Live data from Hacker News

Cisco Acquires Splunk

splunk.com

521–525 of 525 posts

Re: Cisco Acquires Splunk

#522

Earlier quoted context omitted.

“the market thinks” is an expression that makes me cringe. The market does not think, it’s the result of multiple actions, which many many people pretend they can explain or even predict when really they cannot. "the market thinks” gives the stock trade market an aura of reason and intelligence which it absolutely does not deserve for many historical reasons. Trading as it exists today is unhinged capitalism, it’s a…

Couldn't you say the same thing about evolution?

Can evolution be attributed thought or more generally consciousness?

Re: Cisco Acquires Splunk

#523

Earlier quoted context omitted.

Not that I recommend you try this, but my understanding is that if a careless splunk executive were talking about the merger on the phone at the local coffee shop and you, a total stranger, happened to overhear you could trade on that without it being a crime.

Cisco and Splunk merger/acquisition rumors are at least 1 year old. Lots of Splunk employees speculated that it would be announced at the last Splunk conf (2022). Either way I vote for this being a blatant insider trading.

I was working for a startup that was acquired by Splunk in 2018. At the next Cisco Live that was all the talk/rumor: Cisco acquiring Splunk. At one point it sounded like Cisco attempted a somewhat hostile takeover of Splunk. My sources and I rehashed this last week and the initial bid for Splunk was $23B sometime between 2018-2020. At the current price it's hard to tell if the current offer is higher, or actually lower, given inflation and market movement/sentiment.

Either way, it's a bad deal for both Splunk employees and their customers. SIEM is a space that is hard to be a leader in when you're not vendor agnostic. This is basically what XDR has become: vendors who have EDR/NDR/whatever are claiming to have some unique (it's not) data lake that can ingest any source, when in reality all of these solutions suck at everything outside of their own product set. I've worked with countless clients over the last year who, as an example, made the mistake of thinking Microsoft Sentinel was a cost effective tool, only to realize that once you're outside of the Microsoft ecosystem analytics/detections quality becomes very close to zero in terms of quality and the price is not cost effective. But SIEM has always had a flair of vendor lock in to it anyway. It's a hard platform to move from once time has been invested in wrangling all the data sources for ingest, transforming them to some bespoke schema and then all of the detection engineering on top of that. It's almost as bad as large scale firewall migrations.

What a lot of folks don't know is that when Splunk decided to move to a Cloud/SaaS model they literally just lifted and shifted the unoptimized bits of on-prem Splunk to a managed VPC under the direction of then-CTO Tim Tully. Splunk was losing money on every deal due to the infra outcosting the insanely high quotes Splunk was churning out. This is a great case study on Innovators Dilemma as Splunk drug their feet for years internally saying that cloud would never impact them. And then they realized they were far behind the 8-ball and decided to hemorrhage cash so as to not churn customers. They eventually optimized it, but the underpinnings still aren't what a fresh take on the bits would have looked like had Splunk done the "right" thing.

Cisco will continue to play ELA games with customers just like VMware. For those who don't know both companies like to get customers into ELAs. Why? Because those contracts basically state that said customer will buy X number of new products annually or risk losing some, or all, of their currently negotiated discount. For smaller orgs this works less well, but you'd be amazed at how those smaller are easily manipulated by snake oil sales folks. For large orgs this puts them in a bind. I've even seen shady contracts written (from Splunk) that had language wherein if the customer does not renegotiate or cancel a, let's say, 3 year contract in writing 90 days before it's going to expire that the contract will autorenew at a ridiculous percentage increase in cost.

Move away from these enterprise product sets where and when you can. These companies are focused on the bottom line - and that is profit, not the customer. The industry has it all backwards, and it's working for them... Still.

Re: Cisco Acquires Splunk

#524

Earlier quoted context omitted.

It was at one point usable but they drove off the hobbyist/small business crowd a long time ago. We do some work setting up elasticsearch tools that aggregate and filter data later sent to central splunk purely to affect a large reduction in license costs.

A question: where did the hobbyist/small business crowd go?

Kibana and Graylog on top of elastic/opensearch. Even the commerical licenses on those are usually a tiny fraction of splunk's costs, and Graylog does enough for free that it's a much easier path to stand that up and then buy the correlation functionality if you really need it.

For some organizations what Splunk does well is important but for most of them they really only need much more basic log aggregation and analysis tools.

Re: Cisco Acquires Splunk

#525

Earlier quoted context omitted.

Oracle - don't use an Oracle database unless you hate money, yourself, or your company. SAP - getting off of their ERP systems is an absolute nightmare and they know/exploit that fact. Salesforce - CRM systems, in general, can lead to lock-in due to the sheer amount of data and customization they host. In recent years Salesforce has started to leverage this fact to grow revenue without adding value. Unity - they're g…

Thanks. Personally I hate those "give me more free info" responses. Do your own homework.

Albert, I must assume this was targeted at my comment to ask for an enumeration of businesses enjoying the model espoused. "Do your own homework" is fine if the objective is clear; it wasnt (to me at least) and I wasnt sure where to start. Thank you to the OP for adding that list!
Post reply on HN