"How-To" deliver immediate value with ServiceNow AIOps
[Music] thank you kevin so good afternoon everyone i'm benjamin james i'm the technology workflow specialist for our financial services southeast team so i cover all things aiops cloud native observability asset management and strategic portfolio management today you'll also be hearing from carlos peterson he's an advisory solution consultant with our i.t and cloud operations practice and really the brains behind today's demo uh then we also have richard brown scene on to help with questions so as heather mentioned please use the q a panel throughout if you have anything that comes up that you'd like us to answer so with that let's get rolling so just a quick rundown of today's agenda first we're going to cover a 3-0 strategy what it is and why it's important next we'll discuss why not all aiop solutions are created equal and then carlos is going to demonstrate how you can deliver immediate value to your organization with predictive ai ops so we found that companies around the world have a common goal they want to reduce the number of outages and incidents they have to xero and deliver uninterrupted digital services to keep their users productive and secure this is commonly known as the 3-0 strategy which means zero physical footprint running completely in the cloud to gain flexibility scalability and availability zero outages with the goal to drive 100 availability using ai and machine learning to predict and prevent issues before customers and employees are impacted and last but not least to drive incidents down to zero and deliver great end user experiences with self-service and virtual agents in a mobile first world now as the pandemic is clearly shown these are no longer nice to have and simply aspirational goals these are business imperatives if you want to remain competitive and relevant in today's market now most companies are on an aiops journey and they're adopting technologies to deliver on this 3-0 strategy everyone aspires to be a level 4 with more than 70 of your processes automated and services that are intelligent and self-healing but most companies are stuck somewhere between level 1 and 2. you may have a few point solutions that help with some noise reduction or some basic alert aggregation but the problem is you're still just reacting you have to wait for something to happen an alert or an outage before you can actually take action and once you have the relevant data remediation is still manual because most tools today are siloed barely talk to each other don't provide meaningful context and they lack native workflows so the only way to reach level four and deliver self-healing autonomous operations is with a unified predictive ai ops platform and that is the now platform it's one platform one data model and one architecture purpose built for all your workflows our technology workflows help drive a competitive advantage for your business because you can seamlessly plan build operate and service across all it functions in both traditional and continuous delivery models you can align your investments to business value deliver digital products and services faster ensure those services are secure and always on and reduce your hardware software and cloud costs with over 800 out-of-the-box integrations we are the digital enterprise fabric connecting all of your services applications and infrastructure and we want you to work how you want to work we'll bring our platform insights to whatever your favorite tool is whether that's slack teams the now mobile app grafana wherever you work today only the now platform can provide you with the understanding context and end invisibility into every aspect of your software lifecycle when you need it and where you need it now despite the marketing hype and all the buzzwords in reality not all ai ops solutions are created equal most tools in the market today are purely reactive meaning that something has to break before they can deliver any tangible value and when you think about it how smart is an aiops tool if you're the one who has to tell it where to look in advance set thresholds and then constantly fine-tune your apm tools now they can reduce some noise and some of the effort with root cause analysis but only if the data is there they're completely reliant on external tools to load that data nightly such as changes that have occurred and that leaves you with blind spots for most companies you're making dozens or hundreds of changes daily and so you need that context in real time not tomorrow i think of these legacy tools like having a smart smoke alarm you know it'll tell you which room in your house is on fire which is certainly important but what if you could be notified that the wiring in your kitchen was faulty and you could fix that before the fire ever started and that's the power of servicenow's predicted ai ops our ai engine sophie understands what your normal environment looks like and so as soon as she sees that something's abnormal she'll correlate all the relevant indicators logs alerts metrics topology traces changes bring all that data together and raise a flag to say hey you need to check this out something unusual is happening here's the insights i've pulled together to better understand what's going on so you can get this fixed before our users are impacted and here's an automated workflow that will resolve the underlying issue not only that she understands the context of what's happening for example she can understand when a spike in cpu utilization is due to an increase in customer orders versus a service actually going down servicenow's predicted ai ops helps you catch issues sooner as well as find the unknown unknowns issues you never even thought to look for in the first place and that's how our customers are able to predict 35 of issues before any alerts happen while also cutting mean time to resolution in half our vision and strategy has been validated by the market and industry analysts omvia name service is now an industry leader for ai output platforms in 2022 and gartner specifically calls out ai-enabled blog monitoring observability and open telemetry has critical capabilities for the future our predictive ai ops engine sophie is the only autonomous log analysis solution in the market today and last year we acquired lifestyle the industry pioneer and leader in open telemetry based observability now i say all this really just to emphasize that we are heavily invested in the future of aiops observability and the autonomous enterprise now with that i'm going to hand it over to carlos to lead us into the into today's demonstration okay so when when we talk about ai ops it's really uh for many of our customers that are taking that digital pivot digital transformation comes with that excuse me is really the volume of telemetry that needs to be ingested right and as benjamin stated before you know just handling alerts is not enough right and and really what uh customers are looking to do is get in front of issues uh understand patterns even before there's impact to a service or platform so what what's represented on the left hand side is not just the typical events that may be generated from multiple sources management tools or monitoring sources but also time series metrics right being able to look at anomalies outside of what's what's normal and then all and then as uh benjamin uh indicated really looking at anomalies uh that extends to uh the the logs right the content of the logs as well and be able to identify even unknown patterns and and this becomes very important especially as many customers are starting to migrate workloads uh not only lift and shift to the cloud but then also migrating those to containerized environments so these are environments where they're not they may see some unforeseen patterns and uh some unknown of unknowns as mentioned before so really what we're trying to do is make getting that ingesting that telemetry the events the the metrics and also uh this logging information and making it very easy to get into the platform and and uh from a logging perspective that could be our own file bead it could be from elastic it could be from kafka it can be from even a splunk heavy forwarder but the idea is that we want to provide real-time analysis and um and provide some additional insights that we can really understand the full blast radius of an issue okay so once we start to uh normalize and that you know a huge volume of data it's really how do we start leveraging uh ml based machine learning based techniques to really start to understand where there are patterns and where they're related both causal as well as symptomatic alerts that are generated from these events uh anomalies from metrics and blogs and really create an actionable uh incident or notification so some of the techniques that we have out of the box uh more deterministic is tag based learner clustering where we're really looking at uh focusing on the content the payload of the alerts and being able to normalize even uh tags that can be used to be to drive outcomes right without a dependency of whether the cmdb is fully populated so this is a real really great way to get uh get started day zero um with focusing more on the payload natural language uh second a automated temporal analysis is really fully unsupervised uh where you can just start sending the the telemetry right that we start to generate these um these events from and automatically there are patterns that are being created and there's uh essentially a nightly job by default that starts to evaluate a 30-day rolling window and those patterns then start getting recalculated and what's what i think uh the important thing with machine learning is that it does require um some level of feedback or a neural net capability to uh provide um you know an acknowledgement or you know some sort of rating that the clustering is accurate or maybe uh the clustering uh needs to be altered uh but based on a very simple uh feedback mechanism you're training the algorithm to become smarter right by providing a little bit of that which we'll cover uh other techniques uh using topology whether they're full service maps or just basic uh discovery i would say leveraging the the number of of connections or relationships from cis and being able to cluster uh related alerts in that way and then i would skip all the way to the right where true anomaly detection is really probably focused for us on the logging and being able to identify these patterns in real time and surface them up so that they can be acted on so once we've used any number of these techniques we start to group the related alerts and we create a grouped alert or an actionable incident and then from there we can be very data driven uh from the platform we can start to reach out to the appropriate support teams or uh maybe even distributed teams to swarm the issue from a collaboration perspective reach out through the mediums that they're typically working with such as teams or slack or even in the environment such as a grafana as benjamin mentioned remediation we have that is really the power of our platform it's our mode uh motto right let's workflow it and that's where we can start to leverage any number of spokes with automation and orchestration tools to do some level of triage to full remediation right try to um fix the problem so that service comes back to an uh normal operating rhythm and then finally it's it's all about insights right being able to provide those insights and learn from them so that if we do start seeing repeated issues that you know we have um the appropriate information to prevent any issues from from reoccurring in the future and and while always trying to drive you know those outcomes it's all about aligning to the business outcomes of improving service availability improving customer set and then obviously really keeping in line with the agility of uh the business and and that may align with many uh personas like a site reliability engineer so with that said let's go ahead and jump right into an environment and again if you have any questions richard's standing by there's a q a section that as we go through some of the material you can definitely ask those questions and we'll try to get those answered in real time so what you're looking at is our operator workspace a little nugget uh just around the corner i think on the 23rd of this month we've got a next family release where we've got some brilliant workspaces we have a new experience that's being introduced and these new workspaces that are being enhanced not only from a visual perspective using new libraries but also the experience to to really minimize uh clicks and provide a better experience from a usability perspective so that's just around the corner we'll show a little bit of that at the end but what you're looking at right here is what we call the operator workspace now this may be as i log in based on maybe my my alignment to a decentralized team or or support team um i may see things that i really care about so in this case we see um you know i would say the priority or the business criticality of certain services and platforms but very easily we can slice and dice uh this data into any other uh ways that could be based on uh geographic region maybe we're multi-cloud and based on the data centers or regions within that cloud provider that could easily be a view for maybe a cloud ops or other paths admins but let's go back to our business criticality and what we can easily see here is that there's some impacts to some very core or mission critical applications uh to maybe the business unit or maybe even as an app owner i would really want to see what's the the current state of of those services so in this case we see a order status uh very quickly i can get the service details and that's where there's some metadata uh you know about that application service um there could be other things about a history of of incidents and changes even kpis from a metric perspective but more importantly we're kind of focused on there's a problem and we have one grouped alert so if you go back to that powerpoint we're using one of those ml based mechanisms to really start to group related alerts into one actionable incident for example to give me that full blast radius of an issue so i'm just going to click in to this grouped alert and we can see at the at the summary of this this is there seems to be some some disk uh or storage related issue we've auto ticketed right we have the metadata to be completely data driven so if you think about the days of catch and dispatch of looking uh having that l1 and evaluating uh kind of the alerts and then routing those you know those are a thing of the past we need to be able to automate um automate that and then have that uh that persona really work on the more valuable activities uh that will align to those business outcomes of really truncating or truncating some of the resolution times one thing we can also see from this from this um specific grouped alert is that it was grouped using the automated technique right that's the where the temporal analysis you start we can now start to uh build patterns automatically and we can start to provide some level of feedback to make the that ml based clustering technique even smarter but we'll address some of some of this as we go through this issue so one thing we can see here is that um we have 10 related alerts remember we're trying to get that full blast radius and as we scroll down here the source is really the source of those alerts we have our log analytics again we can pull that from kafka elastic our own file beat maybe even from a spunk heavy forwarder there is multiple ways and we're providing real time insights real time anomaly detection we've got other sources we have our own itom agent which could be you know a monitoring presence that can do discovery as well as collect events and even telemetry time series data and even logging data as well you've got xavix vrealize probably traditional uh alerting that that's being forwarded to the platform and then um you know so forth and so forth but one thing that we talk about getting ahead of an issue is really identifying patterns uh before before some something actually occurs and you go back to the definition of an alert right something's already tripped something's already occurred and and that's great we can we can start to act on it but we really can't get any you know i would say we really can't get um any better than kind of that reactive state and to get into the almost preventative side we really start have to look at other telemetry types so let me give you an example so one of these 10 alerts that have been clustered right based on our ml based clustering technique is from our log analytics and the beautiful thing about our log analytics solution is that you can auto map there's no heavy administrative burden of trying to parse out logs that could be in so many different formats and and that's one thing that our platform will do is auto uh map uh the timestamp understand kind of the true summary of the the log itself and and that becomes very easy to to to start ingesting and then start to um really evaluate uh various aspects using different ml models and this is what sophie does so in this case there's a anomaly that's been identified right so in this case there's a spike in the total volume of logs right so we can look at the characteristics of the logs itself but also the contents right keywords exceptions things of that sort also we see the anomaly why is this anomaly why is this considered anomalous right and really what we're starting to see and again this is in real time we didn't necessarily need some subject matter expert to tell us because this could be unknown of unknowns is immediately there's from a from a logging perspective there's now patterns that are happening that are way outside of what's normal maybe from um the last hour maybe from the last day and and so forth so the events per minute is way outside of what is is deemed normal in fact you can kind of see this bait uh this baseline here at the bottom being yellow right and then we start to track or sophie starts to track and raise up that hey there is some anomalous behavior uh based on you know any one of those models so and the meaningful properties would be identified here so we're we're definitely looking at maybe the log itself but those could be uh keywords uh from the content of the log now a great thing is as these insights and anomalies are starting to be surfaced we make it very easy for the right subject matter expert to identify this and say wow this is great but you know this may be something that is very anomalous but maybe something we we don't want to be uh woken up to in the morning for you can mute that alert right that's that's a think of it as a feedback mechanism to train essentially the ml model to say okay well for this environment we we now have a little more information to get more accurate with our reading or on the other hand this could be raised up as being significant it's affirming that this anomaly is truly actionable and again a very easy way to to make the the clustering and some of the anomalies to to make it more intelligent and confirm some of the behavior and patterns that are generated so i'm going to go back to this virtual or that correlated the 10 uh 10 specific uh alerts together to give us that full blast radius and you know we talk about the the different alerts that have been triggered but then also we can look at our own uh i would say time series because that that becomes important as well to look at various facets of the issue that's that's happening so i'm going to go ahead and click on this specific alert that was created from our agent client collector that goes through our metric intelligence where we can now start to collect time series metric data and baseline and create anomalies as well but if i look at the metrics related to this these are maybe kpis and you can see here we have a a baseline in fact what i'll open is our metric explorer and it didn't look like we were having some timeouts right so let's look at our uh one of our metrics that we're collecting and uh we're looking at http code and then the total time and even from here from uh we saw our baseline but we're way kind of you know outside of maybe what what is a normal pattern and we can kind of validate that with other metrics that are being collected within the same environment that you know are fairly consistent but we we definitely see you know a some issue with a connection time maybe from again we have database alerts we have transaction maybe apm related alerts and then we have metrics that are confirming giving giving us more optics into the issue and at the time that it happened okay so back to the um to our primary alert we've got a lot of validation here that um we we had early issues with um http status codes we we have uh either from a metric perspective we we understand there's some resources that um that are also involved we have um you know web or application servers that now are you know the transactions time for those transactions are slowing down and and seeing other anomalous behavior but these are all related right we don't want each one of these to go to different uh support teams or to other notifications because seeing by themselves is really just a symptom and being able to cluster those and see that full blast radius really allows us to to be efficient with our communication and collaboration in understanding the full extent and even how important that is so one thing we can now start to do is even within the platform especially for certain personas you know if this is a uh a potential problem that we have a knowledge article maybe it's from the vendor or it's internally like an sop essentially our agent assist will start to look at the keywords related to this issue and start recommending right start surfacing up the more relevant knowledge articles so that even from if this was the first time that i've encountered it encountered this from a from an engineering or operator perspective i've got something that really seems to be relevant right a knowledge article to the the issue that's arising at hand so i could have steps to [Music] potentially gather some additional triage information um or even some remediation steps so that becomes important to understand that there's ml even in the platform a ton of machine learning that becomes uh usable from from the operator workspace other things that we have are actions and remediation right and in fact if we look at our alert executions here using our flow designer right our power of the workflow we start to document and audit exactly uh things that are being executed even at an alert perspective we've created an incident automatically we have all the metadata so we do that intelligently we do it in a way that we also consider metadata about the potential impacted application services um as well as uh in this case we're doing some actions to gather even the logging data that would be readily available for those subject matter experts or those teams to to view in context so they get an active node proactive notification and maybe you know uh surrounding logs to the issue so that they can quickly identify and even manually look at the um the related data to to help move that process forward i would say one of the the most important you know i say the powers of of our ai ops solution is being able to identify uh probable root cause and you know if you look back uh or think about when gartner mentions you know outages uh are probably you know i would say 80 or 90 percent of the time uh you know the contributing factor to outages is some change right whether that's an authorized change or unauthorized change well in fact what's happened here and what i can do here let me just close this so you can see these two uh these two were generated basically because if you think about the slide you saw from from benjamin since we're on a single common data model on the single platform we have access to all these consuming uh i would say data points from uh from itsm from the other applications so that instantly we have visibility into things like changes so in this case uh related to this issue we have the highest probable cause is actually in unauthorized change and how we do unauthorized changes really on the discovery side using file based discovery that can even look at specific files and contents of those files and see if there's been some change and it can be raised up as an unauthorized change if there's no correlated change record right someone made especially in a production high priority or business to a high priority application service made a change to a production environment without a corresponding change record right so that becomes important as well um and uh being able to see that and then secondly there's uh some deployment you know as we start to see more and more uh focus on uh the ci cd pipeline maybe infrastructurous code being deployed from um from the pipeline itself we can now start to get visibility uh from a machine to machine change and get those details so what can what we can do here is take a look at this um this top uh the the top probable root cause and this is that unauthorized change that was probably surfaced up from our discovery solution and in fact we do have um on a database right and that kind of makes sense we were seeing uh database uh you know resources on a database server uh other kind of downstream uh symptoms of that where transactions application servers were unable to to connect and maybe uh due to some some issue with the database environment itself but the first the highest probable um cause here is that there was actually a configuration change within the database environment right and that becomes uh a great insight in the sense that uh now we can we can look at uh the the ci we we have metadata where we can pull in the right sme if needed to you know potentially back out that change or review those change but we have the context within this outage that um you know potentially there was a change that wasn't reviewed in its proper didn't go through the proper process so other things to to kind of look at as well we have you know visibility into configuration items but in this case we don't necessarily need uh again a fully populated cmdb to to start to cluster related alerts um uh with without having uh again that that fully populated and mature cmdb right so that's uh that is uh somewhat of a myth and and we we absolutely can now start to leverage again the patterns that are automatically created focusing on different aspects maybe of the the payload the natural language the text and being able to cluster those uh into patterns that we can influence so one way of influencing very quickly is even if uh someone was looking at this issue obviously the you know the the mission statement of uh incident management is to restore availability as as quickly as possible but even you know from a clustering how do we make you know better clustering if if it was determined that you know maybe a few of these alerts are just not related you know maybe they're these were automatically clustered based on these patterns looking at a 30-day rolling window well i can influence that simply by you know removing these from a group adding other maybe symptomatic alerts get that full blast radius to this cluster of alerts is another way it's we're actually manually creating a data set and then based on that scheduled job will be then considered and um in the calculation of that 30-day rolling window so the actions here by removing or maybe creating a group of a subset of these alerts is another way to provide feedback and and really start to uh tune the way the the clustering occurs very simply done right here by uh doing some actions from an operator perspective uh to provide um that that neural net feedback uh to to uh to make ultimately the the clustering better uh in the future okay so um a few things uh as you know again we we've covered the the clustering uh we've covered the the metadata that can be used to kind of automate uh the uh the routing um and we've got some metadata to really understand how we can start to kick off automation right not all automation is treated the same meaning that if we have more critical uh things that are impacted well we can drive the automation differently than something that's less important meaning approvals notifications and and really that goes back to the large number of integrations that we have available in the store and you can find that in by going to our store for example here um we have over 800 applications you can simply um you know have these applications applied to your servicenow instance and then um you know based on for example an automation perspective you've got you know we've got out of the box folks that that can be leveraged for you know for those triage for those uh remediation uh use cases likewise from an ingestion perspective growing number uh minutes to value uh from you know either monitoring tools or uh things that are similar to that right from the telemetry side how do we get these ingested whether it's a just a generic web hook or you know you have some of your your investments that are here minutes to configuration so we can start seeing value day zero we talk about different uh experiences that we can start to share now something that's not new right is uh in fact this is my mobile device this is our agent right and so based on my alignment much in the same way i can look at for example that same clustered or grouped alert right that we saw maybe my preference is to work from a mobile device right and we make that um make that very evident here so you're looking at all the same information uh you can perform actions you can look at all the activity explaining exactly how alerts were clustered uh based on you know the specific mechanisms i can leave you know notes here uh you know all the expected things and then much like in the same way of the operator workspace i can now start to look at you know probable root cause uh you know similar is this maybe even a pattern of seeing similar issues like uh recurring theme that may be a great candidate for uh problem management uh and then all the secondary alerts right these could be again giving me the full blast radius uh and understanding of the impact of this issue the second part is really as we start to extend into san diego and this is what we're really excited about we all the uh applications that you're seeing and let me get to one of my workspaces here this is in fact on san diego this is a uh cloud um in fact this is the cmdb workspace so you'll see more and more of these workspaces now start getting added to our servicenow store and the there there's two aspects one is you know where we have now this uh it's called the now experience it's a ux library update where you know things are you know cosmetically uh nicer and and we can organize things in a more modern way but also it's provided really an opportunity for all the uh bus within servicenow to redesign make the usability uh even better for end users like yourselves so less clicks to get valuable data right so in this case um we're looking at this could be cmdb-related cis i can do search for very quickly search for cis and then quickly drill down look at any number of kind of aspects of that configuration item whether those are tags that are discovered if this was some resource in the cloud or virtual environment any tasks incidents changes uh inventory data so again very you know within one or two clicks trying to make that overall experience um you know easier and uh more intuitive essentially another example and and one thing i do like here in in san diego which is uh a new thing uh which i think for servicenow if you've been with servicenow or been a user of the platform is really the the difference between kind of a light and dark mode that could be an individual preference so really nice that we we finally have that and it's again just around the corner here with uh with the ga date just looming on the the 23rd another experience is uh the cloud operations workspace so we we we were just looking at and you're kind of getting this this theme of workspaces being able um being available and and really providing you a better overall experience so in this case this is for maybe the the cloud admins cloud ops um you have uh discovery you can look at your your schedules right uh based on if you're multi-cloud drill into the the discovery schedule the ci's the you know the overall uh inventory that you would otherwise do but again even you can link from one workspace to another so just giving you a very high level drive by so to speak of again what's just around the corner and then another uh i would say another aspect of the now experience is being able to kind of create your your own experience and that's where we have uh for example the the ui builder and here's an example of an ai ops workspace very this is custom but this is the realm of what's possible so uh being able to create for example an experience where you know you can you can now uh start to um really create the the components right that in a way that uh that you can now start to bring your experiences to the platform so in this case the same for example the same alert we were looking at you can get some uh related information all looking at all the uh the alerts themselves everything hyperlinkable maybe to another workspace in context activity uh tagging information um you know additional info as well as even you know providing maybe a timeline which is really important to understand you know how did how did this issue uh evolve um and and being able to see that visually from uh from that custom workspace or uh one of our out-of-the-box workspaces so a lot of flexibility uh we're really excited about the things that are just coming around the corner and uh hopefully you know this is something that you as service now customers will start to experience and and start taking forward uh and then the last thing uh i would say as another experience benjamin james uh mentioned that you know we can now start to be very targeted with our notifications out to ms teams and be able to take action on responses or maybe something like slack what we're seeing is even a growing a growing number of pas admins or cloud teams or site reliability engineers that are already working in environments like grafana so we've created a it's an open source project where you know we feel let's we've got all this uh great metadata uh very service-centric uh information that can be very valuable to these personas that may not log into servicenow directly but they're working out environments like grafana and they're using data sources like prometheus and and maybe even other vendor uh sources to mix and match uh their data together to really align to to you know to their persona so in this case we have uh this is maybe an event management view all the data is is queried uh in real time from the servicenow platform but it's just surfaced up visually within grafana and you can also have links to you know contextual links back into the platform if if there is a need for that but the idea is that all of this data that's coming could be ci data relationships there could be topology the clustering metric data in fact here's uh application services based on the criticality right or the business criticality and being able to just very quickly even drill into secondary uh secondary dashboards um and then what i would say is even having um the ability to uh to look at some of our i would say uh you know our agent client collectors uh that are providing uh even metric collection and um logging and things of that sort so again a very easy way for example in this case this is our agent client collector uh if i just choose let's just say we choose all of the metrics based on the last six hours here we close this little menu you know you can now start to look at all the data that's being collected it's also being baseline within our platform but very quickly this could also be very easy to drill into a specific area so not only are we showing the metrics but we can any active alerts any anomalies from a log perspective and um and even topology and metadata about about the attributes so again uh just a few little i would say it was a a little bit of a harbor cruise on various uh experiences that really may align to different personas within your organization whether they're kind of central i.t to even decentralized teams that manage platforms digital teams or even your site reliability engineers really yeah i want to thank carlos for doing such an awesome job explaining you know predictive apps what it is and what the value is you know with our unique unified and simplified approach you know service out is the only vendor that can really ingest all of this telemetry data from multiple sources in a very simplified manner and deliver meaningful outcomes for your business whether it's reducing outages predicting issues uh you know providing you know servicing root cause analysis very quickly so you can eliminate remediate those uh challenges as well as you know building those insights and servicing those the teams and whatever tools that they prefer so i'm going to wrap up here i'll pause for a minute or two see if there's any questions that come in and if not heather will close out
https://www.youtube.com/watch?v=FzGvHx-FpiQ