5 ms·
Genuinely surprised anybody would acquire Splunk in 2023. Whenever you hear about Splunk from security engineers, they're actively trying to get off it (edit: y
by wittekm 3y ago
Genuinely surprised anybody would acquire Splunk in 2023. Whenever you hear about Splunk from security engineers, they're actively trying to get off it (edit: yes, primarily because of cost). Better, next-gen SIEMs are either here or around the corner.
- burren 3y ago[flagged]
- badblock 3y agoThere’s a couple out there, Devo, Exabeam and Sumo Logic are the big three I’ve seen most recently.
- bugsense 3y agoSumoLogic is equally dead and a way inferior product. It's owned by a PE now, the same that owns New Relic so expect some action there.
- throwy1241265 3y agoAvoid Exabeam. Their UEBA product is riddled with problems, and they are not concerned that it does not display timestamps for when the event occurred- they display timestamps for event ingestion which can sometimes be hours off. They also seem to outsource much of the development, maintenance and support and appear to have high turnover.
- rho138 3y agoAvoid Devo, querying across data sets with their system was hot garbage in comparison to both splunk and elastic. Then when you try and break up with them it becomes a whole thing.
- deleted 3y ago[deleted]
- flangola7 3y agoWhat does next gen even mean
- willk 3y agoI think they’re trying to get off of it because it is so freaking expensive.
- SOLAR_FIELDS 3y agoI used Splunk at a previous job and that’s one of my few/only complaints with it. Great tool but extremely expensive for what you get. Datadog is the same way as well as Pagerduty. There’s not enough competition in these spaces
- ec109685 3y agoWhy is pagerduty hard to switch off of? It has all kinds of useless and expensive bells and whistles, while the core functionality is a commodity that several companies offer. We moved vendors a few time and it wasn’t that painful.
- solatic 3y agoWho else will call a POTS phone line when there's an alert? Fact: I'm not going to hear my phone ping in the middle of the night. I'm much more likely to hear my phone ring.
- aeonik 3y agoWhich ones do you recommend? Every one I have tried hasn't really given me the same flexibility as Splunk, most seem to miss the core part of what makes Splunk cool. Though I'd definitely like to see Splunk improve their design.
- chelmzy 3y agoHe's talking out of his ass. But newish competitors are Devo/Sumo Logic.
- phyzome 3y agoNot sure how well "new" fits Sumo Logic. I was using them ten years ago, I think?
- sbuk 3y agoHumio is also promising, however they've been acquired by CrowdStrike, who aren't know for low prices!
- TheIronMark 3y agoSumoLogic is also not cheap.
- dx034 3y agoGraylog looks like a good competitor. Certainly won't scale as well, but I've had good experience with it.
- cduzz 3y agoThe thing that will totally replace splunk (and elastic and snowflake and likely several other whole ecosystems) is some random thing pouring data into clickhouse. I am nervous about how clickhouse is going to monetize, whenever they decide to turn on the revenue spigot.
- ejcx 3y agoI hate to shill in this thread, but that's exactly what we built at runreveal, so I completely agree! We saw the power of clickhouse when we were at segment and cloudflare, so built a company around it. And since clickhouse is open source, we hope that people will stop giving their security data to vendors who then charge you rent for it. I think the future is writing this data to clickhouse, but also our customer's clickhouses
- tw04 3y agoI haven't heard a single person trying to get off of it because "there are better SIEMs" - they're universally looking at other options because of the price. Cisco has the luxury of bundle and save that Splunk does not.
- jabroni_salad 3y agoformer firepower customer... I guess we'll see. I can see them shipping a really cool-looking whitepaper detailing FTD, Amp, and Splunk... but actually operating it will feel similar to driving a 20 yr old salt state jeep wrangler on the autobahn.
- ta1243 3y agoOh god those firepowers we bought were so bad. The controller webpage needed to control our pair needed something like 32GB of ram just to load. Using fortigates now, far happier with them. But it's not just the firewall level, they were so bad it made us reevaluate our core switches and I don't think we've bought a cisco switch for at least 2 years.
- georgyo 3y agoSplunk is a great product with horrible sales and business team. The reason why them _trying_ to get off it is because they have a bunch of stuff that is easy and works in splunk, but don't want to pay the exorbitant licensing, or pay even more to increase their use. But getting off a good product is hard, and they will continue to use it and even pay. The kind of thing Cisco, Oracle, and IBM love are companies with very expensive products in which no development needs to happen and customers cannot move away easily.
- sumtechguy 3y ago> with horrible sales and business team I was in one of these meetings with like 20 engineers on how amazing this thing was. We knew that because we already used it it quite extensively. The very extremely hyper sales rep kept ducking out of the meeting every 5 mins. I recognized it for what it was. He was ducking out to do bumps of coke so he could be more pumped to sell us more stuff.
- baz00 3y agoI think we had the same sales rep.
- IG_Semmelweiss 3y agojesus, that's incredible
- paws 3y agoYikes. The only other time I heard about the Splunk sales team in the news, it sounded pretty bad also. https://www.theregister.com/2020/08/12/splunk_sales_discrimination_case/ https://www.theregister.com/2020/08/12/splunk_sales_discrimi...
- baz00 3y agoYeah it's easier getting rid of chlamydia than Splunk sales reps.
- hn_throwaway_99 3y ago
- softwaredoug 3y agoSounds exactly like the kind of Enterprise software Cisco wants.... At that pricepoint they don't really care what the security engineers want, they sell to higher level folks.
- TecoAndJix 3y agoI'd love to know what the security engineers you are talking to recommend because Splunk ES/SOAR are top notch products - even with the cost (which is insane).
- steveBK123 3y agoI was at a shop that got heavily integrated into Splunk for security use cases and then entered a split brain mode of 'well if you need observability we already have Splunk' but also 'hey stop doing so much observability, this thing is expensive!'. So for 5 years time we used it for observability, we were only half-integrated and also trying to get off of it. Great stuff.
- 0xBDB 3y agoPretty sure every Splunk customer has that split brain. This thing's great, what can we quit sending to it?
- dharmab 3y agoWorked on a piece of software which suffered from years of this split brain. It had some logging and some metrics, but the team was told to be economical about observability. This resulted in the software having many blind spots which led to production issues that had to be manually reproduced. When I become responsible for the software I personally overhauled the logging and the team had to work together to rebuild the metrics functionality.
- steveBK123 3y agothis is an area that gets very political with architects, managers and other non-coders having too much of a say a lot of paralysis on the app dev side as the status quo is easier than fighting for a sensible outcome its also something that yes, benefits stakeholders... but only on a 2nd/3rd order effect of outage avoidance & remediation.. so theres not a huge reward for doing it really really well in many shops
- mritchie712 3y agohere (just made it around the corner): https://runreveal.com/ https://runreveal.com/
- ikiris 3y agoIts a great fit for Cisco They want so hard to be a software company, and they already have experience with highly inflated priced products. Their real target is probably trying to offer this built in to meraki like products as a one stop shop. I could see them finally burning their monitoring product in a fire and replacing it with splunk and grafana then selling it as an all cloud solution. At least the intent, we know Cisco's track record for integrating acquisitions.
- knallfrosch 3y agoSo Splunk is too expensive and there are better products and people keep paying. This doesn't really add up.
- hiatus 3y agoInertia can be a strong force in organizations. In good times and without external pressures, it can be easier to keep the status quo.