7 ms·
Splunk IP suit against Cribl
- rmdoss 4y agoHope Splunk loses. Trying to kill a good player that makes Splunk less expensive.
- wdb 4y agoPretty happy with opentelemetry collector that allows to receive traces/metrics/logs etc in different formats and then cleanup the data and push it to aggregators like Splunk or Datadog. Makes it easy to switch when the tool I am using now gets a bit expensive for tracing
- danielodievich 4y agoDang! Back in early days of AppDynamics, the founder who started AppDynamics after working at CA got hit by CA lawsuit, which lasted for a while but eventually got settled. Similar allegations. it was highly unpleasant and detrimental to the IPO preps. Some of my colleagues from there went to Cribl and sure hope they aren't going to be impacted, but they likely will will.
- debacle 4y agoSplunk is great software. With no details, hard to read this suit. Would need to know what evidence Splunk has that Clint Sharp stole source code. All the rest seems superfluous.
- skipkey 4y agoThe lawsuit is linked in the post. I didn’t read the whole thing, but skimming, the smoking gun seems to be that an implementation of Splunk’s S2S protocol was posted to his personal GitHub while he was still an employee. They claim that the header files just had the Splunk copyright notices removed, but just being a re-implementation of the objects wouldn’t surprise me. Depending on the jurisdiction that might matter. There are also various copyright claims on things in manuals, plus claims that they infringed numerous patents. All in all, it sounds pretty bad, but lawsuits almost always do. I would wait to read the responses before coming to any conclusions.
- ec109685 4y agoPretty poor that S2S is a proprietary protocol to begin with.
- PanosJee 4y agoI don't think Splunk claims will hold in court. As said running Wireguard would too just fine. Mr. Sharp posted a derivation of Splunk’s proprietary and confidential S2S source code to his personal github webpage (a publicly accessible website for sharing source code). Mr. Sharp named this derived code “go-S2S.”
- PanosJee 4y agoFrom the lawsuit: Although Splunk provides HEC for third parties to use, Splunk maintains other aspects of its software as proprietary. One example of such proprietary software is the “S2S” protocol. S2S stands for “Splunk-to-Splunk,” and this is software that Splunk itself uses to send data to, or receive data from, Splunk Enterprise and other Splunk software and technologies. Splunk does not support use of S2S by third parties, does not publish S2S’s source code, and does not document S2S in a manner that facilitates third-party use of this protocol.
- ec109685 4y agoI still think that is poor form.
- _8j50 4y agoSplunk is the best at what it does with no close competition. I've been looking into Cribl and it seems their product has surpassed their competition as well but not in search, more in data summarization and log reduction, possibly before you ship it off to a more proper place like Splunk. Splunk's cost makes it inaccessible to most people or companies. I mean, I work in infosec and I highly caution against Splunk because it is so amazing you will hate anything else but in security you need tons of otherwise rubbish data collected centrally sometimes and it will force you into a corner where you will say you can't afford to store that log you really should be storing. Better a crappy tool that can be used to find the logs you need than a nice tool that can only retain so much. Cribl is supposed to help people reduce what they put i Splunk so they can keep using Splunk, it would have been nice if they partnered instead. Graylog is another nice tool I like that is somewhat but only slightly similar to Cribl that was founded by a former Splunker out of frustration.
- deleted 4y ago[deleted]
- chillfox 4y agoIs Splunk fast now? Last time I used it was almost a decade ago and it was rubbish, queries took 10-40 minutes to complete.
- jitl 4y agoWe recently transitioned to it at Notion and it’s been very fast, outperforming the previous log vendor substantially while offering better search and UX. If you used the on-prem version, the cloud version is quite a different experience.
- chillfox 4y agoI don't know which version we used, just that it was managed and configured by Splunk. We were only sending a small subset of our logs to it so about 200+ GB a day. Our Linux box with spinning disks could grep the full set of logs much faster than querying Splunk, so I don't think anyone really used it.
- npalli 4y agoYou can't start Cribl without some Crib.
- teraflop 4y agoOn the one hand, taking code from your employer and posting it to GitHub with the copyright notices removed is about as clear-cut a case of copyright infringement as you can get -- if they have evidence. Should be easy to confirm or deny by looking at version control history. (This seems to be the repository in question, but it's been taken down: https://web.archive.org/web/20210104032001/https://github.com/coccyx/go-s2s https://web.archive.org/web/20210104032001/https://github.co...) On the other hand, the patent claims referenced in the lawsuit seem to me like great examples of software patents that ought to be struck down for being uselessly over-broad. For example, I would love to hear an argument as to how the "'433 Patent" wouldn't be infringed by running Wireshark in a Kubernetes pod. That meets every single one of the claimed elements that Splunk is claiming Cribl is infringing.
- EdwardDiego 4y agoI'm not sure I understand the business impact of a protocol? Presumably anyone with Wireshark could reverse it, so does it impart a significant advantage? Or is it just about control?
- adinisom 4y agoA more complete archive: https://archive.ph/HKAF2 https://archive.ph/HKAF2
- flounder3 4y agoSplunk, as a company, is a shell of its former self. All they care about is pimping themselves out to maximize profits to an extreme that only Dilbert can relate to, even at the expense of destroying a long term professional relationship over trivial matters. They are more than happy to kill a deal over a 5% disagreement rather than understand the needs of a Fortune 500 customer and negotiate. They are mad because Cribl is good at transforming data before it ingested by Splunk, so as to reduce the amount of data that is indexed. Period. Splunk ONLY RECENTLY released “Ingest Actions” to filter data post-ingest (to avoid indexing) for their SaaS product — something that has always been a mainstay of their on-premise “Enterprise” product. Their ONLY suggestion to filter data that we didn’t care to index in early 2021? Cribl. There’s literally no other reason for us to use Cribl. I’ve been paying for Splunk since 2008 and can’t wait to get away from them. Their sales teams have decayed into unethical slimebags and I am trying everything in my power to not renew our contracts with them. This just sealed the deal. Source: I cut checks to Splunk for $x,xxx,xxx yearly
- ec109685 4y agoWhat are you planning to move to?
- flounder3 4y agoSounds crazy, but Datadog. I’ve been hammering their product teams for years with specific use cases for the sole purpose of replacing Splunk. They recently migrated search technologies and are rapidly closing the gap. Plus, their exclusion features are instant and fantastic, and their C-suite replies to me when I escalate. Elasticsearch simply couldn’t handle key collisions. We have hundreds of various apps across 5-10 different languages and frameworks where a key name may be reused as either a string or a hash or an integer or an array. If we can’t freeform search (which Splunk is EXCELLENT at), we just need to be able to transform the data beforehand. Datadog plans to do so with their recent acquisition of Vector.
- david38 4y agoSounds crazy indeed. I worked at Splunk for many years and was a DataDog customer later. The costs of either are not something I care to deal with.
- sn0w_crash 4y agoPMs leave and start competing products. This stuff happens all the time. Unless splunk has a smoking gun it’s hard to really take their side here.
- throwawanginee2 4y agoSplunk is a great tool but expensive. I like splunk's aggregation feature very much. If it is server logs, it can aggregate and tell me how many http 500 errors I have, how many requests resulted in 404 etc. It can tell me top IP addresses where I am getting requests from, etc. I want to take a CSV file and provide same functionality. Eg. Give user information on how many times each field occurs. For example, if it is a CSV file with cities, countries, continents, I want to aggregate and tell how many cities are in each country and how many countries are in each continent. Is there an open source version of splunk I can modify? I tried logstash but it is not straight forward to work with. It still needs me to define schema everytime. Thx!
- stevewatson301 4y ago> Is there an open source version of splunk I can modify? https://github.com/grafana/loki https://github.com/grafana/loki might work for you. It’s not a drop in replacement for Splunk, FWIW.
- sofixa 4y agoWhat you're describing sounds like Loki (Grafana's Prometheus inspired logging tool, which is super fast and cheap/easy, even though it sacrifices some flexibility to get there) Metric Queries: https://grafana.com/docs/loki/latest/logql/metric_queries/ https://grafana.com/docs/loki/latest/logql/metric_queries/
- wizwit999 4y agoWe're building Matano (https://github.com/matanolabs/matano https://github.com/matanolabs/matano), an open source security lake platform. It's a different approach since we normalize logs from JSON, csv, etc, and ingest them into Apache Iceberg tables, but it allows for massive scale and joins, aggregations, etc using SQL.
- deleted 4y ago[deleted]
- doorsopen 4y agoFrom the lawsuit looks like the most clear cut evidence they have is: - Founder publishing a private protocol definition to help in building for it - Sales staff sending account and prospect info to their new cribl email addresses before leaving Splunk - Engineers leaving Splunk with technical specifications, such as their newer S2S protocol versions The patent stuff is kind of whatever, but all three of those items would be enough to establish some very clear damages. Cribls an exciting new player but they can't take shortcuts like this, if the allegations are founded.
- ZephyrBlu 4y agoHonest question, where is the line here? Obviously we all retain knowledge from previous jobs so what's the line between that and exactly copying a spec?
- compsciphd 4y agohonestly, I've never moved from a role in one company to a role in a new company that directly competes with the role I had in my old company. While I have jumped to competitors, I moved to roles that weren't in any form competition to my former team/role. That makes it easy, even if I would accidentally take things with me, I wouldn't be tempted to look at it, as there would be no point. So yes, I take all my growth, knowledge and experience, but nothing that is really unique (say trade secrets) to old company would directly apply to my new role, so there has never been any problem. Once one is willing to jump to a competitor in a manner where you trade secret knowledge would benefit your role directly, one is creating a problem.
- aaa_aaa 4y agoTo me, unless there is a legal document you signed with your employer, there is no line. Even, IMO, IP is not `property` so that it cannot be used against. But that is another discussion.
- finnh 4y agoI think the line here is pretty straightforward: the contents of your mind are all yours. Anything beyond that (documents, source code, lists of prospects) is not. Non-compete clauses will try to limit the usefulness of the "in your mind" knowledge by restricting the domains in which you can work post-departure. It's my understanding that such clauses are generally held to be unenforceable except in an acquisition scenario.
- pharmakom 4y agocan anyone explain to a developer what splunk does?
- tannhaeuser 4y agoConveniently (and expensively) provide a destination for log data streams and enable realtime ad-hoc querying against that data at scale, with time series features and a Unix shell pipeline-like query syntax. As the comments tell, though, you must tweak it to actually see performance. And, having seen its use in ecommerce with eg logged transaction details such as credit card numbers and other PII, the prospect of easily and loosely logging all the things is limited by data security and privacy concerns, with some practices a recipe for big-time breaches and lawsuits. Aand, per seat licensing is expensive, such that more often than not IME you have a Splunk guy/gal to whom you must address your data reporting needs, questioning any benefits that ad-hoc querying your logs may have.
- bak3y 4y agoIt does Enterprise level logging better than any other tool I've ever used. And it drains your bank account.
- PanosJee 4y agoSplunk now an IP bully? Go Clint & Ledio!
- kenm47 4y agoI’m currently working with a company in this space (axiom.co) and this shit scares me because it’s splunk scared. Maybe cribl did this? But the press release reads like a self-Pat on the back.
- PanosJee 4y agoAnother funny tidbit: > On March 24, 2017, a few months after his initial copying of Splunk’s source code, Mr. Sharp resigned from Splunk to co-found Cribl with Dritan Bitincka and Ledion Bitincka— both former software architects at Splunk. Except that they didn't because initially the had created a company called diag.io that was focused on troubleshooting fault configurations.
- smallerfish 4y agoOur alerting solution, "OpterVics", was bought by Splunk. Since then it's been a shitshow - the service is running, but it's almost impossible to get a response from support. They sent us an invoice for renewal in early August. I replied back (5 separate times) asking for the original contract (our ops department is tightening up on vendor management, didn't have it on file already); and we've heard nothing. Our service has continued to work despite not having paid (or signed a renewal), but we're switching to opsgenie.
- glonq 4y agoSplunk is/was a damn fine tool, but I had to stop using it 5+ years ago because they priced themselves out of the stratosphere.
- _fat_santa 4y agoI would love to use splunk on some of my side projects. Does anyone know of a decent alternative for non-enterprise customers?
- njpatel 4y ago(co-founder here) Try axiom.co - we support splunk-like query syntax, dashboards, monitors, unlimited sources/hosts/etc, and you get 500GB/mo ingest + 30 days retention on the free plan.
- alloutblitz1 4y agoOpsVerse allows you to bring up Grafana Loki for logs. There's also Logz.io or you can use Elastic for an ES backend.
- rsdbdr203 4y agoI posted above, but starting log-store.com so I'm trying to promote it in threads without being too pushy :-) It's in beta and free. My plan is honestly to have my pricing be free for small amounts of data, and then 50% the price of Splunk for larger data sets. Just show me an invoice, and you'll pay half!
- blarneyrocks 4y agoAfter reading the full lawsuit, I think Cribl has a real threat on their hands. They've been playing fast and loose with the rules for a long time. Exports of leads from departing Splunkers, using licenses they're not entitled to use, and yes, using proprietary code that was gathered through less than fully kosher means. While this doesn't look great for Splunk, they wouldn't have filed the suit if they thought they would lose.