Live data from Hacker News

Cisco Acquires Splunk

splunk.com

61–70 of 525 posts

Re: Cisco Acquires Splunk

#61
I imagine we will see a bit of a reckoning & consolidation in the space.

For a lot of non-megacap companies, while observability is nice.. it might not meet the ROI hurdle in a high rate / low growth environment.

That is - its hard to reconcile sending $$ Millions out the door to Datadog, Splunk, Pagerduty while you are trying to cut budgets elsewhere.

Some of the disclosures by companies of what they've been spending on SaaS are pretty eye popping.

Re: Cisco Acquires Splunk

#62

I hated Splunk so much that I spent a couple days a few months ago writing a single 1200 line python script that does absolutely everything I need in terms of automatic log collection, ingestion, and analysis from a fleet of cloud instances. It pulls in all the log lines, enriches them with useful metadata like the IP address of the instance, the machine name, the log source, the datetime, etc. and stores it all in S…

My complaint is that this acquisition is going to add another 1-4 paragraphs of examinable marketing copy to the Cisco CCNP ENCOR textbook. I'll have to somehow remember not to confuse Splunk with Cisco Firepower NGIPS, which uses Snort. This is what happens when an industry starts to name its products after the sound effects from Peppa Pig.

Re: Cisco Acquires Splunk

#63
post #12
post #4

Genuinely surprised anybody would acquire Splunk in 2023. Whenever you hear about Splunk from security engineers, they're actively trying to get off it (edit: yes, primarily because of cost). Better, next-gen SIEMs are either here or around the corner.

I haven't heard a single person trying to get off of it because "there are better SIEMs" - they're universally looking at other options because of the price. Cisco has the luxury of bundle and save that Splunk does not.

former firepower customer... I guess we'll see.

I can see them shipping a really cool-looking whitepaper detailing FTD, Amp, and Splunk... but actually operating it will feel similar to driving a 20 yr old salt state jeep wrangler on the autobahn.

Re: Cisco Acquires Splunk

#64
post #54

Earlier quoted context omitted.

For how many data sources? The whole reason everyone goes to Splunk is that it scales, and scales incredibly well. Large enterprises can generate hundreds of terabytes to petabytes every day. Splunk has all sorts of issues, but to pretend as if you can replace them in any large shop with a 1200 line python script and SQLite is just being disingenuous. This acquisition falls right into Cisco's sweet spot, they aren't…

It's around 6 data sources on ~25 machines, but it could be easily scaled to way more than that with a bit of work. And I mean less work than it takes to do even trivially simple things using the horrible Splunk API. There are many thousands of small companies using Splunk and getting totally ripped off for a very mediocre product with a rapacious and annoyingly aggressive salesforce.

That is a tiny setup all things considered. You aren’t operating at a scale you’d need to consider a monitoring platform for.

Re: Cisco Acquires Splunk

#65
post #42

It's a strong effort, but not as cerebral as the classics, "Twitter Acquires Magic Pony" https://news.ycombinator.com/item?id=11937756 and "Salesforce Signs Definitive Agreement to Acquire Slack" https://www.youtube.com/watch?v=Qt9MP70ODNw .

Perhaps it's a bit premature. There's no price point in the announcement so there may be some details that drag out...

Apparently, this will be an all-cash deal worth $28 billion[0].

[0] https://www.cnbc.com/2023/09/21/cisco-acquiring-splunk-for-1...

Re: Cisco Acquires Splunk

#67
post #11

Wow - I guess I'm both surprised and completely unsurprised. Surprised because Splunk is a pretty big pill to swallow. Unsurprised because they've obviously been interested in the space for a long time (they attempted to acquire Datadog and got shot down). https://realmoney.thestreet.com/investing/technology/cisco-r... Good luck Splunk folks - Cisco isn't exactly known for their software innovation in the upper stack…

> Cisco isn't exactly known for their software innovation in the upper stacks

I spend most of my day managing Meraki networks and some of that is seriously powerful and innovative.

Re: Cisco Acquires Splunk

#68
post #21
post #9

Earlier quoted context omitted.

Which ones do you recommend? Every one I have tried hasn't really given me the same flexibility as Splunk, most seem to miss the core part of what makes Splunk cool. Though I'd definitely like to see Splunk improve their design.

He's talking out of his ass. But newish competitors are Devo/Sumo Logic.

Humio is also promising, however they've been acquired by CrowdStrike, who aren't know for low prices!

Re: Cisco Acquires Splunk

#69
post #20

Earlier quoted context omitted.

Meraki and OpenDNS both became better post acquisition, and in both cases I’d say it was because Cisco let them continue to maintain a lot of control, the leaders stayed around, and the majority of the engineering teams did, too. Cisco has a long list of successful acquisitions. The release says Gary will report to Chuck directly, which is a strong sign Chuck will make sure Splunk succeeds. (nb, I was CEO of OpenDNS)

So they will compete against AppDynamics for the same customers... Fun times.

AppDynamics isn't SIEM. If anything, this looks like an opportunity to upsell to AppDynamics customers.
Post reply on HN