Live data from Hacker News

Cisco Acquires Splunk

splunk.com

161–170 of 525 posts

Re: Cisco Acquires Splunk

#161
post #33

Earlier quoted context omitted.

It's apparently cheaper to buy Splunk than to a buy Splunk license.

You may be joking but this is why we thought Cisco bought Webex back in the day too.

They bought WebEx for the same reason as most of their other acquisitions: vertical integration and diversified interests. It doesn't even have to work well, it just has to be a feature they can advertise, and dumb executives will assume it works and buy it. By the time they've got their hooks into you, you realize it'll take years to remove it. Pretty good cash flow for years before the customer jumps ship.

What's fascinating is that working inside Cisco, the same tricks work on them. We'd adopt a vendor only to realize it doesn't do what we want, but now we're kinda stuck on them and it costs more to replace them. It's a bog-standard giant enterprise where the left hand doesn't know what the right hand is doing. But they're wizards with cash.

Re: Cisco Acquires Splunk

#162
post #54

I hated Splunk so much that I spent a couple days a few months ago writing a single 1200 line python script that does absolutely everything I need in terms of automatic log collection, ingestion, and analysis from a fleet of cloud instances. It pulls in all the log lines, enriches them with useful metadata like the IP address of the instance, the machine name, the log source, the datetime, etc. and stores it all in S…

For how many data sources? The whole reason everyone goes to Splunk is that it scales, and scales incredibly well. Large enterprises can generate hundreds of terabytes to petabytes every day. Splunk has all sorts of issues, but to pretend as if you can replace them in any large shop with a 1200 line python script and SQLite is just being disingenuous. This acquisition falls right into Cisco's sweet spot, they aren't…

Splunk does not scale to large data sources. It fucks out at a few TB and then you have to spend hours on the phone trying to work out which combination of licenses and sales reps you need to get going again.

By which time you can just suck the damn log file and grep it on the box.

Re: Cisco Acquires Splunk

#163
post #13
post #4

Genuinely surprised anybody would acquire Splunk in 2023. Whenever you hear about Splunk from security engineers, they're actively trying to get off it (edit: yes, primarily because of cost). Better, next-gen SIEMs are either here or around the corner.

Splunk is a great product with horrible sales and business team. The reason why them _trying_ to get off it is because they have a bunch of stuff that is easy and works in splunk, but don't want to pay the exorbitant licensing, or pay even more to increase their use. But getting off a good product is hard, and they will continue to use it and even pay. The kind of thing Cisco, Oracle, and IBM love are companies with…

Yeah it's easier getting rid of chlamydia than Splunk sales reps.

Re: Cisco Acquires Splunk

#164
post #13

Earlier quoted context omitted.

Splunk is a great product with horrible sales and business team. The reason why them _trying_ to get off it is because they have a bunch of stuff that is easy and works in splunk, but don't want to pay the exorbitant licensing, or pay even more to increase their use. But getting off a good product is hard, and they will continue to use it and even pay. The kind of thing Cisco, Oracle, and IBM love are companies with…

> with horrible sales and business team I was in one of these meetings with like 20 engineers on how amazing this thing was. We knew that because we already used it it quite extensively. The very extremely hyper sales rep kept ducking out of the meeting every 5 mins. I recognized it for what it was. He was ducking out to do bumps of coke so he could be more pumped to sell us more stuff.

I think we had the same sales rep.

Re: Cisco Acquires Splunk

#165

Does anyone have an example of an acquisition where the products of the acquired company then became better?

There are exception, but Microsoft seems pretty good at this. GitHub, Minecraft... Skype got a lot better for me in terms of reliability after the acquisition too, of course they've been competed away by other voips like Facetime and Whatsapp these days.

LinkedIn is better than ever for finding a job, or advertising a job, even though lots of people here don't like it because of the LinkedIn poasting culture.

Re: Cisco Acquires Splunk

#167
post #13

Earlier quoted context omitted.

Splunk is a great product with horrible sales and business team. The reason why them _trying_ to get off it is because they have a bunch of stuff that is easy and works in splunk, but don't want to pay the exorbitant licensing, or pay even more to increase their use. But getting off a good product is hard, and they will continue to use it and even pay. The kind of thing Cisco, Oracle, and IBM love are companies with…

> with horrible sales and business team I was in one of these meetings with like 20 engineers on how amazing this thing was. We knew that because we already used it it quite extensively. The very extremely hyper sales rep kept ducking out of the meeting every 5 mins. I recognized it for what it was. He was ducking out to do bumps of coke so he could be more pumped to sell us more stuff.

jesus, that's incredible

Re: Cisco Acquires Splunk

#168

I hated Splunk so much that I spent a couple days a few months ago writing a single 1200 line python script that does absolutely everything I need in terms of automatic log collection, ingestion, and analysis from a fleet of cloud instances. It pulls in all the log lines, enriches them with useful metadata like the IP address of the instance, the machine name, the log source, the datetime, etc. and stores it all in S…

Sounds awesome for your use case!

…but this sounds so much like the legendary Dropbox release thread’s ”just use FTP, SVN, etc” that it made me smile :)

Re: Cisco Acquires Splunk

#169
post #54

Earlier quoted context omitted.

For how many data sources? The whole reason everyone goes to Splunk is that it scales, and scales incredibly well. Large enterprises can generate hundreds of terabytes to petabytes every day. Splunk has all sorts of issues, but to pretend as if you can replace them in any large shop with a 1200 line python script and SQLite is just being disingenuous. This acquisition falls right into Cisco's sweet spot, they aren't…

It's around 6 data sources on ~25 machines, but it could be easily scaled to way more than that with a bit of work. And I mean less work than it takes to do even trivially simple things using the horrible Splunk API. There are many thousands of small companies using Splunk and getting totally ripped off for a very mediocre product with a rapacious and annoyingly aggressive salesforce.

Splunk isn't perfect. Managing it is more work than it should be for example. But I've got hundreds of systems I'm pulling logs from and that's not counting infra and applications as well. And my deployment isn't even a large one by their standards. Your use case just isn't the scale where splunk makes sense.

Re: Cisco Acquires Splunk

#170

Earlier quoted context omitted.

when you read Hacker News thread - every single one of them feels like the world is falling apart. Splunk is a dud or so everyone here thinks: https://siliconangle.com/2023/08/23/splunk-shares-surge-stro...

This is not actually dissonant! HN is mostly a place where technologists gather, not corporate heads of IT or other business people. This is especially true of the subset of users who actively participate rather than only reading. And it is not unusual in the least for an enterprise product to be wildly profitable but not admired by technologists. Indeed, it's the default; Oracle, SAP, Microsoft, etc. What is interes…

I have some bad news about Red Hat...
Post reply on HN