Live data from Hacker News

The Great Splunkbundling (2021)

rakgarg.substack.com

11–12 of 12 posts

Re: The Great Splunkbundling (2021)

#11
post #8

I think it's a space that's largely overengineered when classic solutions tend to work very well and are FOSS. On the log side, rsyslog, systemd-journal-remote, etc are being overlooked in favor of the behemoths like Splunk, and I think the real opportunity is in reducing the SIEM stack complexity by returning to simple tools that do their job well (unix philosophy). The problem is then VC's and their companies are t…

It's overengineered because if you just need "logging" and "insights" you have lots of open source options. If, however, you need "logging that an executive will put their signature to" suddenly you have very few options.

[deleted]

Re: The Great Splunkbundling (2021)

#12

They all sound like good recommendations, but there's not much in the way of a total drop in replacement for Splunk. You can build an ELK stack or something that resembles it, but you have to hire someone to directly maintain it and build out functionality. If you're a megacorp, that might make sense financially. I used to work at Splunk when they were still a fairly trendy start up, it was fun and I helped build out…

I was there as well for years until 2021 in cloud. The fact that you know Rainmaker is pretty solid evidence you know the evolution of cloud.
Post reply on HN