Earlier quoted context omitted.
Which ones do you recommend? Every one I have tried hasn't really given me the same flexibility as Splunk, most seem to miss the core part of what makes Splunk cool. Though I'd definitely like to see Splunk improve their design.
Graylog looks like a good competitor. Certainly won't scale as well, but I've had good experience with it.
Cisco Acquires Splunk
211–220 of 525 posts
Re: Cisco Acquires Splunk
#212Earlier quoted context omitted.
Everything on HN should be taken with a big ol' bag of salt. To do otherwise will cause you to miss out on both employment and investment opportunities you won't find elsewhere.
what other resources do you read?
Re: Cisco Acquires Splunk
#213To pile onto the Splunk "love" going on here. Splunk is one of those systems that's too "powerful" for small use-cases, but too expensive for the ones it's really designed for. Anecdote, I once worked with a client that really wanted to get Splunk, but produced so much network traffic that the discounted annual costs were more than the entire budget for the rest of the organization combined. That's staff, the buildin…
Re: Cisco Acquires Splunk
#214Earlier quoted context omitted.
Sampling via just enabling it for some hosts/partitions is one solution (if you're producing 100M entries a day ... probably could just grab 1/100 of those for parsing). Another solution is pre-processing (serial dupes are not forwarded). Another solution is heavily reduced logging (ERR or higher only on prod hosts). These can be used together and be very helpful.
All technical workarounds for bad pricing.
Re: Cisco Acquires Splunk
#215To pile onto the Splunk "love" going on here. Splunk is one of those systems that's too "powerful" for small use-cases, but too expensive for the ones it's really designed for. Anecdote, I once worked with a client that really wanted to get Splunk, but produced so much network traffic that the discounted annual costs were more than the entire budget for the rest of the organization combined. That's staff, the buildin…
That's what I was wondering about when it comes to this acquisition. Can Cisco make Splunk even more expensive? I have faith they can, I know for many folks, Splunk tops the leaderboards when it comes to spend.
Re: Cisco Acquires Splunk
#216To pile onto the Splunk "love" going on here. Splunk is one of those systems that's too "powerful" for small use-cases, but too expensive for the ones it's really designed for. Anecdote, I once worked with a client that really wanted to get Splunk, but produced so much network traffic that the discounted annual costs were more than the entire budget for the rest of the organization combined. That's staff, the buildin…
That's what I was wondering about when it comes to this acquisition. Can Cisco make Splunk even more expensive? I have faith they can, I know for many folks, Splunk tops the leaderboards when it comes to spend.
Re: Cisco Acquires Splunk
#217To pile onto the Splunk "love" going on here. Splunk is one of those systems that's too "powerful" for small use-cases, but too expensive for the ones it's really designed for. Anecdote, I once worked with a client that really wanted to get Splunk, but produced so much network traffic that the discounted annual costs were more than the entire budget for the rest of the organization combined. That's staff, the buildin…
That's what I was wondering about when it comes to this acquisition. Can Cisco make Splunk even more expensive? I have faith they can, I know for many folks, Splunk tops the leaderboards when it comes to spend.
Re: Cisco Acquires Splunk
#218I wonder if this segment is ready for disruption. Splunk is very expensive, ElasticSearch is still lacking many of the features of Splunk and when hosted on AWS is very expensive. SumoLogic was acquired by private equity, which means that it won't get cheaper. DataDog is also very expensive. Solution like SnowFlake for logs / telemetry where compute and storage are separated might be the future.
- panther siem (python alerts, thank the lord) and then pandas + databricks + s3 data lakes for deep analysis and IR
- maybe swap in panther SIEM for XDRs, if they get better out of the box
Re: Cisco Acquires Splunk
#219Earlier quoted context omitted.
DarkSky seems to be a big exception to this
I disagree. Apple Weather has become an amazing app since the DarkSky acquisition. I especially like the hourly charts.
Re: Cisco Acquires Splunk
#220Somebody: Splunk has exorbitant prices and locked-in enterprise customers! Cisco: Oh these guys are just like us. Better buy them up. We know this business.