Speaking frankly, unless a Splunk alternative implements API compatibility for search, it’s a nonstarter in the marketplace. At the enterprise I work at, developers and operations teams both use splunk to observe and analyze application behavior, and have thousands of dashboards and alerts set up and integrated into mature operational processes. Migrating this over to another application is nontrivial. And the biggest problem isn’t even a technical one, it’s a social one - how do you train three hundred engineers to use a different log search tool.
I would absolutely love to see a competitor emerge that addressed the migration problem through a compatible search api. Handling other timeseries data like metrics would just be icing on the cake.