Live data from Hacker News

Cisco Acquires Splunk

splunk.com

71–80 of 525 posts

Re: Cisco Acquires Splunk

#71

I hated Splunk so much that I spent a couple days a few months ago writing a single 1200 line python script that does absolutely everything I need in terms of automatic log collection, ingestion, and analysis from a fleet of cloud instances. It pulls in all the log lines, enriches them with useful metadata like the IP address of the instance, the machine name, the log source, the datetime, etc. and stores it all in S…

This mostly sounds like a badly managed Splunk. If a 1200 line Python script is all you need to replace a Splunk instance, you weren't doing anything all that interesting or well in the first place.

> useful metadata like the IP address of the instance, the machine name, the log source, the datetime,

This should be tagged on every single log line already, and not something that you should be doing post-ingestion

Re: Cisco Acquires Splunk

#72
post #56
post #53

Earlier quoted context omitted.

I disagree. Apple Weather has become an amazing app since the DarkSky acquisition. I especially like the hourly charts.

Apple Weather may be better, but DarkSky is gone and it has not included all the features it used to have, such as hourly rain probability for any day.

Oddly enough this is the one reason why I don't use Apple Weather. I live in Texas - if you don't have covered parking you will inevitably get hail damage. The 1-2 days per week I go into the office I have to check Accuweather beforehand.

Precipitation probability is the most important thing in a weather app to me.

Re: Cisco Acquires Splunk

#73
post #60

Earlier quoted context omitted.

they price-out medium customers so mind-share decreases

Are medium-sized customers valuable to Splunk? In sales we call this "Ideal Customer Profile." Why do I want a customer with less money to spend if I have a product with enough capability for the gigantic money-is-no-object customers?

I believe the idea is that the big customers are interested because everyone is raving about it. If you price out the smaller customers, there's nobody to rave about it.

Consider, for example, that Akamai's revenues are sitting in a plateau over the last 5 years, while Cloudflare is moving up.

Re: Cisco Acquires Splunk

#74
post #29

Does anyone have an example of an acquisition where the products of the acquired company then became better?

T-Mobile buying Sprint was a huge improvement for me.

Them buying Iowa Wireless was a boon for me. Before that it was either deal with verizon, or deal with being on a limited regional network.

Waiting for the shoe to drop on that Mint Mobile acquisition though...

Re: Cisco Acquires Splunk

#75
post #11

Wow - I guess I'm both surprised and completely unsurprised. Surprised because Splunk is a pretty big pill to swallow. Unsurprised because they've obviously been interested in the space for a long time (they attempted to acquire Datadog and got shot down). https://realmoney.thestreet.com/investing/technology/cisco-r... Good luck Splunk folks - Cisco isn't exactly known for their software innovation in the upper stack…

Splunk is a dead player too. It's a great match.

This might be why Cisco bought them:

OMB Memorandum M-21-31[0], “Improving the Federal Government's Investigative and Remediation Capabilities Related to Cybersecurity Incidents” which includes directives to ensure event logging goes well beyond the current norms.

By all accounts I've heard it's going to enrich the fortunes of every single SIEM/Log aggregation company out there, pretty much every govt contractor is going to need larger licenses in the next few years as contracts get rewritten with this EO in mind.

[0] https://www.fedramp.gov/2023-07-14-fedramp-guidance-for-m-21...

Re: Cisco Acquires Splunk

#76
post #11

Wow - I guess I'm both surprised and completely unsurprised. Surprised because Splunk is a pretty big pill to swallow. Unsurprised because they've obviously been interested in the space for a long time (they attempted to acquire Datadog and got shot down). https://realmoney.thestreet.com/investing/technology/cisco-r... Good luck Splunk folks - Cisco isn't exactly known for their software innovation in the upper stack…

> Cisco isn't exactly known for their software innovation in the upper stacks I spend most of my day managing Meraki networks and some of that is seriously powerful and innovative.

They bought Meraki.

Re: Cisco Acquires Splunk

#77
post #64

Earlier quoted context omitted.

It's around 6 data sources on ~25 machines, but it could be easily scaled to way more than that with a bit of work. And I mean less work than it takes to do even trivially simple things using the horrible Splunk API. There are many thousands of small companies using Splunk and getting totally ripped off for a very mediocre product with a rapacious and annoyingly aggressive salesforce.

That is a tiny setup all things considered. You aren’t operating at a scale you’d need to consider a monitoring platform for.

You'd be surprised how many companies with infra that small have CTOs get consultant buzzword pilled into buying every SaaS under the sun nonetheless...

Re: Cisco Acquires Splunk

#79
post #9
post #4

Genuinely surprised anybody would acquire Splunk in 2023. Whenever you hear about Splunk from security engineers, they're actively trying to get off it (edit: yes, primarily because of cost). Better, next-gen SIEMs are either here or around the corner.

Which ones do you recommend? Every one I have tried hasn't really given me the same flexibility as Splunk, most seem to miss the core part of what makes Splunk cool. Though I'd definitely like to see Splunk improve their design.

Graylog looks like a good competitor. Certainly won't scale as well, but I've had good experience with it.

Re: Cisco Acquires Splunk

#80
post #54

Earlier quoted context omitted.

For how many data sources? The whole reason everyone goes to Splunk is that it scales, and scales incredibly well. Large enterprises can generate hundreds of terabytes to petabytes every day. Splunk has all sorts of issues, but to pretend as if you can replace them in any large shop with a 1200 line python script and SQLite is just being disingenuous. This acquisition falls right into Cisco's sweet spot, they aren't…

It's around 6 data sources on ~25 machines, but it could be easily scaled to way more than that with a bit of work. And I mean less work than it takes to do even trivially simple things using the horrible Splunk API. There are many thousands of small companies using Splunk and getting totally ripped off for a very mediocre product with a rapacious and annoyingly aggressive salesforce.

I think we're talking about very different levels of scale. Enterprises are generally feeding tens to hundreds of thousands of datapoints into Splunk depending on their size between servers, networking gear, endpoint devices, etc.
Post reply on HN