To pile onto the Splunk "love" going on here. Splunk is one of those systems that's too "powerful" for small use-cases, but too expensive for the ones it's really designed for. Anecdote, I once worked with a client that really wanted to get Splunk, but produced so much network traffic that the discounted annual costs were more than the entire budget for the rest of the organization combined. That's staff, the buildin…
Cisco Acquires Splunk
241–250 of 525 posts
Re: Cisco Acquires Splunk
#242Re: Cisco Acquires Splunk
#243I hated Splunk so much that I spent a couple days a few months ago writing a single 1200 line python script that does absolutely everything I need in terms of automatic log collection, ingestion, and analysis from a fleet of cloud instances. It pulls in all the log lines, enriches them with useful metadata like the IP address of the instance, the machine name, the log source, the datetime, etc. and stores it all in S…
Re: Cisco Acquires Splunk
#244Earlier quoted context omitted.
I remember this talk about pricing strategy by one of their employees in a conference many years back (2017) - https://www.heavybit.com/library/video/value-based-pricing-s... . What I took away from that talk was that pricing can be unintuitive, for both the people setting it and buying it.
I just watched the whole video and didn't get that impression at all
Re: Cisco Acquires Splunk
#245Also, is it under the hood some Apache SOLR or ES? Or they have their own?
Re: Cisco Acquires Splunk
#246I hated Splunk so much that I spent a couple days a few months ago writing a single 1200 line python script that does absolutely everything I need in terms of automatic log collection, ingestion, and analysis from a fleet of cloud instances. It pulls in all the log lines, enriches them with useful metadata like the IP address of the instance, the machine name, the log source, the datetime, etc. and stores it all in S…
have you released this anywhere
Re: Cisco Acquires Splunk
#247I wonder if this segment is ready for disruption. Splunk is very expensive, ElasticSearch is still lacking many of the features of Splunk and when hosted on AWS is very expensive. SumoLogic was acquired by private equity, which means that it won't get cheaper. DataDog is also very expensive. Solution like SnowFlake for logs / telemetry where compute and storage are separated might be the future.
Re: Cisco Acquires Splunk
#248Re: Cisco Acquires Splunk
#249Earlier quoted context omitted.
Are medium-sized customers valuable to Splunk? In sales we call this "Ideal Customer Profile." Why do I want a customer with less money to spend if I have a product with enough capability for the gigantic money-is-no-object customers?
Mindshare is valuable, was the point GP was making. If midsize customers ignore you because you're too expensive, and then implement something else before they get big enough to afford you, where do you get new customers? Forget growth, how do you replace attrition as your existing customers die? Personally I can't say if that's actually happening with Splunk, but it's a very plausible scenario.
Somehow companies manage to make it work extracting money from your existing money-is-no-object customers. Oracle and IBM have basically zero mind-share amongst HN reading folks, but yet there they are.
Re: Cisco Acquires Splunk
#250Earlier quoted context omitted.
Splunk does not scale to large data sources. It fucks out at a few TB and then you have to spend hours on the phone trying to work out which combination of licenses and sales reps you need to get going again. By which time you can just suck the damn log file and grep it on the box.
I'm gonna respectfully disagree that it fails "at a few TB". We send them 100s of terabytes a day.