I think it's a space that's largely overengineered when classic solutions tend to work very well and are FOSS. On the log side, rsyslog, systemd-journal-remote, etc are being overlooked in favor of the behemoths like Splunk, and I think the real opportunity is in reducing the SIEM stack complexity by returning to simple tools that do their job well (unix philosophy). The problem is then VC's and their companies are t…
It's overengineered because if you just need "logging" and "insights" you have lots of open source options. If, however, you need "logging that an executive will put their signature to" suddenly you have very few options.
Re: The Great Splunkbundling (2021)
#11[deleted]