Live data from Hacker News

Cisco Acquires Splunk

splunk.com

211–220 of 525 posts

Re: Cisco Acquires Splunk

#211
post #79
post #9

Earlier quoted context omitted.

Which ones do you recommend? Every one I have tried hasn't really given me the same flexibility as Splunk, most seem to miss the core part of what makes Splunk cool. Though I'd definitely like to see Splunk improve their design.

Graylog looks like a good competitor. Certainly won't scale as well, but I've had good experience with it.

I used to love Graylog, but I was evaluated it for use with AWS and a) it's AWS bits seem limited and b) I found a bunch of deadlinks from their github to their site. If they can't keep their docs updated, it doesn't give me warm fuzzies about their product.

Re: Cisco Acquires Splunk

#212

Earlier quoted context omitted.

Everything on HN should be taken with a big ol' bag of salt. To do otherwise will cause you to miss out on both employment and investment opportunities you won't find elsewhere.

what other resources do you read?

I read everything I can consume (news, analysis, mailing lists, etc), but find smaller or private forums to be most valuable for participation. "Be conservative in what you send, be liberal in what you accept."

Re: Cisco Acquires Splunk

#213
post #108

To pile onto the Splunk "love" going on here. Splunk is one of those systems that's too "powerful" for small use-cases, but too expensive for the ones it's really designed for. Anecdote, I once worked with a client that really wanted to get Splunk, but produced so much network traffic that the discounted annual costs were more than the entire budget for the rest of the organization combined. That's staff, the buildin…

I'm not sure who splunk is priced for, because every company I've been at has ditched it for cheaper competitor products.

Re: Cisco Acquires Splunk

#214
post #157

Earlier quoted context omitted.

Sampling via just enabling it for some hosts/partitions is one solution (if you're producing 100M entries a day ... probably could just grab 1/100 of those for parsing). Another solution is pre-processing (serial dupes are not forwarded). Another solution is heavily reduced logging (ERR or higher only on prod hosts). These can be used together and be very helpful.

All technical workarounds for bad pricing.

Processing that amount of data is going to be expensive, regardless.

Re: Cisco Acquires Splunk

#215
post #108

To pile onto the Splunk "love" going on here. Splunk is one of those systems that's too "powerful" for small use-cases, but too expensive for the ones it's really designed for. Anecdote, I once worked with a client that really wanted to get Splunk, but produced so much network traffic that the discounted annual costs were more than the entire budget for the rest of the organization combined. That's staff, the buildin…

That's what I was wondering about when it comes to this acquisition. Can Cisco make Splunk even more expensive? I have faith they can, I know for many folks, Splunk tops the leaderboards when it comes to spend.

[deleted]

Re: Cisco Acquires Splunk

#216
post #108

To pile onto the Splunk "love" going on here. Splunk is one of those systems that's too "powerful" for small use-cases, but too expensive for the ones it's really designed for. Anecdote, I once worked with a client that really wanted to get Splunk, but produced so much network traffic that the discounted annual costs were more than the entire budget for the rest of the organization combined. That's staff, the buildin…

That's what I was wondering about when it comes to this acquisition. Can Cisco make Splunk even more expensive? I have faith they can, I know for many folks, Splunk tops the leaderboards when it comes to spend.

More expensive and less innovative.

Re: Cisco Acquires Splunk

#217
post #108

To pile onto the Splunk "love" going on here. Splunk is one of those systems that's too "powerful" for small use-cases, but too expensive for the ones it's really designed for. Anecdote, I once worked with a client that really wanted to get Splunk, but produced so much network traffic that the discounted annual costs were more than the entire budget for the rest of the organization combined. That's staff, the buildin…

That's what I was wondering about when it comes to this acquisition. Can Cisco make Splunk even more expensive? I have faith they can, I know for many folks, Splunk tops the leaderboards when it comes to spend.

Cisco will not be out competed in the expensive tech industry, so they had to buy them.

Re: Cisco Acquires Splunk

#218

I wonder if this segment is ready for disruption. Splunk is very expensive, ElasticSearch is still lacking many of the features of Splunk and when hosted on AWS is very expensive. SumoLogic was acquired by private equity, which means that it won't get cheaper. DataDog is also very expensive. Solution like SnowFlake for logs / telemetry where compute and storage are separated might be the future.

A stack we’ll see:

- panther siem (python alerts, thank the lord) and then pandas + databricks + s3 data lakes for deep analysis and IR

- maybe swap in panther SIEM for XDRs, if they get better out of the box

Re: Cisco Acquires Splunk

#219
post #53
post #35

Earlier quoted context omitted.

DarkSky seems to be a big exception to this

I disagree. Apple Weather has become an amazing app since the DarkSky acquisition. I especially like the hourly charts.

I wish Apple's hourly visuals for when it's going to rain didn't require a microscope to see.
Post reply on HN