Live data from Hacker News

Cisco Acquires Splunk

splunk.com

261–270 of 525 posts

Re: Cisco Acquires Splunk

#262

Somebody: Splunk has exorbitant prices and locked-in enterprise customers! Cisco: Oh these guys are just like us. Better buy them up. We know this business.

when you read Hacker News thread - every single one of them feels like the world is falling apart. Splunk is a dud or so everyone here thinks: https://siliconangle.com/2023/08/23/splunk-shares-surge-stro...

Splunk was an absolute game changer when a company I worked for bought it. I say bought because we started to pay for it before anyone actually used it for anything meaningful. The "adoption" (blaming the company that bought it not Splunk) was terrible and teams were left to find value or not at their discretion without onboarding/training.

The tool itself when I started using it was brilliant and quite deep on capabilities.

All that said, the cost structure for the product can and SHOULD scare away any SMBs. Hosted or cloud, you're probably paying way beyond the value it's bringing in. That's probably the single largest determinant to the product.

Re: Cisco Acquires Splunk

#263
post #33

Earlier quoted context omitted.

It's apparently cheaper to buy Splunk than to a buy Splunk license.

Microsoft’s “request for external license” form is one page long, and has a “how much would this company cost to acquire” section. Or so I’ve heard.

While at Microsoft, a project I was on was acquiring a license for a library and just to be sure of everything, instead of the standard "usage for this product" license, MS acquired a lifetime license to do whatever we wanted with the library.

Anyway tl;dr their lead engineer flew out and helped us get everything up and running. :-D

Re: Cisco Acquires Splunk

#264
post #162

Earlier quoted context omitted.

Splunk does not scale to large data sources. It fucks out at a few TB and then you have to spend hours on the phone trying to work out which combination of licenses and sales reps you need to get going again. By which time you can just suck the damn log file and grep it on the box.

I've worked at companies with objectively large amounts of data. Splunk scaled to meet their workloads. At no enterprise doing this is someone able to just isolate a single log file and grep through it at scale.

Presumably you can have a cluster of grepping machines. I wonder how it scales compared to the millions you pay for Splunk.

Re: Cisco Acquires Splunk

#265
post #261

Somebody had a 45,650% gain in one overnight trade on $SPLK calls. Amazing luck. [1] Someone opened 127 calls for $22,000, and closed them today after the buy-out announcement. A cool way to turn $22,000 into $10,043,000 [1] https://www.reddit.com/r/wallstreetbets/comments/16oi9an/som...

99.99% that's insider trading.

Re: Cisco Acquires Splunk

#267
post #108

To pile onto the Splunk "love" going on here. Splunk is one of those systems that's too "powerful" for small use-cases, but too expensive for the ones it's really designed for. Anecdote, I once worked with a client that really wanted to get Splunk, but produced so much network traffic that the discounted annual costs were more than the entire budget for the rest of the organization combined. That's staff, the buildin…

My experience back in Netflix too. Elasticsearch (we didn't use the L or K) plus query engine on S3 with a catalog was more versatile and way cheaper than Splunk. Nowadays we get a slew of performant OLAP storages that can be used for log analysis as well, which further render Splunk unnecessary.

[deleted]

Re: Cisco Acquires Splunk

#268
post #257

Earlier quoted context omitted.

But, and this is not meant as criticism or insult as I have no idea how Splunk works, it is just based on other comments; do you know what license your company has with them? It appears that if you are paying them millions, it scales fine, otherwise, it does not?

> I have no idea how Splunk works Cool > It appears that if you are paying them millions, it scales fine yes, if you pay someone for product and services, you get them. If you don't, you don't

Yeah, because that is what I meant. A lot of services are useable without paying through the nose, this one apparently not, but thanks for the excellent input.

Re: Cisco Acquires Splunk

#270
post #9
post #4

Genuinely surprised anybody would acquire Splunk in 2023. Whenever you hear about Splunk from security engineers, they're actively trying to get off it (edit: yes, primarily because of cost). Better, next-gen SIEMs are either here or around the corner.

Which ones do you recommend? Every one I have tried hasn't really given me the same flexibility as Splunk, most seem to miss the core part of what makes Splunk cool. Though I'd definitely like to see Splunk improve their design.

There are some players that are more established than others but check out:

https://panther.com - Built on top of Snowflake, so it scales well and they are building a more Splunk like interface.

https://runreveal.com - Still seed but shows a lot of promise

https://matando.dev - Still seed and don't have a hosted product yet but smart founders that have the right idea

https://hunters.ai - More threat hunting than SIEM but maybe that what certain folks need

https://gem.security - Still fairly early but if you are focused on cloud use cases this could be more of an option. (Disclaimer: I'm an Investor)

Post reply on HN