Forwarder 6.x Compatibility with Splunk 8.0

By: Forrest Lybarger | Splunk Consultant

 

If you are looking into upgrading Splunk to 8.0, you have probably come across the compatibility matrix for forwarders:

Source: https://docs.splunk.com/Documentation/VersionCompatibility/current/Matrix/Compatibilitybetweenforwardersandindexers

 

This table means that Splunk does not support, nor has it tested, the use of 6.x forwarders with 8.0 indexers. It doesn’t mean that it is impossible for them to work together. In other words, you can use 6.x forwarders at your own risk. Any problems you have with these forwarders, however, will almost always be caused by the version difference and most likely fixed by upgrading.

With all the caveats out of the way, how do you get this working? Well, it depends on what exact version your forwarders have. Here are the affected versions:

  • 6.0.0 to 6.0.6
  • 6.1.0 to 6.1.4
  • 6.2.0 to 6.2.6
  • 6.3.0 to 6.3.1
  • 6.3.1511.1

The issue is that some older 6.x versions of Splunk use a different SSL protocol from 6.6.x and later versions, which makes them unable to connect via the management port (usually port 8089) and unable to communicate with the deployment server. To correct this, you need to force the newer Splunk components to use an SSL version that the older components can understand. In this case, your forwarders are the only components not upgrading to 8.0, so you only need to fix the deployment server. To avoid issues with these forwarder versions add an app with a server.conf containing this stanza to your deployment server:

[sslConfig]

sslVersions = *,-ssl2

sslVersionsForClient = *,-ssl2

cipherSuite = TLSv1+HIGH:TLSv1.2+HIGH:@STRENGTH

Allow any sslConfigs apps your environment already has to override this app by giving it a lower priority name or just add the lines from the stanza that aren’t present in your current app. You can delete this new ssl config after your forwarders are upgraded.

This fix should only be used if you must upgrade to 8.0 and can’t wait for your forwarders to upgrade. Keep in mind that this is not Splunk supported, so for now it could work (latest version as of writing this is 8.0.6), but in the future, Splunk could break this workaround. When you do implement this fix, make sure to prioritize upgrading your forwarders and understand that any problems involving data ingestion or forwarding are most likely caused by not upgrading your forwarders to at least 7.0 (latest version possible is recommended).

Want to learn more about forwarder 6.x compatibility with Splunk 8.0? Contact us today!

 

How Robotic Process Automation Fuels Document Understanding

By: Troy Allen | VP Cloud Services

RPA, or Robotic Process Automation, is becoming more prevalent in the world of business process automation. In its simplest form, RPA is the practice of utilizing bots or Artificial Intelligence to analyze information and make recommendations for actions based on that analysis.  RPA is not a static set of rules that a process follows. It is an evolving model that learns and adapts by examining recommendations and the actual actions taken and adjusts future actions based on what it has “learned.”  In short, RPA is business process automation driven by Artificial intelligence that learns as it goes to provide increasingly accurate actions and results.

As with business process automation, RPA can be utilized for many common tasks in an organization.  Insurance companies leverage RPA to automate the onboarding of new clients and validate insurance claims to reduce the amount of human-based processing while increasing accuracy.  Manufacturing companies utilize RPA to process Bill of Material documents and Purchase Order management.  Both examples focus on automatically processing documents and associated information that normally requires a high level of human interaction and decision making.

As an essential part of RPA, Document Understanding provides critical insights into the information being processed, helping to make the automation more accurate.

Document Understanding, a subset and critical function of RPA, interprets unstructured documents into a recognizable set of information that can be analyzed and acted upon with high levels of confidence.  Using specialized Artificial Intelligence tools, Document Understanding allows for the recognition of critical details and associations that would normally require human review to identify. For example, with forms processing and extracting key information from tables, Document Understanding enables RPA processes to perform highly accurate analysis and actions based on that information.

RPA and Document Understanding in Action

Onboarding new employees requires a large amount of information to be collected and processed.  Typical employers accept and track candidate applications, compensation details, candidate/employee profiles, onboarding documentation, performance management documentation, and various state and federal employee documents.  This can result in 15 to 20 documents being processed for each employee being hired.

Imagine an organization that hires thousands of employees for seasonal work, this can result in 2,000 or more documents that have to be reviewed, processed, and acted upon in a very quick timeframe.  Considering that a single document may take a human resource worker 2 minutes to review and make critical decisions about it, and up to 2 hours per document to complete its process, this can result in over 4,000 hours of processing.  Assuming the average resource cost for the participants involved in the processing of new employees is $25 an hour, the company could be looking at over $100,000 just to onboard these new employees.  This cost is most likely higher considering that not every candidate is a fit for the role or company and more candidates must be screened, interviewed, and processed to meet their hiring goals.

With RPA and Document Understanding, automated processes could be deployed to help minimize the amount of time each processor has to interact with the various documents and the actual process.  In many cases, documents can be automatically reviewed, analyzed, categorized, and routed for action based on a well-defined business process.  As an example, this can reduce the overall processing of those 2,000 employees from 4,000 hours to 2,000 hours, resulting in a $50,000 reduction in onboarding and hiring costs for seasonal employees.

What are the savings with RPA and Document Understanding?

As with any process, it takes time to establish, configure, test, and update to make the process as efficient and accurate as possible.  This is true with Robotic Process Automation and Document Understanding.  Many RPA tools provide a baseline of processes and intelligence based on business processes, but no two organizations operate the same way.

These baseline processes need to be modified to meet specific organizational operations.  In many cases, RPA and Document Understanding platforms provide a solid foundation to build upon which can save significant operational costs right out of the box.  RPA and Document Understanding are designed to learn as more information is processed which means that speed and efficiency grow exponentially.

Over time, organizations who utilize RPAs can see upwards of a 40% to 50% increase in efficiency and a reduction of 50% or more in processing costs.  The following chart outlines the potential return on investment (ROI) of an RPA solution with Document Understanding with 2 automated processes that traditionally take 4 full-time employees 35% of their time to perform with a salary of $55,000 annually per employee:

How to Learn More

Contact us to learn more about our RPA and Document Understanding solution – Content Process Automation (CPA) by TekStream. Through our experience and hundreds of implementations, we help companies streamline business processes and improve decision-making with a structured approach to unstructured content and data.

Using TekStream CPA, organizations can enable their users to quickly process and manage critical business documents, images, forms, video files, and unstructured data from a wide variety of sources. Fill out the form below to see how we can help you understand how Robotic Process Automation and Document Understanding can be leveraged within your organization. You’ll improve your processing efficiency, reduce overhead, and see a return on your RPA investment quickly so you can focus on driving your business to even greater heights of success.

TekStream Promoted to Premier Tier in Splunk Partner+ Program

TekStream, an Atlanta-based digital transformation technology firm, announced it has once again achieved Premier Partner status in the Splunk Partner+ Program.

In order to achieve Premier Partner status, partners must achieve $2 million in sales over the past 12 months and staff accreditations commensurate with the tier. With its Premier status, TekStream’s Splunk customers benefit from an enhanced level of engagement, commitment, and support.

By including TekStream in its Premier Partner Tier, Splunk has recognized TekStream for its outstanding achievement and commitment to Splunk market development, strategic prioritization, and customer success.

“I’m proud of our team and the hard work they’ve put in to achieve this accomplishment.  It’s especially impressive considering the circumstances we’ve all endured this year.  I’m excited about the momentum this creates heading into 2021 for our team, our customers, and Splunk” said Matthew Clemmons, Managing Director of the Splunk practice at TekStream.

About TekStream
TekStream accelerates clients’ digital transformation by navigating complex technology environments with a combination of technical expertise and staffing solutions. We guide clients’ decisions, quickly implement the right technologies with the right people, and keep them running for sustainable growth. Our battle-tested processes and methodology help companies with legacy systems get to the cloud faster, so they can be agile, reduce costs, and improve operational efficiencies. And with 100s of deployments under our belt, we can guarantee on-time and on-budget project delivery. That’s why 97% of clients are repeat customers. For more information visit https://www.tekstream.com/

OCI DR in the Cloud

Business Continuance via Disaster Recovery is an essential element of IT and takes on many forms. The high end consists of high availability solutions that provide real-time replication of systems. While these systems provide seamless continuity during outages they are large, complex, and expensive, justifiable to support only the most critical business applications. At the other end of the continuum, however, Disaster Recovery is little more than tape backup or backup to NAS which have complicated and lengthy restore procedures which take hours or days.
A major improvement can be made in disaster recovery with a solution that provides business continuity in a model that simply extends the existing IT architecture into the Cloud.

Rackware RMM Migration/DR platform is a non-intrusive Agentless Technology with pre- and post- Migration Configuration Capabilities that is easy to set up and configure for complicated enterprise environments/applications. Rackware RMM supports both Linux and Windows-based workloads for migration to the Oracle Cloud Infrastructure.

RackWare RMM platform provides a flexible and all-encompassing solution for Migration and disaster recovery. RackWare helps Enterprises and large Organizations take advantage of the agility promised by Oracle Cloud Infrastructure. Rackware’s platform eliminates the complexity of protecting, moving, and managing large-scale applications, including critical business applications and their workloads into the Oracle Cloud. It is now possible for enterprise customers to forgo the upfront purchase of duplicate recovery hardware, the cost of set up, configuring, and maintaining that hardware by leveraging Oracle cloud infrastructure.

Rackware RMM provides the following value proposition for enterprises in the Oracle Cloud:

  • Non-disruptive / Live Captures -No agents installed, safe and secure replication of your production environments
  • Network and Application Discovery – Automatically discover network configurations and applications allowing you to reconfigure them in the OCI environment during migration
  • Universal DR Protection – RackWare support spans all physical and virtual confluences, even for complex environments with Large SQL Clusters, and Network Attached Storage
  • Seamless Failback –  To physical and virtual environments, for simple disaster recovery drills
  • Cost Reduction – Orchestration engine for multiple polices of RPOs and RTOs based on tolerance to reduce costs with less expensive compute, network, and storage utilization.

Storage Methods

There are 2 storage methods available for Disaster Recovery.

Store and Forward

Store and Forward will create an image of your source workload in storage on the RMM’s database. When using this method, the RMM will need a datastore capable of containing the amount of used data from each source hosts minus typical compression savings.

Store and Forward is required if using the auto-provision feature whereby the RMM will only provision the compute resources during a DR event or test/drill event or to offer the multi-stage protection of having data protected by a stored image and then synced from stored image to target compute resources.

Passthrough

RMM does not store a copy of the used data from source hosts. The RMM acts as a passthrough proxy to sync the source workload data through itself and onto the target DR instances.

How it works

RMM provides a DR solution that builds on its image mobility and elasticity features to bring economic DR to enterprises. The building blocks of RackWare’s DR solution include onboarding, cloud bursting and the policy framework to automate necessary functions. Captured images from production (origin) instances are cloned and pushed out to a local or remote DR site. Changes in production images are periodically synchronized with the remote images, keeping the original host Image and the DR image in sync. In the event of an outage at the origin site, the up to date image at the DR site can assume operations through RackWare’s fail-over mechanism.

After the production instance is repaired and operational, it’s easy to restore the origin site to any up any changes made to the CloudImage in the cloud. When the origin site is restored to its operational state, the administrator can utilize the capture from cloud feature to refresh the original Image and synchronize any changes that occurred during the outage.

Overhead on the origin Host is extremely small involving only resources to take a delta snapshot. Thus the data overhead of the WAN link incurs only the delta of information, keeping bandwidth needs and sync time to a minimum. It’s important that Image updates include user data, Operating System updates, and application installations and configuration changes so that the recovery image behaves exactly like the production image should a failover occur. The cloud DR feature supports all of these. While OS updates are more infrequent it is still important to ensure that kernel patches are kept in sync with the DR Image. When updating the OS, an image refresh operation is done from the RMM first before the sync to the CloudImage. Should the production system be compromised or inoperable, the CloudImage is automatically launched and is running with the latest synchronized changes.

Oracle & Rackware partnership provides a seamless experience to Migrate to the Oracle Cloud Infrastructure and secure customer workloads with dynamic provisioning and disaster recovery.

About TekStream
TekStream accelerates clients’ digital transformation by navigating complex technology environments with a combination of technical expertise and staffing solutions. We guide clients’ decisions, quickly implement the right technologies with the right people, and keep them running for sustainable growth. Our battle-tested processes and methodology help companies with legacy systems get to the cloud faster, so they can be agile, reduce costs, and improve operational efficiencies. And with 100s of deployments under our belt, we can guarantee on-time and on-budget project delivery. That’s why 97% of clients are repeat customers. For more information visit https://www.tekstream.com/

TekStream Helps to Support the Launch of Professional Services in AWS Marketplace

TekStream, a digital transformation company and Amazon Web Services (AWS) Advanced Consulting Partner, announced today that it is participating in the launch of Professional Services in AWS Marketplace. AWS customers can now find and purchase professional services from TekStream in AWS Marketplace, a curated digital catalog of software, data, and services that makes it easy to find, test, buy, and deploy software and data products that run on AWS. As a participant in the launch, TekStream is one of the first AWS Consulting Partners to quote and contract services in AWS Marketplace to help customers implement, support, and manage their software on AWS. Click here for more information.

As organizations migrate to the cloud, they want to use their preferred software solutions on AWS. AWS customers often rely on professional services from TekStream to implement, migrate, support, and manage their software in the cloud. Until now, AWS customers had to find and contract professional services outside of AWS Marketplace and could not identify software and associated services in a single procurement experience. With professional services from TekStream available in AWS Marketplace, customers have a simplified way to purchase and be billed for both software and related services in a centralized place. Customers can further streamline their purchase of software with standard contract terms to simplify and accelerate procurement cycles.

“TekStream views AWS Marketplace as a strategic channel for our services to be discovered and procured,” said Judd Robins, Executive Vice President. “Complete solutions generally have a technology and a human component to make them work successfully. AWS Marketplace has always been a great catalog of technical solutions. With the addition of Professional Services in AWS Marketplace, customers now have a broader range of options to get those solutions launched and managed.”

• Database Migration QuickStart – Jumpstart your Database migration to AWS with a 1-week process to analyze and assess Oracle, Microsoft, and open-source database migrations to AWS purpose-built database solutions.
• Splunk Cloud QuickStart – Get your Top 3 IT Operations and/or Security use cases implemented leveraging Splunk with 2 weeks of services, training, and 3 months of go-live support provided by TekStream.
• Splunk CMMC QuickStart – a practical, proven, and effective solution to get you compliant in under 30 days.
• Oracle License Optimization Plan – 1 week to analyze and assess your Oracle licenses and contracts to reduce costs – paving your way to Database Freedom on AWS.
• CloudEndure Cloud Migration QuickStart – 1 week to Migrate Development, QA, or Testing On-Premise Workload to AWS
• CloudEndure Cloud Disaster Recover QuickStart – 1 week to implement and test disaster recovery for up to 3 on-premise workloads to AWS

TekStream accelerates clients’ digital transformation by navigating complex technology environments with a combination of technical expertise and staffing solutions. We guide clients’ decisions, quickly implement the right technologies with the right people, and keep them running for sustainable growth. Our battle-tested processes and methodology help companies with legacy systems get to the cloud faster, so they can be agile, reduce costs, and improve operational efficiencies. And with 100s of deployments under our belt, we can guarantee on-time and on-budget project delivery. That’s why 97% of clients are repeat customers.