The reason why them _trying_ to get off it is because they have a bunch of stuff that is easy and works in splunk, but don't want to pay the exorbitant licensing, or pay even more to increase their use.
But getting off a good product is hard, and they will continue to use it and even pay.
The kind of thing Cisco, Oracle, and IBM love are companies with very expensive products in which no development needs to happen and customers cannot move away easily.
I was in one of these meetings with like 20 engineers on how amazing this thing was. We knew that because we already used it it quite extensively. The very extremely hyper sales rep kept ducking out of the meeting every 5 mins. I recognized it for what it was. He was ducking out to do bumps of coke so he could be more pumped to sell us more stuff.
https://www.theregister.com/2020/08/12/splunk_sales_discrimi...
So for 5 years time we used it for observability, we were only half-integrated and also trying to get off of it. Great stuff.
a lot of paralysis on the app dev side as the status quo is easier than fighting for a sensible outcome
its also something that yes, benefits stakeholders... but only on a 2nd/3rd order effect of outage avoidance & remediation.. so theres not a huge reward for doing it really really well in many shops
Cisco has the luxury of bundle and save that Splunk does not.
I can see them shipping a really cool-looking whitepaper detailing FTD, Amp, and Splunk... but actually operating it will feel similar to driving a 20 yr old salt state jeep wrangler on the autobahn.
Using fortigates now, far happier with them.
But it's not just the firewall level, they were so bad it made us reevaluate our core switches and I don't think we've bought a cisco switch for at least 2 years.
We moved vendors a few time and it wasn’t that painful.
Fact: I'm not going to hear my phone ping in the middle of the night. I'm much more likely to hear my phone ring.
That said, every other product in this space is crap. I'm not sure why though. This seems like a pretty good market for disruption. Maybe there is some hidden "problem" that I don't know about.
I am nervous about how clickhouse is going to monetize, whenever they decide to turn on the revenue spigot.
And since clickhouse is open source, we hope that people will stop giving their security data to vendors who then charge you rent for it. I think the future is writing this data to clickhouse, but also our customer's clickhouses
Makes it attractive for enterprises already on their platform and they throw in discounts for E5 license tier customers as well (gotta keep pushing the “give us everything or pay way more for single feature licenses”).
https://panther.com - Built on top of Snowflake, so it scales well and they are building a more Splunk like interface.
https://runreveal.com - Still seed but shows a lot of promise
https://matando.dev - Still seed and don't have a hosted product yet but smart founders that have the right idea
https://hunters.ai - More threat hunting than SIEM but maybe that what certain folks need
https://gem.security - Still fairly early but if you are focused on cloud use cases this could be more of an option. (Disclaimer: I'm an Investor)
So was it you then with that one day call options trade? /s
We are still in early access but you can browse through our docs or swing by our Discord.
They want so hard to be a software company, and they already have experience with highly inflated priced products.
Their real target is probably trying to offer this built in to meraki like products as a one stop shop. I could see them finally burning their monitoring product in a fire and replacing it with splunk and grafana then selling it as an all cloud solution. At least the intent, we know Cisco's track record for integrating acquisitions.