials, templates, and expert guidance for every aspect of your Splunk implementation, from data onboarding and platform management to suggestions for user education.

The Success Framework Handbook starts with best practices that establish a strong foundation, then offers implementation best practices organized into four service areas that support basic, intermediate, and advanced goals.

Most of the best practices in the Success Framework apply to both Splunk Cloud and on-premises Splunk Enterprise deployments. Where needed, topics specify whether something applies to only one or the other.

Foundation best practices

Foundation best practices are decisions, agreements, and success criteria that establish the purpose, goals, and ownership of your Splunk implementation. These tactical decisions provide clarity and accountability that are essential elements of a successful deployment. The Success Framework Handbook lays out four foundation best practices:

Determine the purpose and scope of your Splunk deployment
A purpose sets out the objectives and scope of your Splunk implementation.
Identify an executive sponsor
An executive sponsor is the leader(s) accountable for the success of your Splunk implementation.
Establish success measurements
Metrics set benchmarks so you can measure success as your Splunk implementation matures.
Establish an operations framework
An operations framework suggests different ways to set up your Splunk environment depending on your goals, and best practices for setting up a successful Splunk implementation team.

The foundation best practices set expectations with stakeholders and ensure that your Splunk implementation stays on track and can grow and expand as your needs grow and expand. For more, see About the SSF foundation best practices.

Success Framework service areas

Best practices for implementing Splunk are organized into four service areas:

Platform management best practices support the availability, scalability, and maintainability of your Splunk deployment
Program management best practices enable you to realize maximum value from your Splunk deployment
Data lifecycle best practices generate well-designed and effective use cases that are tightly aligned to data
User management best practices enable users and teams by using learning incentives and role-based access to features and data

Whether you have a single deployment or a multi-instance enterprise deployment, the best practices in each service area offer three implementation options, good (standard), better (intermediate), and best (advanced) to match your priorities, needs, and goals.

Good (standard)
Best practices that establish the basis for an optimally performing Splunk environment.
Better (intermediate)
Best practices that offer more control for results you can tailor to how you organize your Splunk implementation.
Best (advanced)
Best practices that suggest configurations and optimizations to scale your Splunk implementation.

For details, see About the Splunk Success Framework service areas.

Success Framework terminology

The Splunk Success Framework uses the following terms:

Splunk deployment
A Splunk deployment refers to Splunk software that has been installed and configured on a system and is accessible to at least one user and data source.
Splunk environment
A Splunk environment refers to the equipment that hosts your Splunk software. For on-prem Splunk Enterprise deployments, this is the hardware, virtual machines, and operating systems upon which your Splunk software is deployed. For Splunk Cloud deployments, this is the service hosted by Splunk.
Splunk implementation
A Splunk implementation refers to your Splunk deployment and Splunk environment (platform), the team of people that use and support Splunk software (people), the data and use cases you use Splunk software and solutions to address (data), and the processes your community of users follow to deploy, use, maintain, and grow an organization's use of Splunk software and solutions (program).

Where is the Splunk Center of Excellence (CoE)?

Splunk Success Framework is the new name for the Splunk Center of Excellence (CoE)! The Splunk Success Framework emphasizes best practices you can apply flexibly at any stage of implementation to realize the full benefits of Splunk software.

Release notes for the SSF Handbook

This documentation applies to the following versions of Splunk® Success Framework: ssf

Was this documentation topic helpful?

Enter your email address, and someone from the documentation team will respond to you:

Please provide your comments here. Ask a question or make a suggestion.

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters