Live data from Hacker News

Splunk IP suit against Cribl

splunk.com

101–107 of 107 posts

Re: Splunk IP suit against Cribl

#101

Earlier quoted context omitted.

Pretty poor that S2S is a proprietary protocol to begin with.

From the lawsuit: Although Splunk provides HEC for third parties to use, Splunk maintains other aspects of its software as proprietary. One example of such proprietary software is the “S2S” protocol. S2S stands for “Splunk-to-Splunk,” and this is software that Splunk itself uses to send data to, or receive data from, Splunk Enterprise and other Splunk software and technologies. Splunk does not support use of S2S by t…

I still think that is poor form.

Re: Splunk IP suit against Cribl

#102
post #75

Earlier quoted context omitted.

Sad. Splunk should be more fantastic. They have done the heavy lifting of taking streams of data at high volume, which should be the basis to build a log search product, metrics And alerting, and observability. Instead, each of these systems have their own collectors and correlating from one to the other is hard. A canonical log line is so much more valuable than a metric collected every 60 seconds, and the former ca…

I built a PCI compliance solution for a customer back in 2008 for ~$200k all-in when the closest competitor's bid was five times that. The product was amazing at runtime but of course had some idiosyncrasies in how it was configured and whatnot. I've been a user (only) of Splunk heavily ever since and just last year got pulled into a project to migrate a huge install to a cloud platform. It felt like I got into a tim…

Yeah, team decided K8s for Splunk would be too much work and ended up needing to use vanilla VM’s with block storage on an open stack env on prem.

Pretty lame not cloud native.

Re: Splunk IP suit against Cribl

#104

Earlier quoted context omitted.

What are you planning to move to?

Sounds crazy, but Datadog. I’ve been hammering their product teams for years with specific use cases for the sole purpose of replacing Splunk. They recently migrated search technologies and are rapidly closing the gap. Plus, their exclusion features are instant and fantastic, and their C-suite replies to me when I escalate. Elasticsearch simply couldn’t handle key collisions. We have hundreds of various apps across 5…

Would love to know more about specific use-cases you've been talking to Datadog about. I'm starting a company (log-store.com) that I pitch to people as 75% of the features of Splunk at 50% the price. Right now that 75% is probably more like 25%, and the 50% is _actually_ 0%... it's FREE! Any and all feedback is greatly appreciated!

Re: Splunk IP suit against Cribl

#105

I would love to use splunk on some of my side projects. Does anyone know of a decent alternative for non-enterprise customers?

I posted above, but starting log-store.com so I'm trying to promote it in threads without being too pushy :-)

It's in beta and free. My plan is honestly to have my pricing be free for small amounts of data, and then 50% the price of Splunk for larger data sets. Just show me an invoice, and you'll pay half!

Re: Splunk IP suit against Cribl

#106

I would love to use splunk on some of my side projects. Does anyone know of a decent alternative for non-enterprise customers?

(co-founder here) Try axiom.co - we support splunk-like query syntax, dashboards, monitors, unlimited sources/hosts/etc, and you get 500GB/mo ingest + 30 days retention on the free plan.

Re: Splunk IP suit against Cribl

#107

Earlier quoted context omitted.

we had an on-prem splunk implementation and it was SOO SLOW.. it was built/managed by splunk and its consultants. We finally got rid of it a few years later, but for the entire time we had it, it was a constant "round hole square peg" problems. Each time the consultants assured us Splunk could do what we needed, each time it could not.

I wonder if Splunk has a QA problem with their consultants or if there are certain edge cases they simply don't do well with. Just that it looks like most people here had a good experience and we had a bad one for some reason.

Just coming back around to this, we also used Splunk consultants for their SIEM solution and the first one we got wasn't very good, but the second was amazing (I wish we could have hired her directly).

The guy we had help us tune our clusters after I rebuilt them all was also very good. Fortunately I'd done most everything by the books and we overkilled the nodes with hardware (we had some older hypervisor nodes lying around I stole for Splunk).

Post reply on HN