Live data from Hacker News

Splunk IP suit against Cribl

splunk.com

71–80 of 107 posts

Re: Splunk IP suit against Cribl

#71

Splunk, as a company, is a shell of its former self. All they care about is pimping themselves out to maximize profits to an extreme that only Dilbert can relate to, even at the expense of destroying a long term professional relationship over trivial matters. They are more than happy to kill a deal over a 5% disagreement rather than understand the needs of a Fortune 500 customer and negotiate. They are mad because Cr…

I can add from the other side of the fence. I worked for a startup that was acquired by Splunk. They are everything listed here and worse on the inside. My first few weeks at Splunk were very odd. They try to indoctrinate new hires with a barrage of "A-players" that continuously talked about how awesome Splunk was. Except... When I started Splunk was getting their ass kicked by cloud-first players that had recently c…

Interesting, I helped manage a splunk install at a fortune 200 about a decade ago. At the time the recommendation was to use syslog-ng to filter incoming logs before indexing. I just heard of cribl 2 weeks ago because the fortune 20 I currently work for is planning on switching to it. I didn't realize it was a massive shift like that, I just thought it was the corporation switching things just because they do that sometimes.

Re: Splunk IP suit against Cribl

#72
Our alerting solution, "OpterVics", was bought by Splunk. Since then it's been a shitshow - the service is running, but it's almost impossible to get a response from support.

They sent us an invoice for renewal in early August. I replied back (5 separate times) asking for the original contract (our ops department is tightening up on vendor management, didn't have it on file already); and we've heard nothing. Our service has continued to work despite not having paid (or signed a renewal), but we're switching to opsgenie.

Re: Splunk IP suit against Cribl

#73
post #35

Earlier quoted context omitted.

> Is there an open source version of splunk I can modify? https://github.com/grafana/loki might work for you. It’s not a drop in replacement for Splunk, FWIW.

Is there any way to do subqueries (or some kind of join) with loki? That is one feature of splunk I haven't seen elsewhere, open source or not.

New Relic’s NRQL can do sub queries.

Re: Splunk IP suit against Cribl

#74

From the lawsuit looks like the most clear cut evidence they have is: - Founder publishing a private protocol definition to help in building for it - Sales staff sending account and prospect info to their new cribl email addresses before leaving Splunk - Engineers leaving Splunk with technical specifications, such as their newer S2S protocol versions The patent stuff is kind of whatever, but all three of those items…

Honest question, where is the line here? Obviously we all retain knowledge from previous jobs so what's the line between that and exactly copying a spec?

To me, unless there is a legal document you signed with your employer, there is no line. Even, IMO, IP is not `property` so that it cannot be used against. But that is another discussion.

Re: Splunk IP suit against Cribl

#75

Earlier quoted context omitted.

Sounds crazy, but Datadog. I’ve been hammering their product teams for years with specific use cases for the sole purpose of replacing Splunk. They recently migrated search technologies and are rapidly closing the gap. Plus, their exclusion features are instant and fantastic, and their C-suite replies to me when I escalate. Elasticsearch simply couldn’t handle key collisions. We have hundreds of various apps across 5…

Sad. Splunk should be more fantastic. They have done the heavy lifting of taking streams of data at high volume, which should be the basis to build a log search product, metrics And alerting, and observability. Instead, each of these systems have their own collectors and correlating from one to the other is hard. A canonical log line is so much more valuable than a metric collected every 60 seconds, and the former ca…

I built a PCI compliance solution for a customer back in 2008 for ~$200k all-in when the closest competitor's bid was five times that. The product was amazing at runtime but of course had some idiosyncrasies in how it was configured and whatnot. I've been a user (only) of Splunk heavily ever since and just last year got pulled into a project to migrate a huge install to a cloud platform. It felt like I got into a time machine...there were seemingly zero administrative or architectural improvements to make the product more manageable or supportable in the 10+ years since I had last looked at it from an ops perspective.

I'm sure that's not 100% true but it felt like it. Trying to build Splunk on top of a modern IaC deployment methodology is a huuuuge lift.

Re: Splunk IP suit against Cribl

#76

Earlier quoted context omitted.

What are you planning to move to?

Exactly. This is the question. If you’re looking for APM well you’ve got great options but for those using Splunk in the security space (SIEM & SOAR) you’re screwed. There’s no better SIEM alternative that deals with logs at scale. Splunk recently screwed a friends Fortune 50 company. They didn't pay a bill on time (renewal negotiations) and Splunk without even contacting them just left all the logs from one of their…

>There’s no better SIEM alternative that deals with logs at scale.

I think folks that use Splunk for basic search just don't fully comprehend how capable the product is for hunt-type operations when someone fluent in SPL is at the helm.

Re: Splunk IP suit against Cribl

#77

Earlier quoted context omitted.

I can add from the other side of the fence. I worked for a startup that was acquired by Splunk. They are everything listed here and worse on the inside. My first few weeks at Splunk were very odd. They try to indoctrinate new hires with a barrage of "A-players" that continuously talked about how awesome Splunk was. Except... When I started Splunk was getting their ass kicked by cloud-first players that had recently c…

Interesting, I helped manage a splunk install at a fortune 200 about a decade ago. At the time the recommendation was to use syslog-ng to filter incoming logs before indexing. I just heard of cribl 2 weeks ago because the fortune 20 I currently work for is planning on switching to it. I didn't realize it was a massive shift like that, I just thought it was the corporation switching things just because they do that so…

There have been a few other recommendations over the years, including putting a separate tier of forwarders first in line to perform transforms and such. There were always plenty of options for on-prem/DIY/Enterprise especially when using syslog instead of directly via HEC.

Their SaaS offering used to have said inline tier called IDM (Inputs Data Manager) where we were directed to configure filters during our POC… a key requirement for moving from Enterprise to SaaS because conf files aren’t managed the same. One month (to the day!) after we moved, they randomly decided to migrate us to a new “Victoria experience” where that tier suddenly disappeared without explanation. We filed support tickets asking 1) what happened? and 2) how do we filter things out now? and were directed to hire professional services because that was outside the scope of standard support!

The whole point of moving to SaaS was to not have to babysit our own clusters (small shop at the time), so spinning up a ton of infra in front of the freshly greenlit SaaS setup would have negated the productivity gains and financial pivot.

Ultimately, the entropy of hundreds of applications logging in disparate formats and namespaces outweighed our ability to sanitize each app within a reasonable amount of time, leading to unwanted data being indexed, ergo overages. Overages that our sales engineer originally assured us we could address by filtering things out with the snap of a finger. Bait and switch.

Ingest Actions were not available at the time, and were not functional (even in beta) until 10 months later.

Re: Splunk IP suit against Cribl

#78
post #7
post #4

Splunk is the best at what it does with no close competition. I've been looking into Cribl and it seems their product has surpassed their competition as well but not in search, more in data summarization and log reduction, possibly before you ship it off to a more proper place like Splunk. Splunk's cost makes it inaccessible to most people or companies. I mean, I work in infosec and I highly caution against Splunk be…

Is Splunk fast now? Last time I used it was almost a decade ago and it was rubbish, queries took 10-40 minutes to complete.

Yes BUT it needs tuning. Splunk is complicated and takes continuous maintenance to optimize speed.

I work as a Splunk integrator and here's what I often see:

1. Customer installs Splunk with a qualified Splunk or third-party architect team. The deployment works well.

2. Customer adds infrastructure to the deployment. Splunk slows down. License costs go up.

3. Customer chooses between outside help or DIY. DIY rarely works.

4. Customer now needs outside help. Now Splunk is very slow and expensive, and now it will cost a lot to tune it.

Splunk, the company, is in a tough spot for several reasons: rotating c-level cast, unpopular changes to license model, bad acquisitions. The product is still best in class but tough to keep optimized.

Re: Splunk IP suit against Cribl

#79

From the lawsuit looks like the most clear cut evidence they have is: - Founder publishing a private protocol definition to help in building for it - Sales staff sending account and prospect info to their new cribl email addresses before leaving Splunk - Engineers leaving Splunk with technical specifications, such as their newer S2S protocol versions The patent stuff is kind of whatever, but all three of those items…

Honest question, where is the line here? Obviously we all retain knowledge from previous jobs so what's the line between that and exactly copying a spec?

I think the line here is pretty straightforward: the contents of your mind are all yours. Anything beyond that (documents, source code, lists of prospects) is not.

Non-compete clauses will try to limit the usefulness of the "in your mind" knowledge by restricting the domains in which you can work post-departure. It's my understanding that such clauses are generally held to be unenforceable except in an acquisition scenario.

Re: Splunk IP suit against Cribl

#80
post #7

Earlier quoted context omitted.

Is Splunk fast now? Last time I used it was almost a decade ago and it was rubbish, queries took 10-40 minutes to complete.

Yes BUT it needs tuning. Splunk is complicated and takes continuous maintenance to optimize speed. I work as a Splunk integrator and here's what I often see: 1. Customer installs Splunk with a qualified Splunk or third-party architect team. The deployment works well. 2. Customer adds infrastructure to the deployment. Splunk slows down. License costs go up. 3. Customer chooses between outside help or DIY. DIY rarely w…

So basically what you are saying is this.

A firm with a competent IT team is unable to get splunk to work and only "outside help" can make the product work?

Given splunks license costs are tied to data ingested, how do you integrate new infrastructure to the deployment and not have license costs go up?

Way to sell us on Splunk?

Post reply on HN