Live data from Hacker News

Cisco Acquires Splunk

splunk.com

81–90 of 525 posts

Re: Cisco Acquires Splunk

#81

Does anyone have an example of an acquisition where the products of the acquired company then became better?

Youtube, Instagram.

Why YouTube? It was definitely worse pre-acquisition, but so did the rest of the internet. Do you think it could've gone under without Google's capital?

Re: Cisco Acquires Splunk

#82
post #4

Genuinely surprised anybody would acquire Splunk in 2023. Whenever you hear about Splunk from security engineers, they're actively trying to get off it (edit: yes, primarily because of cost). Better, next-gen SIEMs are either here or around the corner.

I was at a shop that got heavily integrated into Splunk for security use cases and then entered a split brain mode of 'well if you need observability we already have Splunk' but also 'hey stop doing so much observability, this thing is expensive!'.

So for 5 years time we used it for observability, we were only half-integrated and also trying to get off of it. Great stuff.

Re: Cisco Acquires Splunk

#84
post #71

I hated Splunk so much that I spent a couple days a few months ago writing a single 1200 line python script that does absolutely everything I need in terms of automatic log collection, ingestion, and analysis from a fleet of cloud instances. It pulls in all the log lines, enriches them with useful metadata like the IP address of the instance, the machine name, the log source, the datetime, etc. and stores it all in S…

This mostly sounds like a badly managed Splunk. If a 1200 line Python script is all you need to replace a Splunk instance, you weren't doing anything all that interesting or well in the first place. > useful metadata like the IP address of the instance, the machine name, the log source, the datetime, This should be tagged on every single log line already, and not something that you should be doing post-ingestion

The logs included things like the systemd logs and stuff that I don’t have control over. You need to be able to enrich with arbitrary metadata for it to be generally useful.

My point is more that a large portion of Splunk customers could do the same thing I did and be way better off. Obviously not their huge enterprise customers spending millions a year.

Re: Cisco Acquires Splunk

#85
post #60

Earlier quoted context omitted.

they price-out medium customers so mind-share decreases

Are medium-sized customers valuable to Splunk? In sales we call this "Ideal Customer Profile." Why do I want a customer with less money to spend if I have a product with enough capability for the gigantic money-is-no-object customers?

I work in a 100+ year old giga bank, systemic in the country it comes from, in their Hong Kong investment bank branch.

We loved Splunk, we invested quite a bit in it both for technical monitoring and business intelligence. After a while the price went so high we cut it all, moved to kdb/tableau/elk/whatever crappier system that cost less.

Money is ALWAYS an object and Splunk makes sure to dig a hole deep enough for even the deepest pockets. I too prefer my shareholders to collect the fruit of my labor rather than... Splunk. At least they can reinvest some profit in us. Not Splunk, nope, they keep digging that hole in our pockets.

Re: Cisco Acquires Splunk

#86
post #41

Earlier quoted context omitted.

What makes you say Splunk is a dead player? Not arguing with you, it's genuine curiosity on my part.

they price-out medium customers so mind-share decreases

It's better -because it's easier to scale- to sell a single 1M$ license than selling a thousand 1000$ licenses.

Re: Cisco Acquires Splunk

#89

Somebody: Splunk has exorbitant prices and locked-in enterprise customers! Cisco: Oh these guys are just like us. Better buy them up. We know this business.

when you read Hacker News thread - every single one of them feels like the world is falling apart. Splunk is a dud or so everyone here thinks:

https://siliconangle.com/2023/08/23/splunk-shares-surge-stro...

Re: Cisco Acquires Splunk

#90
post #54

Earlier quoted context omitted.

For how many data sources? The whole reason everyone goes to Splunk is that it scales, and scales incredibly well. Large enterprises can generate hundreds of terabytes to petabytes every day. Splunk has all sorts of issues, but to pretend as if you can replace them in any large shop with a 1200 line python script and SQLite is just being disingenuous. This acquisition falls right into Cisco's sweet spot, they aren't…

It's around 6 data sources on ~25 machines, but it could be easily scaled to way more than that with a bit of work. And I mean less work than it takes to do even trivially simple things using the horrible Splunk API. There are many thousands of small companies using Splunk and getting totally ripped off for a very mediocre product with a rapacious and annoyingly aggressive salesforce.

I have an order of magnitude more machines than you and would never in a million years consider splunk

Right tool for the right job. Splunk is for mega-scale setups

Post reply on HN