Live data from Hacker News

Splunk IP suit against Cribl

splunk.com

41–50 of 107 posts

Re: Splunk IP suit against Cribl

#41

Earlier quoted context omitted.

Splunk worked with us to optimize our configs but we always managed it ourselves.

Nope, sports betting. I was on the operations side of things and Splunk was something the corporate side organised and championed, but it just couldn't be used to troubleshoot issues in the time frames we needed.

[deleted]

Re: Splunk IP suit against Cribl

#42

Earlier quoted context omitted.

I personally brought Splunk to Apple in 2010 alongside a small handful of people (Hi, Sean and Ariel!). There is a massive difference between real-time searches where latency beyond a few seconds is unacceptable, and historical searches which can take a bit longer. I can assure you that it did its job spectacularly, much to my chagrin that there are few competitors to this day.

Cool! That makes sense. I only really used it as part of the (now defunct I think) "orchard" internal hosting platform that was very much beta when I was using it, for tiny internal apps running on like 4 instances at most, and missed being able to just grep log files; my wild, uneducated guess from what you said is that there was some kind of pooling of our meager logs with other people's from orchard, or we were ot…

I was part of Orchard and miss it dearly. It had a lot of potential but it was launched as a proof of concept built on pooled resources freed up from optimizing legacy workloads (namely, moving Siri from VMware to Mesos).

It never got the love it deserved and I could absolutely believe that its Splunk cluster suffered as a result. RIP

Re: Splunk IP suit against Cribl

#44
post #7
post #4

Splunk is the best at what it does with no close competition. I've been looking into Cribl and it seems their product has surpassed their competition as well but not in search, more in data summarization and log reduction, possibly before you ship it off to a more proper place like Splunk. Splunk's cost makes it inaccessible to most people or companies. I mean, I work in infosec and I highly caution against Splunk be…

Is Splunk fast now? Last time I used it was almost a decade ago and it was rubbish, queries took 10-40 minutes to complete.

On modern NVMe storage it is INCREDIBLY fast.

Re: Splunk IP suit against Cribl

#45
From the lawsuit looks like the most clear cut evidence they have is:

- Founder publishing a private protocol definition to help in building for it

- Sales staff sending account and prospect info to their new cribl email addresses before leaving Splunk

- Engineers leaving Splunk with technical specifications, such as their newer S2S protocol versions

The patent stuff is kind of whatever, but all three of those items would be enough to establish some very clear damages. Cribls an exciting new player but they can't take shortcuts like this, if the allegations are founded.

Re: Splunk IP suit against Cribl

#46

Splunk, as a company, is a shell of its former self. All they care about is pimping themselves out to maximize profits to an extreme that only Dilbert can relate to, even at the expense of destroying a long term professional relationship over trivial matters. They are more than happy to kill a deal over a 5% disagreement rather than understand the needs of a Fortune 500 customer and negotiate. They are mad because Cr…

Last used splunk around 2010, and we ran a bunch of scripts to truncate and reformat logs before they got anywhere near our splunk data load license

Re: Splunk IP suit against Cribl

#47

Earlier quoted context omitted.

Cool! That makes sense. I only really used it as part of the (now defunct I think) "orchard" internal hosting platform that was very much beta when I was using it, for tiny internal apps running on like 4 instances at most, and missed being able to just grep log files; my wild, uneducated guess from what you said is that there was some kind of pooling of our meager logs with other people's from orchard, or we were ot…

I was part of Orchard and miss it dearly. It had a lot of potential but it was launched as a proof of concept built on pooled resources freed up from optimizing legacy workloads (namely, moving Siri from VMware to Mesos). It never got the love it deserved and I could absolutely believe that its Splunk cluster suffered as a result. RIP

100% agree, the idea of an internal Heroku was a great one, it just didn't seem to work with how Apple was designed organizationally or something and seemed under resourced.

Re: Splunk IP suit against Cribl

#48

Splunk, as a company, is a shell of its former self. All they care about is pimping themselves out to maximize profits to an extreme that only Dilbert can relate to, even at the expense of destroying a long term professional relationship over trivial matters. They are more than happy to kill a deal over a 5% disagreement rather than understand the needs of a Fortune 500 customer and negotiate. They are mad because Cr…

I can add from the other side of the fence. I worked for a startup that was acquired by Splunk. They are everything listed here and worse on the inside. My first few weeks at Splunk were very odd. They try to indoctrinate new hires with a barrage of "A-players" that continuously talked about how awesome Splunk was. Except... When I started Splunk was getting their ass kicked by cloud-first players that had recently c…

Sounds like a good move... From their about page:

    Splunkers have received over 1,020 patents to date
that tells me everything I need to know.

Re: Splunk IP suit against Cribl

#49
post #6

On the one hand, taking code from your employer and posting it to GitHub with the copyright notices removed is about as clear-cut a case of copyright infringement as you can get -- if they have evidence. Should be easy to confirm or deny by looking at version control history. (This seems to be the repository in question, but it's been taken down: https://web.archive.org/web/20210104032001/https://github.co... ) On th…

I'm not sure I understand the business impact of a protocol?

Presumably anyone with Wireshark could reverse it, so does it impart a significant advantage? Or is it just about control?

Re: Splunk IP suit against Cribl

#50

Earlier quoted context omitted.

Exactly. This is the question. If you’re looking for APM well you’ve got great options but for those using Splunk in the security space (SIEM & SOAR) you’re screwed. There’s no better SIEM alternative that deals with logs at scale. Splunk recently screwed a friends Fortune 50 company. They didn't pay a bill on time (renewal negotiations) and Splunk without even contacting them just left all the logs from one of their…

Lol, this is exactly what I was referring to! We were negotiating a massive renewal (50x budget IN EARNEST!) and out of nowhere they threatened to cut us off with less than 24 hours notice because we were a week behind their schedule, despite signed agreements. Thankfully our VAR (a longtime partner) jumped in and cut a PO to vouch for us and our word. NONE of our other vendors have EVER done that shit in my entire c…

Lol, I could have written exactly the same comments you did about Splunk. I'm the one who decided to start using splunk for our company 8 years ago, we're working on migrating away and I will never under any circumstances consider recommending splunk for any future companies I work for.
Post reply on HN