Cisco Acquires Splunk
splunk.com
splunk.com
https://realmoney.thestreet.com/investing/technology/cisco-r...
Good luck Splunk folks - Cisco isn't exactly known for their software innovation in the upper stacks (they still do pretty incredible things at the network OS layer).
Not arguing with you, it's genuine curiosity on my part.
In sales we call this "Ideal Customer Profile." Why do I want a customer with less money to spend if I have a product with enough capability for the gigantic money-is-no-object customers?
Consider, for example, that Akamai's revenues are sitting in a plateau over the last 5 years, while Cloudflare is moving up.
That's not how enterprise procurement works, which is what makes the big bucks for companies like Akamai and Splunk.
Cloudflare traditionally targeted mid-market and is in the process of building out an upper market/enterprise motion (I worked with the guy they hired to lead that in a previous role).
I can dig deeper into ICP, Market Segmentation, and Enterprise sales if interested. There is too much FUD on HN
Akamai has certainly done well over their lifetime, but their revenue for the last 5 years is very flat. That's not "FUD".
In this case the big customers are already using it. Splunk's value proposition for those customer is that they can handle with a massive volume without a hiccup. Small customers don't have the needs where Splunk is uniquely useful.
We loved Splunk, we invested quite a bit in it both for technical monitoring and business intelligence. After a while the price went so high we cut it all, moved to kdb/tableau/elk/whatever crappier system that cost less.
Money is ALWAYS an object and Splunk makes sure to dig a hole deep enough for even the deepest pockets. I too prefer my shareholders to collect the fruit of my labor rather than... Splunk. At least they can reinvest some profit in us. Not Splunk, nope, they keep digging that hole in our pockets.
Personally I can't say if that's actually happening with Splunk, but it's a very plausible scenario.
Somehow companies manage to make it work extracting money from your existing money-is-no-object customers. Oracle and IBM have basically zero mind-share amongst HN reading folks, but yet there they are.
We would routinely switch vendors and it would be an fyi to the end users if that.
It’s one of the reasons myself and huge corps don’t mix!
I think once a customer with a big enough budget is recognized by sales at one of these big organizations they make the sale happen. They talk to the higher-ups and either make them happy, or feed them a lot of FUD (or both), and then they're in, regardless of what the people working with the products (many of whom might be external vendors or consultants!) think.
They're basically focused on more traditional sales & marketing instead of more grassroots sales & marketing (mindshare), but at least in my experience they definitely still get new customers.
Microsoft dominated the nineties especially and the naughts less so but still because the marginal price of their OS was zero - due to piracy. Yes they didn't like business to run unlicensed but if you were a customer, nobody cared, because in 5-10-20 years you'd be a paying business or would work for a paying business.
Splunk doesn't get that. There are no hobbyist/prosumer splunk installations. Zero. Nada. That's also how Linux won in the server space - nobody set up Windows servers as a hobby and 20 years later we're here.
IOW it's medium-term short-sightedness, if it makes sense. Tactically good, strategically so-so to bad, depending on your moat and momentum.
Not true. I ran a free (legit!) Splunk instance in my homelab for years. It's been several years since I shut the homelab down, so I couldn't tell you if they still have hobbyist licensing, but they certainly had it in the past.
I know they have a free license for super small deployments but haven’t heard of anyone actually using it.
I think modern solutions would be any of the recent Clickhouse based solutions.
Loki exists but it seems to have a tragically small market share.
For some organizations what Splunk does well is important but for most of them they really only need much more basic log aggregation and analysis tools.
What splunk has going for it now is that they have lot invested in compliance and security but its only matter of time before other providers start offering the same. Only use case i would consider them for is a SIEM. Datadog logging is so cheap and works and gives me more money to spend on other things.
But as you lose the smaller and middle-range customers, you're also missing on the trends of the market, while getting shaken up by the big players you can't afford to say no to. If one of your whales needs feature Y, no matter how exotic you think it could be, you'll have to implement Y, bloating your product for the rest of your clients.
And while you're doing that, smaller competitors slowly creep up, eating up the bottom of you market, until you're stuck in a niche.
So what, milking mega enterprise for ossified products is a decently profitable niche. IBM, SAP, that huge American company powering a lot of hospital IT, Cisco itself...
Epic
There's a few contenders for sure.
Basically every ERP technology every invented.
It was super expensive and what I dubbed a "choice bot"
Where you are basically navigating a decision tree and the text box is extraneous
It is not better at all, by almost any metric other than overhead. Losing 1 of 1000 customers @ $1000 is very different than 1 of 1 customer @ $1M. One is easy to manage, the other leaves you dead in the water. In addition, you'd start to make concessions/unnatural decisions because you're so lopsided in diversity. And you're going to get completely fucked at renewal time. and, and and..
Good M&A teams know this. They build a risk profile when revenue is a component of the acquisition. The acquiring party gets to learn a lot about the fundamentals when putting deals together and it's all factored in.
To put it simply: having a healthy balance of revenue from multiple sources is a premium. Those are opportunities to advance your relationship and grow. Too many eggs in too few baskets are major red flags that will have your revenue working against you.
They'll pick up another 10-20% capex/open/cogs on private pricing that Cisco gets.
Great M&A if Cisco manages to maintain Splunk's customer base. I look at Splunk as the Oracle DB of the world now, does anything a giant enterprise can imagine, but is old and costs a leg & arm.
PagerDuty is significantly better for about the same price and demonstrates ways in which the product could have kept improving.
They care about its capabilities and its on a different level than Datadog, Elastic etc
That’s… a compliment? There have been very few positive interface developments in the last 2 decades for power users. If you want to rip out 95% of the functionality and 99% of the usefulness so morons with iPads can navigate it, then it probably needs adjustments.
OMB Memorandum M-21-31[0], “Improving the Federal Government's Investigative and Remediation Capabilities Related to Cybersecurity Incidents” which includes directives to ensure event logging goes well beyond the current norms.
By all accounts I've heard it's going to enrich the fortunes of every single SIEM/Log aggregation company out there, pretty much every govt contractor is going to need larger licenses in the next few years as contracts get rewritten with this EO in mind.
[0] https://www.fedramp.gov/2023-07-14-fedramp-guidance-for-m-21...
The logs into metrics abilities along with the ability to unlock finding relationships in data is amazing. Mouse over the fields found in logs matching your search and see the top N values for other these keys.
Imagine getting an alert and being able to search your logs for that error message and immediately being able to see it affects these N users disproportionally, that it is split 50/50 in two of your seven regions, only affects version X of your service. A couple more searches to dig in and you can see it is only feature Y with setting Z that is the problem. You switch to a timechart view and can see the moment the error started and the affected user counts. A few more minutes and your support team has a list of known affected users. You decide to monitor this new feature so you quickly create a new dashboard (or panel on an existing dashboard) and a new alert. At no time did you have to declare a field of your structured logs as an index or as searchable or aggregatable.
We used Splunk to associate a change request ticket number all the way through the change control process to the Puppet log output tagging each change to the original business purpose.
It was like magic for auditors back then and I rarely see that depth of tracing automated changes to business purpose in the field today, though we get close with gitops.
With Vector you can even source from Splunk and move elsewhere.
I spend most of my day managing Meraki networks and some of that is seriously powerful and innovative.
0 - Even switching originally came to Cisco via a whole series of acquisitions in the 90s. You could argue -- and Stanford certainly did -- that routing was an acquisition of sorts, as well.
1 - Their M&A guy even wrote a book about it, called Doing Both, which purported to explain how Cisco achieved so many of their goals by refusing to make false "either/or" decisions. Ironically, almost every example in the book was something that Cisco is spectacularly bad at.
One other thing that I think feeds into these acquisition mishaps is that Cisco has, in my opinion, consistently over-estimated how much intelligence would be needed (or wanted) in the core network. In their view, intelligent network services = expensive network devices = revenue for Cisco. I think what the Internet specifically and IP in general, as well as the evolution of LAN technologies over time have proven is that when it comes to the core network, simple is almost always better and intelligence should move to the edge, where innovation can happen quicker and where services can be implemented in software.
As an example, at one point they had what was, essentially, a middleware system (like Websphere,) which they called Application Oriented Networking. The idea was you would deploy these on your network gear, throughout your network, and it would provide message routing and translation services. They had a whole "architecture" built for it, called Services Oriented Network Architecture[0]. I don't think the people who built it really understood that it provided no real advantage over a cluster of middleware/ESB/MQ servers in a data center and that nobody was going to pay a huge premium to build that capability in their IP routers.
0 - https://www.cisco.com/c/dam/global/it_it/solutions/ent/tecno...
Ironically, those set top makers were in a perfect position to take advantage of it. They could have been Roku - they already had huge market penetration.
The one other rule that John Chambers lived by was "no merger of equals." It was always about a big fish swallowing a smaller one. Cisco's market cap is an order of magnitude greater than Splunk's, but this is as close to breaking that Chambers Rule of Acquisitions as anything they've done to date.
Here's the full history of Cisco acquisitions. Maybe someone with more M&A lore would scorecard it to see which were dreams and which were duds.
https://www.cisco.com/c/en/us/about/corporate-strategy-offic...
I enjoyed Cisco (great 4th July parties!) but it never felt like we were properly integrated.
and they're buying Splunk, so if the concern is continued innovation at the upper levels of the stack...
It is certainly no secret that Cisco wanted to buy Splunk for $20BN in Februart 2022
2. Don’t do it by buying short-dated out-of-the-money call options on merger targets [0]
[0]: lawsofinsidertrading.com
IMO though it could easily be just some WSB bro that gambled and got lucky. Robinhood and other platforms make it easy to trade short dated options these days and people love to gamble on them.
100%
It's possible someone was selling contracts as a hedge since the tech market has been really bad this week. A market maker was obligated to buy the contracts.
The person selling the contracts gets $22k in premium, and misses out on the pop. The market maker will absolutely exercise the contracts and profit.
(This is coming from someone who sold APPL calls expiring tomorrow for .08 at a high strike today)
Personal opinion: It's insider trading. You'd need a ton of shares to be able to sell $22k worth of contracts at a high strike unless you're doing naked options selling.
In terms of how the market maker is involved:
https://www.projectfinance.com/options-market-maker/
hedging:
Selling options, on the other hand...
Either way, it's a bad deal for both Splunk employees and their customers. SIEM is a space that is hard to be a leader in when you're not vendor agnostic. This is basically what XDR has become: vendors who have EDR/NDR/whatever are claiming to have some unique (it's not) data lake that can ingest any source, when in reality all of these solutions suck at everything outside of their own product set. I've worked with countless clients over the last year who, as an example, made the mistake of thinking Microsoft Sentinel was a cost effective tool, only to realize that once you're outside of the Microsoft ecosystem analytics/detections quality becomes very close to zero in terms of quality and the price is not cost effective. But SIEM has always had a flair of vendor lock in to it anyway. It's a hard platform to move from once time has been invested in wrangling all the data sources for ingest, transforming them to some bespoke schema and then all of the detection engineering on top of that. It's almost as bad as large scale firewall migrations.
What a lot of folks don't know is that when Splunk decided to move to a Cloud/SaaS model they literally just lifted and shifted the unoptimized bits of on-prem Splunk to a managed VPC under the direction of then-CTO Tim Tully. Splunk was losing money on every deal due to the infra outcosting the insanely high quotes Splunk was churning out. This is a great case study on Innovators Dilemma as Splunk drug their feet for years internally saying that cloud would never impact them. And then they realized they were far behind the 8-ball and decided to hemorrhage cash so as to not churn customers. They eventually optimized it, but the underpinnings still aren't what a fresh take on the bits would have looked like had Splunk done the "right" thing.
Cisco will continue to play ELA games with customers just like VMware. For those who don't know both companies like to get customers into ELAs. Why? Because those contracts basically state that said customer will buy X number of new products annually or risk losing some, or all, of their currently negotiated discount. For smaller orgs this works less well, but you'd be amazed at how those smaller are easily manipulated by snake oil sales folks. For large orgs this puts them in a bind. I've even seen shady contracts written (from Splunk) that had language wherein if the customer does not renegotiate or cancel a, let's say, 3 year contract in writing 90 days before it's going to expire that the contract will autorenew at a ridiculous percentage increase in cost.
Move away from these enterprise product sets where and when you can. These companies are focused on the bottom line - and that is profit, not the customer. The industry has it all backwards, and it's working for them... Still.
This was insider trading.
Or let’s say I was short the stock and wanted to hedge during a volatile FOMC period.
Scalping your gamma?
Feels like the stock market is just a bunch of jargon, subterfuge and financial sleight of hand. Like we learned nothing from 2008, and just created financial 'products' mechanisms and gambits out of thin air.
Stock shorting has got to be one of the most pants-on-head stupid things I've ever heard.
Well, next to gamma scalping.
Here, what they're doing is establishing a position which will make money if the stock moves either direction out of a narrow band. If you believe there's going to be a big industry upset, but don't know whether it will hurt or harm a specific player, you might enter this position. In turn, the overall market volatility is reduced and liquidity is added by your information being added to the market.
> Stock shorting has got to be one of the most pants-on-head stupid things I've ever heard.
All kinds of simple, legitimate reasons to short stocks. E.g. you are excessively exposed to that company's welfare for some reason (stock options, they're an important vendor, they're a big component in a mutual fund you own but you'd rather not own their stock, etc)-- you can take an opposite position by shorting. Or, here, you can use it to offset an option that moves in the opposite direction.
> Like we learned nothing from 2008, and just created financial 'products' mechanisms and gambits out of thin air.
This isn't too much like the house of cards from 2008. These types of strategies are not new; offsetting short positions by writing or buying options was in frequent use in the 1970s, if not before. Option use to profit from volatility (or hedge volatility) dates back more than 2000 years.
I'm not a big fan of esoteric, complicated financial schemes, or in creating options and financialized products for everything (e.g. cap and trade)... or situations where market players profit from privileged access to marketplaces (e.g. HFT). But the things you name are not any of these.
This is literally every industry. Do you think the average trader can understand the majority of discussions on HN w/o any domain experience? The jargon exists for a reason.
> Like we learned nothing from 2008, and just created financial 'products' mechanisms and gambits out of thin air.
The financial engineering issues in 2008 were fueled by other issues: simply we had the government suppressing true borrowing costs and fueling a housing bubble under socially progressive cover. These moves almost universally end in disaster historically. The "out of thin air" products I presume you're referring to all had/have legitimate use-cases: the problem is that nobody bothered to do proper risk management because the US Government was fanning the flames in one direction.
> Stock shorting has got to be one of the most pants-on-head stupid things I've ever heard.
That's probably because you don't understand the positive aspects. Shorting is absolutely critical to well functioning and efficient markets. It's not simply evil hedge funds betting against businesses or whatever trope you might have heard.
In fact, if housing was an easily shortable asset class, the above crisis you mention would have been far less severe (or possibly not happened at all) as short selling pressure would have kept prices at more reasonable levels.
What are your thoughts on insurance? Because shorting can be an insurance/hedge against price changes.
In the above, I’ve just realized a small profit by trading the underlying and a small bit of theta burn. As long as the former is greater than the latter (as long as realized vol > implied vol) I make money.
Rinse and repeat this process over and over again.
The only way the buyer could make a profit would be for Splunk to go higher than $127 and if it went significantly higher, they'd stand to make an eye-watering return-on-investment multiple in one day. Which is what happens.
It would be suspicious if this turns out to be a speculative trader making a one-off transaction.
Calls are the right to buy at $127 - the shares received can then be sold at market price.
Puts are the right to sell at $127 - the short position can then be closed by buying at market price.
However, AppDynamics and Duo seem to be doing well at Cisco from what I can tell. I think observability and security tools are a good match for Cisco and bundle well with hardware. For this reason, I’ll bet Splunk does reasonably well under Cisco too.
Already a customer/friend at a $6B retail customer of mine sent me the link first thing as a Splunk owner there. Just last week I asked if they'd looked at Datadog much yet, and said they'd rip Splunk from their cold dead hands. The follow up to the link for buyout news as that they were going to start looking at Datadog now. Splunk was already expensive, but not Cisco expensive.
We moved vendors a few time and it wasn’t that painful.
Fact: I'm not going to hear my phone ping in the middle of the night. I'm much more likely to hear my phone ring.
That said, every other product in this space is crap. I'm not sure why though. This seems like a pretty good market for disruption. Maybe there is some hidden "problem" that I don't know about.
I am nervous about how clickhouse is going to monetize, whenever they decide to turn on the revenue spigot.
And since clickhouse is open source, we hope that people will stop giving their security data to vendors who then charge you rent for it. I think the future is writing this data to clickhouse, but also our customer's clickhouses
Makes it attractive for enterprises already on their platform and they throw in discounts for E5 license tier customers as well (gotta keep pushing the “give us everything or pay way more for single feature licenses”).
https://panther.com - Built on top of Snowflake, so it scales well and they are building a more Splunk like interface.
https://runreveal.com - Still seed but shows a lot of promise
https://matando.dev - Still seed and don't have a hosted product yet but smart founders that have the right idea
https://hunters.ai - More threat hunting than SIEM but maybe that what certain folks need
https://gem.security - Still fairly early but if you are focused on cloud use cases this could be more of an option. (Disclaimer: I'm an Investor)
So was it you then with that one day call options trade? /s
We are still in early access but you can browse through our docs or swing by our Discord.
Cisco has the luxury of bundle and save that Splunk does not.
I can see them shipping a really cool-looking whitepaper detailing FTD, Amp, and Splunk... but actually operating it will feel similar to driving a 20 yr old salt state jeep wrangler on the autobahn.
Using fortigates now, far happier with them.
But it's not just the firewall level, they were so bad it made us reevaluate our core switches and I don't think we've bought a cisco switch for at least 2 years.
The reason why them _trying_ to get off it is because they have a bunch of stuff that is easy and works in splunk, but don't want to pay the exorbitant licensing, or pay even more to increase their use.
But getting off a good product is hard, and they will continue to use it and even pay.
The kind of thing Cisco, Oracle, and IBM love are companies with very expensive products in which no development needs to happen and customers cannot move away easily.
I was in one of these meetings with like 20 engineers on how amazing this thing was. We knew that because we already used it it quite extensively. The very extremely hyper sales rep kept ducking out of the meeting every 5 mins. I recognized it for what it was. He was ducking out to do bumps of coke so he could be more pumped to sell us more stuff.
https://www.theregister.com/2020/08/12/splunk_sales_discrimi...
So for 5 years time we used it for observability, we were only half-integrated and also trying to get off of it. Great stuff.
a lot of paralysis on the app dev side as the status quo is easier than fighting for a sensible outcome
its also something that yes, benefits stakeholders... but only on a 2nd/3rd order effect of outage avoidance & remediation.. so theres not a huge reward for doing it really really well in many shops
They want so hard to be a software company, and they already have experience with highly inflated priced products.
Their real target is probably trying to offer this built in to meraki like products as a one stop shop. I could see them finally burning their monitoring product in a fire and replacing it with splunk and grafana then selling it as an all cloud solution. At least the intent, we know Cisco's track record for integrating acquisitions.
Anecdote, I once worked with a client that really wanted to get Splunk, but produced so much network traffic that the discounted annual costs were more than the entire budget for the rest of the organization combined. That's staff, the building, equipment, power, water, everything...the estimated Splunk cost was more than that.
They went with a combination of ELK and a small team of dedicated developers writing automation and analytics against Spark and some enterprise SQL database. Still expensive, still cheaper than Splunk.
Great product, but completely useless utility value with financial considerations for environments with high volume.
Wow, it's THAT expensive?
There's even reluctance to turning things on and _watching_ it for 10 minutes. An activity that would immediately give you a much better idea of volume. Folks just don't like doing it.
Then you get the things were setting up a redundant logsource is just unwise. DNS logging was 2 orders of magnitude greater than everything else a SIEM was doing. And Email was about the same size.
(If you aren't careful and aren't managing your costs, but I suppose that's true of almost anything =)
Developers being absolutely terrible at pricing is not unintuitive (I'm a developer)
Splunk was used by a much larger product (easily 10x our scale) for monitoring events so there was no red tape to start using it.
After launching the detailed instrumentation (1 structured log event per HTTP request with a breakout of database/service activity) I was able to gain all of the insight needed and build a simple user/url lookup dashboard page to help other engineers see what was going on. We went from being mostly blind to almost full visibility in less than two weeks.
The downside was, we increased our billable Splunk usage by 50% since we were capturing so much more data per log event than the other product just consuming standard IIS/Apache logs.
That type of flexibility was totally worth it. Due to some acquisition shenanigans we broke off from that group and wound up on ELK stack which didn't perform quite as well, but was still usable with the same data. In today's day and age we could have just built an OpenTelemtry library.
Another solution is pre-processing (serial dupes are not forwarded).
Another solution is heavily reduced logging (ERR or higher only on prod hosts).
These can be used together and be very helpful.
With that said Splunk should offer such a pre-processing product (maybe it does?) which would probably increase their moat even though it reduces revenue somewhat in the near term.
https://www.splunk.com/en_us/blog/platform/introducing-edge-...
https://www.splunk.com/en_us/blog/conf-splunklive/ingest-act...
So it doesn’t need to be expensive, naturally, it just is.
Back in the day, I worked for an automation company. The software was called "Blade Runner." This was in the era when blade servers were all the rage.
Turns out you can't use a copyrighted name, so they changed it from "Blade Runner" to "BladeLogic." (All the directories are still "BR" btw.)
A bunch of the people from BladeLogic pulled a Mark Zuckerberg and moved from the Boston area to the Bay Area and founded SumoLogic, hence the name.
Oracle isn’t just expensive, it also has to be technically horrible but still operational.
fail to monetize the light?
It seems to me the marriage between APM and logging would be a home run.
* https://www.splunk.com/en_us/about-splunk/acquisitions/signa...
* https://www.splunk.com/en_us/blog/conf-splunklive/introducin...
Someone (not to name names) got bitten by the "anti-weirdware" bug and started shifting us off of all our custom-built solutions. Every team got hit with major distractions from their roadmaps for each of these changes. None of the headcount dedicated to staffing the internal systems was freed up - they had to run the new integrations.
The decision was made one day to migrate all of our observability stuff over to SignalFx. Observability wasn't our "core competency" and our systems were "weirdware".
We had to rewrite our instrumentation, all of our reporting dashboards, and all of our alerting DSLs changed. They were not replaced 1:1 for every system and metric, so we emerged in a much worse, much less visible situation across the board. Outages happened or went unreported.
Splunk acquired SignalFx and dramatically raised prices. We scrambled to do the migration process yet again, impacting roadmaps and leading to more outages.
Leadership was changed.
There's one thing to be said about NIH, but when you write systems that are already working, inexpensive, and easy to maintain, you shouldn't throw them out because you're worried analytics isn't your "core competency". Yes - it is your core competency, because you're selling uptime to your customers.
Any lower priced alternatives? Or self-hosted?
Splunk / Datadog have the classic user interface lead of a closed source solution, but IMO that premium's days are numbered.
I’m always happy when I can use some of our sources that are in splunk but get sad that I can’t do that with everything else.
Its cloud pricing is funny because it’s so much more powerful with massive amounts of data, but they charge based on storage. Our on prem instance wasn’t just simpler to price but we could throttle resources to allow for really high volumes of data with relatively slow query and analysis.
Splunk shares were trading at $119.59, so ~31% premium.
Cisco lost 4% in premarket trading.
acquirer pays a premium to nudge the acquiree's board to approve
acquirer's shareholders that disagree with the deal sell, in anticipation of value destruction
a board that approves a 0% premium (barring unusual exceptions) will be sued to oblivion
"the market thinks” gives the stock trade market an aura of reason and intelligence which it absolutely does not deserve for many historical reasons. Trading as it exists today is unhinged capitalism, it’s a cancer on our societies as it widens the gap between rich and poor. It should be taxed, something like an Automated Payment Transaction tax, to make high frequency or even medium frequency trading simply unrentable.
I’m not against the concept of stocks in general, but the way it operates now is simply sick, I don’t see how to phrase this differently.
Insider trade on Splunk acquisition? - https://news.ycombinator.com/item?id=37599587
Show HN: My Single-File Python Script I Used to Replace Splunk in My Startup - https://news.ycombinator.com/item?id=37600019
Cisco pulled out of SentinelOne acquisition after due diligence - https://news.ycombinator.com/item?id=37598299
Back in the day, logging, metrics, event collection etc. was a hard problem that they solved. Esp. when there weren't any simple distributed storage operators.
They have been a cockroach in the orgs, surviving every downturn. As a dev, you might hate it, CISO and CIOs love it. Orgs, often mandate it. The way they dominated the market is via creating CEF formats, integrations. It is more than a logging solution right now. It is an XDR, threat analysis platform etc.
This acquisition is going to be interesting with app dynamics+splunk and others, it feels like there is a larger play here for Cisco.
I don't think the value that splunk have is transitive to ES or grafana. It is, its own thing.
I know lot of cloud providers are also whitelabeling known products.
If you can afford Splunk, just wait a couple of years until they figure that out.
Someone opened 127 calls for $22,000, and closed them today after the buy-out announcement.
A cool way to turn $22,000 into $10,043,000
[1] https://www.reddit.com/r/wallstreetbets/comments/16oi9an/som...
[0] https://www.cnbc.com/2023/09/21/cisco-acquiring-splunk-for-1...
Insider trade on Splunk acquisition? - https://news.ycombinator.com/item?id=37599587 - Sept 2023 (245 comments)
I'm sure there are tons of other, lesser known acquisitions... looking at what Apple acquires - seems relevant to be integrated into their products: https://en.wikipedia.org/wiki/List_of_mergers_and_acquisitio...
Oh, wow, they even acquired Intel smartphone modem business at 2019 and other Semiconductor businesses.
Precipitation probability is the most important thing in a weather app to me.
The cost also went down. DarkSky was $4. I wasn't ever willing to pay for a weather app.
I see hourly rain predictability for today, and for future days there are hourly precipitation charts in inches. I can't imagine that precipitation beyond the current day on an hourly basis has any chance of being accurate.
I think alternative weather apps like DarkSky were incentivized to provide extra information that justifies their existence regardless of accuracy/precision.
E.g., if I make my own weather app and my selling point is that I give you a forecast for every 10 minutes or that my forecast goes out 5 years, I don't have to have any shred of accuracy because it's just a forecast. I was able to sell you my app because you're impressed by the fact that I give you more granular predictions.
I was the same way. Then I broke down and paid the $5. Best app purchase I ever made. One time fee and used it for years. I wish there were more apps like this.
It’s one of the few apps I bought and it’s frustrating that Apple bought them, picked a few features, killed the rest, and shut everything down.
I’m not even complaining about killing the api, that makes sense since Apple doesn’t care about this.
But Apple Weather’s maps don’t work as well, the precipitation views aren’t as detailed, the user supplied precipitation reports are gone. It just does different things.
But, yes, Apple Weather is now a better app because the acquisition.
Was the easiest way to put some fire under Qualcomm's arse, RF modems, batteries and displays are the only things Apple doesn't have under their direct control - but for batteries and displays they at least have a selection of competing suppliers. With modems, they're stuck at whatever crap Qualcomm delivers.
Waiting for the shoe to drop on that Mint Mobile acquisition though...
When a company is deemed a good investment it's invested into by financiers, actual companies often buy other companies for other means than developing them further.
LinkedIn is better than ever for finding a job, or advertising a job, even though lots of people here don't like it because of the LinkedIn poasting culture.
Is so much worse under Microsoft. As a parent, it’s funny how much Microsoft hate is in the house because the Minecraft fuckery. They made new versions, migrated accounts, added micro purchases, made mods harder.
My 5-year-old had a Mojang account and could download and install Minecraft. Migrating to a Microsoft account was very hard and took multiple attempts and my direct help. And for some reasons “sucks.”
Solution like SnowFlake for logs / telemetry where compute and storage are separated might be the future.
- panther siem (python alerts, thank the lord) and then pandas + databricks + s3 data lakes for deep analysis and IR
- maybe swap in panther SIEM for XDRs, if they get better out of the box
Decoupling compute and storage is definitely the way to go. We’re using Lambda functions and ECS Fargate containers for compute that scales up and down rapidly, and S3 for storage. Getting ~1TB/sec log scan speeds, which feels fairly good. We keep sparse indices in S3 to narrow down regions of logs to scan. Eg. if you’re searching for an IP address that appears 10 times in a 25TB log set, the indices reduce the search space to around 300MB. Takes a few seconds to complete that query, whereas Athena and CloudWatch take like 20 minutes.
We’re also using Rust to maximize memory efficiency and speed - there are lots of great SIMD optimized string search and regex libraries on crates.io.
We’re early, so there are a lot of SIEM features like detection rules that we are still building. But Splunk/DataDog users might find it useful if costs are a problem and they use mostly log search:
I feel like we should be talking about the sad state of logging where we think it’s perfectly ok to dump millions of 10k stack trace dumps and think that should be cheap.
It worked out to be something like 20x to 30x cheaper than any of the cloud solutions such as Splunk or Azure Log Analytics.
"RansomWare"
My leading example is SAP. Actually, most of the big ERP packages are ransomware.
SAP - getting off of their ERP systems is an absolute nightmare and they know/exploit that fact.
Salesforce - CRM systems, in general, can lead to lock-in due to the sheer amount of data and customization they host. In recent years Salesforce has started to leverage this fact to grow revenue without adding value.
Unity - they're getting aggressive in trying to extract more money from their existing customers and I'm not referring to the recent license changes. Nightmare company that you should avoid working with on enterprise software at all costs.
Blackboard - within the education section their LMS is challenging to migrate off of and they will bend you over backwards because they know it.
ServiceNow - they've seemingly given up on making a better product and have invested all their efforts in extracting more money out of their current customers.
PagerDuty - whose sales rep who told me straight up that they didn't need to negotiate with us because it would be too difficult to switch away from their product.
For specific product lines IBM, Cisco, and VMware also do this but I don't think it would be fair to characterize that as their overriding business strategy like the above.
Personally I hate those "give me more free info" responses. Do your own homework.
Also, from a business perspective, Cisco basically removed a competitor from the field.
I've used several Splunk competitors (Sumo Logic, Datadog, etc.) that all have various strengths but suffer from a lesser version of Splunk's problem (once you're locked in and up for renewal, watch out). I also tried some ELK-based stuff, which just plain sucked.
The one thing that hasn't sucked is AWS CloudWatch Logs, after they added Insights (a log query engine). It has reasonable pricing and works really well if you're on AWS.
For some applications, it also makes sense to use the built in Logs API that exports logs to S3 (the export process is very fast) then use any of a variety of tools geared toward searching through data on S3.
I know a splunk employee (splunker?); hopefully she somehow gets rich(er) as part of this deal.
Also, is it under the hood some Apache SOLR or ES? Or they have their own?
For a lot of non-megacap companies, while observability is nice.. it might not meet the ROI hurdle in a high rate / low growth environment.
That is - its hard to reconcile sending $$ Millions out the door to Datadog, Splunk, Pagerduty while you are trying to cut budgets elsewhere.
Some of the disclosures by companies of what they've been spending on SaaS are pretty eye popping.
I hope it will help some smaller teams/companies cope in this high rate / low growth environment. :=)
Like snort, but looks at system calls.
Are acquisitions often followed by layoffs?
In my head, layoffs tend to happen BEFORE acquisitions.
Disclaimer: I work at Cisco (Webex)
0 - See MARS, https://en.wikipedia.org/wiki/Cisco_Security_Monitoring%2C_A...
1 - A few examples: before WebEx, Cisco had MeetingPlace which was partially internally developed and partially built with external hardware and software products. Before Firepower Threat Defense (Snort acquisition,) there was the internally built ASA product line, which developed from the acquired PIX line. In load balancers, they had ACE (internally developed,) replacing CSS/CSM (based off of their Arrowpoint acquisition.) For NAC, they had NAC framework (internally developed, never really took off,) NAC appliance (acquired,) and now ISE (internally developed.) There are many, many, other examples here.
Cisco: Oh these guys are just like us. Better buy them up. We know this business.
Amen :)
https://www.reuters.com/technology/cisco-made-20-billion-plu...
What's fascinating is that working inside Cisco, the same tricks work on them. We'd adopt a vendor only to realize it doesn't do what we want, but now we're kinda stuck on them and it costs more to replace them. It's a bog-standard giant enterprise where the left hand doesn't know what the right hand is doing. But they're wizards with cash.
Anyway tl;dr their lead engineer flew out and helped us get everything up and running. :-D
People buy $20 socks with a $300 suit because $20 seems inconsequential compared to the suit.
What's $90/mo compared to $50M to acquire them :-P
https://siliconangle.com/2023/08/23/splunk-shares-surge-stro...
But it's more useful - though still not the full story at all of course - as a finger on the pulse of the people who actually implement software products, rather than their business models and their sales and marketing.
This is not intended to downplay the importance of any of those things! Those people are just not the majority of the audience here. (I honestly wish I knew where they hang out, but I'm not sure there is such a place - all the people I know in those roles just play their cards much closer to their chests than those of us who participate here.)
As far as the business types, why do you think they'd be here? The community chants grift, scam, and enshittification at pretty much any change in the customer contract these days. Is that the kind of environment that someone on the business side will find welcoming?
But having said that, your comment (and the thread-starter) is a pretty good example of "getting a pulse"! A pulse isn't just "the average viewpoint", it also includes the distribution. And for every bit of conventional HN wisdom like "splunk sucks and is too expensive", there is pretty much always a comment like "splunk is pretty successful, actually". Your "I've been around a long time and attitudes toward SaaSes are actually pretty positive or at least calculating" is part of the "pulse" in this thread.
To wit: I honestly had no idea about splunk. I played with it in the distant past and thought "cool!", but I've never used it in the auspices of an enterprise license, and I've certainly never tried to purchase one myself, so I just didn't know anything about this. And if you had asked me about their recent earnings, I would have similarly had no clue. I just had no idea what the "pulse" on splunk was, either way. And now, because of the zeitgeisty comments making fun of how expensive it is, and also the comments like yours and the thread-starter's pushing back on that narrative, I have an updated prior on the splunk. It surely isn't the full story, and I wouldn't walk into a conversation and be all "I'm an expert on splunk, folks!", but I have a much better sense than I did a few hours ago. That's what I mean by "pulse".
> As far as the business types, why do you think they'd be here?
I didn't say I think they'd be here... I'm the one who pointed out that they aren't! Honestly not sure how you read into my comment what you seem to have read into it. But I'm glad I gave you an opportunity to rant a bit!
HN is mostly a place where technologists gather, not corporate heads of IT or other business people. This is especially true of the subset of users who actively participate rather than only reading.
And it is not unusual in the least for an enterprise product to be wildly profitable but not admired by technologists. Indeed, it's the default; Oracle, SAP, Microsoft, etc.
What is interesting is to look for examples of things that break this mold, that are both profitable and mostly admired. Frankly, I can't think of any... All the ones I can think of were out-competed and either acquired and ruined or just run out of business. Maybe RedHat is the closest example... I'm not sure though.
But I don't think there's really a great place to get a zeitgeist of the rest of the population. I think they're mostly doing other stuff rather than talking about technology on internet forums. (They're smarter than us.)
AWS?
But yeah, this does seem right for the "core" services; ec2, s3, maybe lambda, etc.
It was like that from the beginning. That's why there's much less animosity towards AWS, because they just allow you to run your X without the overhead of infra investment.
The "take a popular OSS system and provide it as a service" thing is a complement to that business model, because they can say "now that you're using our infrastructure, you can also use all these services, and we'll manage it for you, and you'll only have a single vendor to pay". It provides additional value and lock-in to the business model, but isn't the essential part of it.
And no, that isn't where it began. Providing managed services for open source systems was not a part of their initial value proposition. When I started using EC2 (with EBS and S3), one of the tricky things was getting our own database infrastructure to work reliably on EC2.
It's true that RDS was released not long after, and did the "take a popular OSS system" thing, but they really didn't embrace that model until years later. Indeed, I think RDS still seems like second fiddle to their proprietary non-relational DB service.
none of these are currently profitable
What's interesting is things that break this mold, like Microsoft Teams, because that's something that can be disrupted, and thus be successful, by having a better product.
Although "enterprise chat" is also entirely owned by unloved corporate products now.
The tool itself when I started using it was brilliant and quite deep on capabilities.
All that said, the cost structure for the product can and SHOULD scare away any SMBs. Hosted or cloud, you're probably paying way beyond the value it's bringing in. That's probably the single largest determinant to the product.
https://lantern.splunk.com/Splunk_Platform/Splunk_Cloud_Plat...
I put it in a cronjob and it's infinitely better (at least for my purposes) than Splunk, which is just a total nightmare to use, and can be customized super easily and quickly. My coworkers all prefer it to Splunk as well. And oh yeah, it's totally free instead of costing my company thousands of dollars a year! If I owned CSCO stock I would sell it-- this deal shows incredibly bad judgment.
Large enterprises can generate hundreds of terabytes to petabytes every day. Splunk has all sorts of issues, but to pretend as if you can replace them in any large shop with a 1200 line python script and SQLite is just being disingenuous. This acquisition falls right into Cisco's sweet spot, they aren't chasing shops that can dump all their security and infrastructure logging into a SQLite database and not have it tip over in an hour.
I think “expensive” here is basically relative to revenue/margin. Where margins are high, spending on Splunk (etc.) isn’t meaningful. Where margins are thin, it hurts.
Basically, the arguments here seem to reflect the markets and business model folks are working under. Some pay, some can’t and some won’t - all valid.
Right tool for the right job. Splunk is for mega-scale setups
I guess you'd appreciate the words easily and bit are doing a lot of heavy lifting there.
This goes with the previous comment:
> And oh yeah, it's totally free instead of costing my company thousands of dollars a year
Unless you work for free, then something you make and maintain is not "totally free".
I havent developed it yet. But my Splunk killer solutions actually scales so big we can use it to walk to the center of the universe. And its only 1 line of Rust and a bash script that runs when ever the Unix clock has 420 in the number string.
By which time you can just suck the damn log file and grep it on the box.
> It appears that if you are paying them millions, it scales fine
yes, if you pay someone for product and services, you get them. If you don't, you don't
I was getting 2-4 calls a week.
It was so fucking annoying and expensive ($1.2M spend each cycle) we shitcanned the entire platform.
First thing they hear of this is when our ingress rate drops to zero and they phone us up to ask what is happening. Then we don't go to the numerous catch up and renewal meetings and calls. Then we stop answering the phone.
I think there's not much of a useful "flat rate" tier; you pay based on usage. People can accidentally spin up a ton of EC2 instances and get a huge surprise AWS bill, too. And yeah our logging needs are high and monotonically increasing but they're also relatively predictable at our scale.
It ALSO turns out though that Splunk is really really good at their job and matching their expertise would require tons of engineering effort and it's not like the disk space alone is THAT cheap if you want it to be searchable.
> useful metadata like the IP address of the instance, the machine name, the log source, the datetime,
This should be tagged on every single log line already, and not something that you should be doing post-ingestion
My point is more that a large portion of Splunk customers could do the same thing I did and be way better off. Obviously not their huge enterprise customers spending millions a year.
While it doesn't compete with Splunk, IMHO, it's much easier and much better than what 1,200 lines of Python could conjure up. Dashboarding and all. I love it and use it in a very large enterprise environment.
…but this sounds so much like the legendary Dropbox release thread’s ”just use FTP, SVN, etc” that it made me smile :)
When you have a hugely complex, made by committee, enterprise-grade generic system/protocol like opentelemetry that does anything and everything, at any scale, it's always going to have huge amount of excess complexity when you are trying to do a specific simple thing well and quickly. It would be harder to figure out the config files for that stuff than it was to just make my own system.
That's from a friend of mine in a tech chat.
In other words, what if there were no log files?
Intended as a thought experiment.