Live data from Hacker News

Cisco Acquires Splunk

splunk.com

371–380 of 525 posts

Re: Cisco Acquires Splunk

#371
post #11

Wow - I guess I'm both surprised and completely unsurprised. Surprised because Splunk is a pretty big pill to swallow. Unsurprised because they've obviously been interested in the space for a long time (they attempted to acquire Datadog and got shot down). https://realmoney.thestreet.com/investing/technology/cisco-r... Good luck Splunk folks - Cisco isn't exactly known for their software innovation in the upper stack…

rsyslogd strikes again.

Re: Cisco Acquires Splunk

#372

Earlier quoted context omitted.

Most of Cisco's current product suite came via acquisitions[0]. The difference with Meraki, compared to the typical Cisco acquisition, is how independently they were allowed to operate. WebEx was a similar story. Cisco would tell you that acquisition is a core competency of theirs[1], but having worked there for 8 years (including during the WebEx and Meraki acquisitions,) I'd say their track record is far more spott…

I sat in on the all Cisco acquisitions teams from c. 1994 - 1999. Even during that heyday there were awesome acquisitions that took off and others that went nowhere. Cisco was historically always better at hardware acquisitions than pure-play software. It would often kill the software products entirely — Internet Junction, TGV, Precept come to mind. The one other rule that John Chambers lived by was "no merger of equ…

Based on my experience in (mostly) software companies, hardware just seems more likely to work. The people building it are formally trained, the government forces a minimum amount of safety testing, and a design mistake could cost millions to fix, besides the reputational damage. Software is more like getting retail workers to build a remote controlled forklift out of junkyard parts.

Re: Cisco Acquires Splunk

#373
post #41

Earlier quoted context omitted.

What makes you say Splunk is a dead player? Not arguing with you, it's genuine curiosity on my part.

they price-out medium customers so mind-share decreases

I have never. Once. worked somewhere that could afford splunk. But I have used it on trail many times, very cool.

Re: Cisco Acquires Splunk

#374
post #280

Earlier quoted context omitted.

It's difficult to control data ingress so you end up in debt and on repayment plans. Which are expensive.

That makes sense, so looking at what people ingress, they pay afterwards or just really huge plans upfront? Or a mix?

Well usually you have to overpurchase up front and they sell you a 3 year lock in to make it affordable capital cost. Then when you eek over it temporarily, the sales guy calls you up within 10 nanoseconds to bill you for more.

I was getting 2-4 calls a week.

It was so fucking annoying and expensive ($1.2M spend each cycle) we shitcanned the entire platform.

First thing they hear of this is when our ingress rate drops to zero and they phone us up to ask what is happening. Then we don't go to the numerous catch up and renewal meetings and calls. Then we stop answering the phone.

Re: Cisco Acquires Splunk

#375
post #13

Earlier quoted context omitted.

Splunk is a great product with horrible sales and business team. The reason why them _trying_ to get off it is because they have a bunch of stuff that is easy and works in splunk, but don't want to pay the exorbitant licensing, or pay even more to increase their use. But getting off a good product is hard, and they will continue to use it and even pay. The kind of thing Cisco, Oracle, and IBM love are companies with…

> with horrible sales and business team I was in one of these meetings with like 20 engineers on how amazing this thing was. We knew that because we already used it it quite extensively. The very extremely hyper sales rep kept ducking out of the meeting every 5 mins. I recognized it for what it was. He was ducking out to do bumps of coke so he could be more pumped to sell us more stuff.

Yikes. The only other time I heard about the Splunk sales team in the news, it sounded pretty bad also.

https://www.theregister.com/2020/08/12/splunk_sales_discrimi...

Re: Cisco Acquires Splunk

#376

Earlier quoted context omitted.

Most likely they will let AppD die.

Why? I haven't used AppD in ~7 years, but I remember it being one of the most pleasurable APMs (but also ridiculously expensive) It seems to me the marriage between APM and logging would be a home run.

Splunk bought SignalFX a while ago and they are trying to lean in hard on the observability craze and piggybacking on OpenTelemetry. I wasn't involve heavily in this migrate to Splunk Observability Cloud project about a year ago but it was a shit show and half-baked and ultimately they dumped it in favor of DataDog IIUC (I had since changed jobs but kept in touch with ex-colleagues).

* https://www.splunk.com/en_us/about-splunk/acquisitions/signa...

* https://opentelemetry.io/

* https://www.splunk.com/en_us/blog/conf-splunklive/introducin...

Re: Cisco Acquires Splunk

#378

Splunk is so expensive and slow. My workplace keeps trying throttle queries and how far back logs are stored. Been spending the last month or so adding ELK stack for tracing to our apps.

Splunk's advantage is that it can handle volumes of logs which ELK, Graylog and Loki simply cannot. If you're not there yet... yeah, Splunk is hella expensive.

Re: Cisco Acquires Splunk

#379
post #9

Earlier quoted context omitted.

Which ones do you recommend? Every one I have tried hasn't really given me the same flexibility as Splunk, most seem to miss the core part of what makes Splunk cool. Though I'd definitely like to see Splunk improve their design.

There are some players that are more established than others but check out: https://panther.com - Built on top of Snowflake, so it scales well and they are building a more Splunk like interface. https://runreveal.com - Still seed but shows a lot of promise https://matando.dev - Still seed and don't have a hosted product yet but smart founders that have the right idea https://hunters.ai - More threat hunting than SIEM…

I would add https://blumira.com to that list; it's more mature than at least a few of these (I'm a former employee)

Re: Cisco Acquires Splunk

#380
post #4

Genuinely surprised anybody would acquire Splunk in 2023. Whenever you hear about Splunk from security engineers, they're actively trying to get off it (edit: yes, primarily because of cost). Better, next-gen SIEMs are either here or around the corner.

I was at a shop that got heavily integrated into Splunk for security use cases and then entered a split brain mode of 'well if you need observability we already have Splunk' but also 'hey stop doing so much observability, this thing is expensive!'. So for 5 years time we used it for observability, we were only half-integrated and also trying to get off of it. Great stuff.

Worked on a piece of software which suffered from years of this split brain. It had some logging and some metrics, but the team was told to be economical about observability. This resulted in the software having many blind spots which led to production issues that had to be manually reproduced. When I become responsible for the software I personally overhauled the logging and the team had to work together to rebuild the metrics functionality.
Post reply on HN