Live data from Hacker News

Cisco Acquires Splunk

splunk.com

181–190 of 525 posts

Re: Cisco Acquires Splunk

#182

I hated Splunk so much that I spent a couple days a few months ago writing a single 1200 line python script that does absolutely everything I need in terms of automatic log collection, ingestion, and analysis from a fleet of cloud instances. It pulls in all the log lines, enriches them with useful metadata like the IP address of the instance, the machine name, the log source, the datetime, etc. and stores it all in S…

look at vector.dev and clickhouse. fast, has a language for extension, v easy to set up.

I used Vector in the Beaker Studio prototype back when it was designed to deploy directly to Ubuntu virtual machines. That was a couple years ago at this point, and it worked wonderfully!

Re: Cisco Acquires Splunk

#183
post #119
post #108

To pile onto the Splunk "love" going on here. Splunk is one of those systems that's too "powerful" for small use-cases, but too expensive for the ones it's really designed for. Anecdote, I once worked with a client that really wanted to get Splunk, but produced so much network traffic that the discounted annual costs were more than the entire budget for the rest of the organization combined. That's staff, the buildin…

> That's staff, the building, equipment, power, water, everything...the estimated Splunk cost was more than that. Wow, it's THAT expensive?

The joke used to be 'splunk is amazing until the first invoice comes in', it's funny because it's true. Note Datadog is very similar in that regard.

Re: Cisco Acquires Splunk

#184
post #108

To pile onto the Splunk "love" going on here. Splunk is one of those systems that's too "powerful" for small use-cases, but too expensive for the ones it's really designed for. Anecdote, I once worked with a client that really wanted to get Splunk, but produced so much network traffic that the discounted annual costs were more than the entire budget for the rest of the organization combined. That's staff, the buildin…

Sounds like something Oracle would love.

It has to be insanely complicated with horrible UX too so probably did not pass.

Re: Cisco Acquires Splunk

#185

Somebody: Splunk has exorbitant prices and locked-in enterprise customers! Cisco: Oh these guys are just like us. Better buy them up. We know this business.

Startup Founder: Come, Hack Big Log Processing With Us! (Goes on to launch an undifferentiated cloud log processing with a hilarious comparison sheet)

Re: Cisco Acquires Splunk

#186
post #6

Earlier quoted context omitted.

[flagged]

There’s a couple out there, Devo, Exabeam and Sumo Logic are the big three I’ve seen most recently.

Avoid Exabeam. Their UEBA product is riddled with problems, and they are not concerned that it does not display timestamps for when the event occurred- they display timestamps for event ingestion which can sometimes be hours off.

They also seem to outsource much of the development, maintenance and support and appear to have high turnover.

Re: Cisco Acquires Splunk

#187
post #108

To pile onto the Splunk "love" going on here. Splunk is one of those systems that's too "powerful" for small use-cases, but too expensive for the ones it's really designed for. Anecdote, I once worked with a client that really wanted to get Splunk, but produced so much network traffic that the discounted annual costs were more than the entire budget for the rest of the organization combined. That's staff, the buildin…

Sounds like something Oracle would love.

[dead]

Re: Cisco Acquires Splunk

#188
post #64

Earlier quoted context omitted.

It's around 6 data sources on ~25 machines, but it could be easily scaled to way more than that with a bit of work. And I mean less work than it takes to do even trivially simple things using the horrible Splunk API. There are many thousands of small companies using Splunk and getting totally ripped off for a very mediocre product with a rapacious and annoyingly aggressive salesforce.

That is a tiny setup all things considered. You aren’t operating at a scale you’d need to consider a monitoring platform for.

How many servers does Stack overflow run on? It’s not a good measure of data volume or criticality.

I think “expensive” here is basically relative to revenue/margin. Where margins are high, spending on Splunk (etc.) isn’t meaningful. Where margins are thin, it hurts.

Basically, the arguments here seem to reflect the markets and business model folks are working under. Some pay, some can’t and some won’t - all valid.

Re: Cisco Acquires Splunk

#189
post #183
post #119

Earlier quoted context omitted.

> That's staff, the building, equipment, power, water, everything...the estimated Splunk cost was more than that. Wow, it's THAT expensive?

The joke used to be 'splunk is amazing until the first invoice comes in', it's funny because it's true. Note Datadog is very similar in that regard.

Yes ... it's very possible for DataDog costs to exceed the cost of the infrastructure that it's monitoring (e.g. AWS). I've seen it happen.

(If you aren't careful and aren't managing your costs, but I suppose that's true of almost anything =)

Re: Cisco Acquires Splunk

#190
post #144

Earlier quoted context omitted.

> I believe the idea is that the big customers are interested because everyone is raving about it. If you price out the smaller customers, there's nobody to rave about it. That's not how enterprise procurement works, which is what makes the big bucks for companies like Akamai and Splunk. Cloudflare traditionally targeted mid-market and is in the process of building out an upper market/enterprise motion (I worked with…

How is what I said "FUD"? I know what it stands for. I don't see where I went with any of those three themes. Akamai has certainly done well over their lifetime, but their revenue for the last 5 years is very flat. That's not "FUD".

That wasn't aimed at you. I meant the general discourse of Enterprise Sales and GTM on HN is filled with FUD
Post reply on HN