Live data from Hacker News

Cisco Acquires Splunk

splunk.com

311–320 of 525 posts

Re: Cisco Acquires Splunk

#311
post #277
post #60

Earlier quoted context omitted.

Are medium-sized customers valuable to Splunk? In sales we call this "Ideal Customer Profile." Why do I want a customer with less money to spend if I have a product with enough capability for the gigantic money-is-no-object customers?

That's why companies die in the long run. Microsoft dominated the nineties especially and the naughts less so but still because the marginal price of their OS was zero - due to piracy. Yes they didn't like business to run unlicensed but if you were a customer, nobody cared, because in 5-10-20 years you'd be a paying business or would work for a paying business. Splunk doesn't get that. There are no hobbyist/prosumer…

> Splunk doesn't get that. There are no hobbyist/prosumer splunk installations. Zero. Nada.

Not true. I ran a free (legit!) Splunk instance in my homelab for years. It's been several years since I shut the homelab down, so I couldn't tell you if they still have hobbyist licensing, but they certainly had it in the past.

Re: Cisco Acquires Splunk

#312
post #9

Earlier quoted context omitted.

Which ones do you recommend? Every one I have tried hasn't really given me the same flexibility as Splunk, most seem to miss the core part of what makes Splunk cool. Though I'd definitely like to see Splunk improve their design.

There are some players that are more established than others but check out: https://panther.com - Built on top of Snowflake, so it scales well and they are building a more Splunk like interface. https://runreveal.com - Still seed but shows a lot of promise https://matando.dev - Still seed and don't have a hosted product yet but smart founders that have the right idea https://hunters.ai - More threat hunting than SIEM…

Founder of runreveal here, if anyone is interested let me know. The news today was big, but not necessarily too surprising.

Re: Cisco Acquires Splunk

#313
post #108

To pile onto the Splunk "love" going on here. Splunk is one of those systems that's too "powerful" for small use-cases, but too expensive for the ones it's really designed for. Anecdote, I once worked with a client that really wanted to get Splunk, but produced so much network traffic that the discounted annual costs were more than the entire budget for the rest of the organization combined. That's staff, the buildin…

Having used other ELK stacks for logging, but never Splunk, what makes them worth what they charge?

Re: Cisco Acquires Splunk

#315

Earlier quoted context omitted.

Actually yeah, closer than most. I think it's a somewhat grudging admiration at this point, increasingly so as they do more and more also-ran services. But yeah, this does seem right for the "core" services; ec2, s3, maybe lambda, etc.

AWS business model is to just literally take a popular OSS system and provide it as a service. It was like that from the beginning. That's why there's much less animosity towards AWS, because they just allow you to run your X without the overhead of infra investment.

Maybe in the beginning. Taking an OSS package, cloning its wire protocol, and then offering their closed source almost-compatible version without having to contribute anything back upstream earns them a lot of animosity.

Re: Cisco Acquires Splunk

#316

Earlier quoted context omitted.

Worked at a medium size enterprise and was trying to get some detailed performance metrics with a legacy tech stack that didn't have a drop-in APM soluion. This was in the age of graphite which was great for aggregating metrics cheap but not getting detail. Splunk was used by a much larger product (easily 10x our scale) for monitoring events so there was no red tape to start using it. After launching the detailed ins…

We had an ELK stack I was never very happy with (granted it was very old versions) and then it got replaced by Clickhouse. It’s been excellent.

E in it is great, L is fiddly but useful but K is easily my least liked tool

Re: Cisco Acquires Splunk

#317
post #285

Earlier quoted context omitted.

They would do that for you for free

Oracle? Cisco? Do something for somebody else for free? Are you mad? They'll license the fire, and calculate the fees based on volume of air heated.

… and then sue passers-by for pirating their pre-warmed air.

Re: Cisco Acquires Splunk

#319
post #108

To pile onto the Splunk "love" going on here. Splunk is one of those systems that's too "powerful" for small use-cases, but too expensive for the ones it's really designed for. Anecdote, I once worked with a client that really wanted to get Splunk, but produced so much network traffic that the discounted annual costs were more than the entire budget for the rest of the organization combined. That's staff, the buildin…

Splunk is honestly kind of the mainframe of SIEM. If you need it, you need it and can probably afford it and they know that. Can you do the job with something else for cheaper? Probably, but not as good and not as easy.

Re: Cisco Acquires Splunk

#320
post #64

Earlier quoted context omitted.

It's around 6 data sources on ~25 machines, but it could be easily scaled to way more than that with a bit of work. And I mean less work than it takes to do even trivially simple things using the horrible Splunk API. There are many thousands of small companies using Splunk and getting totally ripped off for a very mediocre product with a rapacious and annoyingly aggressive salesforce.

That is a tiny setup all things considered. You aren’t operating at a scale you’d need to consider a monitoring platform for.

But you definitely want to, even if it simple ELK stack
Post reply on HN