Live data from Hacker News

Cisco Acquires Splunk

splunk.com

91–100 of 525 posts

Re: Cisco Acquires Splunk

#91
post #54

Earlier quoted context omitted.

For how many data sources? The whole reason everyone goes to Splunk is that it scales, and scales incredibly well. Large enterprises can generate hundreds of terabytes to petabytes every day. Splunk has all sorts of issues, but to pretend as if you can replace them in any large shop with a 1200 line python script and SQLite is just being disingenuous. This acquisition falls right into Cisco's sweet spot, they aren't…

It's around 6 data sources on ~25 machines, but it could be easily scaled to way more than that with a bit of work. And I mean less work than it takes to do even trivially simple things using the horrible Splunk API. There are many thousands of small companies using Splunk and getting totally ripped off for a very mediocre product with a rapacious and annoyingly aggressive salesforce.

> it could be easily scaled to way more than that with a bit of work.

I guess you'd appreciate the words easily and bit are doing a lot of heavy lifting there.

Re: Cisco Acquires Splunk

#92
post #33

Somebody: Splunk has exorbitant prices and locked-in enterprise customers! Cisco: Oh these guys are just like us. Better buy them up. We know this business.

It's apparently cheaper to buy Splunk than to a buy Splunk license.

Not the first time they tried to buy a license!

https://www.reuters.com/technology/cisco-made-20-billion-plu...

Re: Cisco Acquires Splunk

#93
post #54

Earlier quoted context omitted.

For how many data sources? The whole reason everyone goes to Splunk is that it scales, and scales incredibly well. Large enterprises can generate hundreds of terabytes to petabytes every day. Splunk has all sorts of issues, but to pretend as if you can replace them in any large shop with a 1200 line python script and SQLite is just being disingenuous. This acquisition falls right into Cisco's sweet spot, they aren't…

It's around 6 data sources on ~25 machines, but it could be easily scaled to way more than that with a bit of work. And I mean less work than it takes to do even trivially simple things using the horrible Splunk API. There are many thousands of small companies using Splunk and getting totally ripped off for a very mediocre product with a rapacious and annoyingly aggressive salesforce.

ya as someone else already noted - Splunk is not for you

Re: Cisco Acquires Splunk

#94
Building splunk has become very democratised in today's day and age.

Back in the day, logging, metrics, event collection etc. was a hard problem that they solved. Esp. when there weren't any simple distributed storage operators.

They have been a cockroach in the orgs, surviving every downturn. As a dev, you might hate it, CISO and CIOs love it. Orgs, often mandate it. The way they dominated the market is via creating CEF formats, integrations. It is more than a logging solution right now. It is an XDR, threat analysis platform etc.

This acquisition is going to be interesting with app dynamics+splunk and others, it feels like there is a larger play here for Cisco.

I don't think the value that splunk have is transitive to ES or grafana. It is, its own thing.

Re: Cisco Acquires Splunk

#96
post #73
post #60

Earlier quoted context omitted.

Are medium-sized customers valuable to Splunk? In sales we call this "Ideal Customer Profile." Why do I want a customer with less money to spend if I have a product with enough capability for the gigantic money-is-no-object customers?

I believe the idea is that the big customers are interested because everyone is raving about it. If you price out the smaller customers, there's nobody to rave about it. Consider, for example, that Akamai's revenues are sitting in a plateau over the last 5 years, while Cloudflare is moving up.

> I believe the idea is that the big customers are interested because everyone is raving about it. If you price out the smaller customers, there's nobody to rave about it.

That's not how enterprise procurement works, which is what makes the big bucks for companies like Akamai and Splunk.

Cloudflare traditionally targeted mid-market and is in the process of building out an upper market/enterprise motion (I worked with the guy they hired to lead that in a previous role).

I can dig deeper into ICP, Market Segmentation, and Enterprise sales if interested. There is too much FUD on HN

Re: Cisco Acquires Splunk

#98
post #12

Earlier quoted context omitted.

I haven't heard a single person trying to get off of it because "there are better SIEMs" - they're universally looking at other options because of the price. Cisco has the luxury of bundle and save that Splunk does not.

former firepower customer... I guess we'll see. I can see them shipping a really cool-looking whitepaper detailing FTD, Amp, and Splunk... but actually operating it will feel similar to driving a 20 yr old salt state jeep wrangler on the autobahn.

Oh god those firepowers we bought were so bad. The controller webpage needed to control our pair needed something like 32GB of ram just to load.

Using fortigates now, far happier with them.

But it's not just the firewall level, they were so bad it made us reevaluate our core switches and I don't think we've bought a cisco switch for at least 2 years.

Re: Cisco Acquires Splunk

#99

I hated Splunk so much that I spent a couple days a few months ago writing a single 1200 line python script that does absolutely everything I need in terms of automatic log collection, ingestion, and analysis from a fleet of cloud instances. It pulls in all the log lines, enriches them with useful metadata like the IP address of the instance, the machine name, the log source, the datetime, etc. and stores it all in S…

Why wouldn't you just use Graylog Free Edition?

While it doesn't compete with Splunk, IMHO, it's much easier and much better than what 1,200 lines of Python could conjure up. Dashboarding and all. I love it and use it in a very large enterprise environment.

Re: Cisco Acquires Splunk

#100
post #75

Earlier quoted context omitted.

Splunk is a dead player too. It's a great match.

This might be why Cisco bought them: OMB Memorandum M-21-31[0], “Improving the Federal Government's Investigative and Remediation Capabilities Related to Cybersecurity Incidents” which includes directives to ensure event logging goes well beyond the current norms. By all accounts I've heard it's going to enrich the fortunes of every single SIEM/Log aggregation company out there, pretty much every govt contractor is g…

Partially, but Splunk has been on the market for sometime actually. Also, large companies that compete with Cisco like CRWD, PAN, etc have been building out SIEM capabilities, as has Cisco, though Cisco being Cisco it didn't get the attention needed.
Post reply on HN