Live data from Hacker News

Cisco Acquires Splunk

splunk.com

281–290 of 525 posts

Re: Cisco Acquires Splunk

#281

Earlier quoted context omitted.

This is not actually dissonant! HN is mostly a place where technologists gather, not corporate heads of IT or other business people. This is especially true of the subset of users who actively participate rather than only reading. And it is not unusual in the least for an enterprise product to be wildly profitable but not admired by technologists. Indeed, it's the default; Oracle, SAP, Microsoft, etc. What is interes…

stripe, cloudflare (ish), github

> that are both profitable

none of these are currently profitable

Re: Cisco Acquires Splunk

#282
post #280
post #257

Earlier quoted context omitted.

> I have no idea how Splunk works Cool > It appears that if you are paying them millions, it scales fine yes, if you pay someone for product and services, you get them. If you don't, you don't

It's difficult to control data ingress so you end up in debt and on repayment plans. Which are expensive.

That makes sense, so looking at what people ingress, they pay afterwards or just really huge plans upfront? Or a mix?

Re: Cisco Acquires Splunk

#283
post #183

Earlier quoted context omitted.

The joke used to be 'splunk is amazing until the first invoice comes in', it's funny because it's true. Note Datadog is very similar in that regard.

Yes ... it's very possible for DataDog costs to exceed the cost of the infrastructure that it's monitoring (e.g. AWS). I've seen it happen. (If you aren't careful and aren't managing your costs, but I suppose that's true of almost anything =)

Sounds like a double whammy. Misconfigure one AWS service, and you get hit with a giant bill from both.

Re: Cisco Acquires Splunk

#284
post #108

To pile onto the Splunk "love" going on here. Splunk is one of those systems that's too "powerful" for small use-cases, but too expensive for the ones it's really designed for. Anecdote, I once worked with a client that really wanted to get Splunk, but produced so much network traffic that the discounted annual costs were more than the entire budget for the rest of the organization combined. That's staff, the buildin…

I’ve had the same experience in that I love splunk and their tooling is so easy and powerful. But I can’t afford to put data, especially long term data that requires reproducibility for many years.

I’m always happy when I can use some of our sources that are in splunk but get sad that I can’t do that with everything else.

Its cloud pricing is funny because it’s so much more powerful with massive amounts of data, but they charge based on storage. Our on prem instance wasn’t just simpler to price but we could throttle resources to allow for really high volumes of data with relatively slow query and analysis.

Re: Cisco Acquires Splunk

#286
post #4

Genuinely surprised anybody would acquire Splunk in 2023. Whenever you hear about Splunk from security engineers, they're actively trying to get off it (edit: yes, primarily because of cost). Better, next-gen SIEMs are either here or around the corner.

Its a great fit for Cisco

They want so hard to be a software company, and they already have experience with highly inflated priced products.

Their real target is probably trying to offer this built in to meraki like products as a one stop shop. I could see them finally burning their monitoring product in a fire and replacing it with splunk and grafana then selling it as an all cloud solution. At least the intent, we know Cisco's track record for integrating acquisitions.

Re: Cisco Acquires Splunk

#287

Earlier quoted context omitted.

Cisco cash is flowing out to Splunk shareholders so it makes sense that its equity value is X% lower after announcement

There are ~4bn Cisco shares outstanding. CSCO is down $2. So the market thinks that Cisco is overpaying by $8bn, or a 33 percent premium. Seems pretty bang on to me. Score one for the efficient market hypothesis.

“the market thinks” is an expression that makes me cringe. The market does not think, it’s the result of multiple actions, which many many people pretend they can explain or even predict when really they cannot.

"the market thinks” gives the stock trade market an aura of reason and intelligence which it absolutely does not deserve for many historical reasons. Trading as it exists today is unhinged capitalism, it’s a cancer on our societies as it widens the gap between rich and poor. It should be taxed, something like an Automated Payment Transaction tax, to make high frequency or even medium frequency trading simply unrentable.

I’m not against the concept of stocks in general, but the way it operates now is simply sick, I don’t see how to phrase this differently.

Re: Cisco Acquires Splunk

#288
post #54

Earlier quoted context omitted.

For how many data sources? The whole reason everyone goes to Splunk is that it scales, and scales incredibly well. Large enterprises can generate hundreds of terabytes to petabytes every day. Splunk has all sorts of issues, but to pretend as if you can replace them in any large shop with a 1200 line python script and SQLite is just being disingenuous. This acquisition falls right into Cisco's sweet spot, they aren't…

It's around 6 data sources on ~25 machines, but it could be easily scaled to way more than that with a bit of work. And I mean less work than it takes to do even trivially simple things using the horrible Splunk API. There are many thousands of small companies using Splunk and getting totally ripped off for a very mediocre product with a rapacious and annoyingly aggressive salesforce.

Wait what this is such an important detail. Log aggregators like Splunk start being something to consider when you get to about 25 THOUSAND machines, not 25 machines. I hope that for you, humility will come with experience.

Re: Cisco Acquires Splunk

#289

I hated Splunk so much that I spent a couple days a few months ago writing a single 1200 line python script that does absolutely everything I need in terms of automatic log collection, ingestion, and analysis from a fleet of cloud instances. It pulls in all the log lines, enriches them with useful metadata like the IP address of the instance, the machine name, the log source, the datetime, etc. and stores it all in S…

This comment is incredibly naive. Cisco isn't making acquisition decisions based on your happiness. Splunk's revenue is increasing every year and their losses decrease. It is an incredibly popular tool that complements their products and services well.

Re: Cisco Acquires Splunk

#290
post #162
post #54

Earlier quoted context omitted.

For how many data sources? The whole reason everyone goes to Splunk is that it scales, and scales incredibly well. Large enterprises can generate hundreds of terabytes to petabytes every day. Splunk has all sorts of issues, but to pretend as if you can replace them in any large shop with a 1200 line python script and SQLite is just being disingenuous. This acquisition falls right into Cisco's sweet spot, they aren't…

Splunk does not scale to large data sources. It fucks out at a few TB and then you have to spend hours on the phone trying to work out which combination of licenses and sales reps you need to get going again. By which time you can just suck the damn log file and grep it on the box.

Uhhhh you splunk scales no matter the size. for just pure ingest. Now if you got duped into the SVC model I can see what you mean. But for pure Gigs/Day ingest if you know what youre doing it can scale infinitely.
Post reply on HN