https://realmoney.thestreet.com/investing/technology/cisco-r...
Good luck Splunk folks - Cisco isn't exactly known for their software innovation in the upper stacks (they still do pretty incredible things at the network OS layer).
https://realmoney.thestreet.com/investing/technology/cisco-r...
Good luck Splunk folks - Cisco isn't exactly known for their software innovation in the upper stacks (they still do pretty incredible things at the network OS layer).
It is certainly no secret that Cisco wanted to buy Splunk for $20BN in Februart 2022
2. Don’t do it by buying short-dated out-of-the-money call options on merger targets [0]
[0]: lawsofinsidertrading.com
IMO though it could easily be just some WSB bro that gambled and got lucky. Robinhood and other platforms make it easy to trade short dated options these days and people love to gamble on them.
100%
It's possible someone was selling contracts as a hedge since the tech market has been really bad this week. A market maker was obligated to buy the contracts.
The person selling the contracts gets $22k in premium, and misses out on the pop. The market maker will absolutely exercise the contracts and profit.
(This is coming from someone who sold APPL calls expiring tomorrow for .08 at a high strike today)
Personal opinion: It's insider trading. You'd need a ton of shares to be able to sell $22k worth of contracts at a high strike unless you're doing naked options selling.
In terms of how the market maker is involved:
https://www.projectfinance.com/options-market-maker/
hedging:
Selling options, on the other hand...
Either way, it's a bad deal for both Splunk employees and their customers. SIEM is a space that is hard to be a leader in when you're not vendor agnostic. This is basically what XDR has become: vendors who have EDR/NDR/whatever are claiming to have some unique (it's not) data lake that can ingest any source, when in reality all of these solutions suck at everything outside of their own product set. I've worked with countless clients over the last year who, as an example, made the mistake of thinking Microsoft Sentinel was a cost effective tool, only to realize that once you're outside of the Microsoft ecosystem analytics/detections quality becomes very close to zero in terms of quality and the price is not cost effective. But SIEM has always had a flair of vendor lock in to it anyway. It's a hard platform to move from once time has been invested in wrangling all the data sources for ingest, transforming them to some bespoke schema and then all of the detection engineering on top of that. It's almost as bad as large scale firewall migrations.
What a lot of folks don't know is that when Splunk decided to move to a Cloud/SaaS model they literally just lifted and shifted the unoptimized bits of on-prem Splunk to a managed VPC under the direction of then-CTO Tim Tully. Splunk was losing money on every deal due to the infra outcosting the insanely high quotes Splunk was churning out. This is a great case study on Innovators Dilemma as Splunk drug their feet for years internally saying that cloud would never impact them. And then they realized they were far behind the 8-ball and decided to hemorrhage cash so as to not churn customers. They eventually optimized it, but the underpinnings still aren't what a fresh take on the bits would have looked like had Splunk done the "right" thing.
Cisco will continue to play ELA games with customers just like VMware. For those who don't know both companies like to get customers into ELAs. Why? Because those contracts basically state that said customer will buy X number of new products annually or risk losing some, or all, of their currently negotiated discount. For smaller orgs this works less well, but you'd be amazed at how those smaller are easily manipulated by snake oil sales folks. For large orgs this puts them in a bind. I've even seen shady contracts written (from Splunk) that had language wherein if the customer does not renegotiate or cancel a, let's say, 3 year contract in writing 90 days before it's going to expire that the contract will autorenew at a ridiculous percentage increase in cost.
Move away from these enterprise product sets where and when you can. These companies are focused on the bottom line - and that is profit, not the customer. The industry has it all backwards, and it's working for them... Still.
This was insider trading.
Or let’s say I was short the stock and wanted to hedge during a volatile FOMC period.
Scalping your gamma?
Feels like the stock market is just a bunch of jargon, subterfuge and financial sleight of hand. Like we learned nothing from 2008, and just created financial 'products' mechanisms and gambits out of thin air.
Stock shorting has got to be one of the most pants-on-head stupid things I've ever heard.
Well, next to gamma scalping.
Here, what they're doing is establishing a position which will make money if the stock moves either direction out of a narrow band. If you believe there's going to be a big industry upset, but don't know whether it will hurt or harm a specific player, you might enter this position. In turn, the overall market volatility is reduced and liquidity is added by your information being added to the market.
> Stock shorting has got to be one of the most pants-on-head stupid things I've ever heard.
All kinds of simple, legitimate reasons to short stocks. E.g. you are excessively exposed to that company's welfare for some reason (stock options, they're an important vendor, they're a big component in a mutual fund you own but you'd rather not own their stock, etc)-- you can take an opposite position by shorting. Or, here, you can use it to offset an option that moves in the opposite direction.
> Like we learned nothing from 2008, and just created financial 'products' mechanisms and gambits out of thin air.
This isn't too much like the house of cards from 2008. These types of strategies are not new; offsetting short positions by writing or buying options was in frequent use in the 1970s, if not before. Option use to profit from volatility (or hedge volatility) dates back more than 2000 years.
I'm not a big fan of esoteric, complicated financial schemes, or in creating options and financialized products for everything (e.g. cap and trade)... or situations where market players profit from privileged access to marketplaces (e.g. HFT). But the things you name are not any of these.
This is literally every industry. Do you think the average trader can understand the majority of discussions on HN w/o any domain experience? The jargon exists for a reason.
> Like we learned nothing from 2008, and just created financial 'products' mechanisms and gambits out of thin air.
The financial engineering issues in 2008 were fueled by other issues: simply we had the government suppressing true borrowing costs and fueling a housing bubble under socially progressive cover. These moves almost universally end in disaster historically. The "out of thin air" products I presume you're referring to all had/have legitimate use-cases: the problem is that nobody bothered to do proper risk management because the US Government was fanning the flames in one direction.
> Stock shorting has got to be one of the most pants-on-head stupid things I've ever heard.
That's probably because you don't understand the positive aspects. Shorting is absolutely critical to well functioning and efficient markets. It's not simply evil hedge funds betting against businesses or whatever trope you might have heard.
In fact, if housing was an easily shortable asset class, the above crisis you mention would have been far less severe (or possibly not happened at all) as short selling pressure would have kept prices at more reasonable levels.
What are your thoughts on insurance? Because shorting can be an insurance/hedge against price changes.
In the above, I’ve just realized a small profit by trading the underlying and a small bit of theta burn. As long as the former is greater than the latter (as long as realized vol > implied vol) I make money.
Rinse and repeat this process over and over again.
The only way the buyer could make a profit would be for Splunk to go higher than $127 and if it went significantly higher, they'd stand to make an eye-watering return-on-investment multiple in one day. Which is what happens.
It would be suspicious if this turns out to be a speculative trader making a one-off transaction.
Calls are the right to buy at $127 - the shares received can then be sold at market price.
Puts are the right to sell at $127 - the short position can then be closed by buying at market price.
I spend most of my day managing Meraki networks and some of that is seriously powerful and innovative.
0 - Even switching originally came to Cisco via a whole series of acquisitions in the 90s. You could argue -- and Stanford certainly did -- that routing was an acquisition of sorts, as well.
1 - Their M&A guy even wrote a book about it, called Doing Both, which purported to explain how Cisco achieved so many of their goals by refusing to make false "either/or" decisions. Ironically, almost every example in the book was something that Cisco is spectacularly bad at.
One other thing that I think feeds into these acquisition mishaps is that Cisco has, in my opinion, consistently over-estimated how much intelligence would be needed (or wanted) in the core network. In their view, intelligent network services = expensive network devices = revenue for Cisco. I think what the Internet specifically and IP in general, as well as the evolution of LAN technologies over time have proven is that when it comes to the core network, simple is almost always better and intelligence should move to the edge, where innovation can happen quicker and where services can be implemented in software.
As an example, at one point they had what was, essentially, a middleware system (like Websphere,) which they called Application Oriented Networking. The idea was you would deploy these on your network gear, throughout your network, and it would provide message routing and translation services. They had a whole "architecture" built for it, called Services Oriented Network Architecture[0]. I don't think the people who built it really understood that it provided no real advantage over a cluster of middleware/ESB/MQ servers in a data center and that nobody was going to pay a huge premium to build that capability in their IP routers.
0 - https://www.cisco.com/c/dam/global/it_it/solutions/ent/tecno...
Ironically, those set top makers were in a perfect position to take advantage of it. They could have been Roku - they already had huge market penetration.
The one other rule that John Chambers lived by was "no merger of equals." It was always about a big fish swallowing a smaller one. Cisco's market cap is an order of magnitude greater than Splunk's, but this is as close to breaking that Chambers Rule of Acquisitions as anything they've done to date.
Here's the full history of Cisco acquisitions. Maybe someone with more M&A lore would scorecard it to see which were dreams and which were duds.
https://www.cisco.com/c/en/us/about/corporate-strategy-offic...
I enjoyed Cisco (great 4th July parties!) but it never felt like we were properly integrated.
and they're buying Splunk, so if the concern is continued innovation at the upper levels of the stack...
Not arguing with you, it's genuine curiosity on my part.
In sales we call this "Ideal Customer Profile." Why do I want a customer with less money to spend if I have a product with enough capability for the gigantic money-is-no-object customers?
Consider, for example, that Akamai's revenues are sitting in a plateau over the last 5 years, while Cloudflare is moving up.
That's not how enterprise procurement works, which is what makes the big bucks for companies like Akamai and Splunk.
Cloudflare traditionally targeted mid-market and is in the process of building out an upper market/enterprise motion (I worked with the guy they hired to lead that in a previous role).
I can dig deeper into ICP, Market Segmentation, and Enterprise sales if interested. There is too much FUD on HN
Akamai has certainly done well over their lifetime, but their revenue for the last 5 years is very flat. That's not "FUD".
In this case the big customers are already using it. Splunk's value proposition for those customer is that they can handle with a massive volume without a hiccup. Small customers don't have the needs where Splunk is uniquely useful.
We loved Splunk, we invested quite a bit in it both for technical monitoring and business intelligence. After a while the price went so high we cut it all, moved to kdb/tableau/elk/whatever crappier system that cost less.
Money is ALWAYS an object and Splunk makes sure to dig a hole deep enough for even the deepest pockets. I too prefer my shareholders to collect the fruit of my labor rather than... Splunk. At least they can reinvest some profit in us. Not Splunk, nope, they keep digging that hole in our pockets.
Personally I can't say if that's actually happening with Splunk, but it's a very plausible scenario.
Somehow companies manage to make it work extracting money from your existing money-is-no-object customers. Oracle and IBM have basically zero mind-share amongst HN reading folks, but yet there they are.
We would routinely switch vendors and it would be an fyi to the end users if that.
It’s one of the reasons myself and huge corps don’t mix!
I think once a customer with a big enough budget is recognized by sales at one of these big organizations they make the sale happen. They talk to the higher-ups and either make them happy, or feed them a lot of FUD (or both), and then they're in, regardless of what the people working with the products (many of whom might be external vendors or consultants!) think.
They're basically focused on more traditional sales & marketing instead of more grassroots sales & marketing (mindshare), but at least in my experience they definitely still get new customers.
Microsoft dominated the nineties especially and the naughts less so but still because the marginal price of their OS was zero - due to piracy. Yes they didn't like business to run unlicensed but if you were a customer, nobody cared, because in 5-10-20 years you'd be a paying business or would work for a paying business.
Splunk doesn't get that. There are no hobbyist/prosumer splunk installations. Zero. Nada. That's also how Linux won in the server space - nobody set up Windows servers as a hobby and 20 years later we're here.
IOW it's medium-term short-sightedness, if it makes sense. Tactically good, strategically so-so to bad, depending on your moat and momentum.
Not true. I ran a free (legit!) Splunk instance in my homelab for years. It's been several years since I shut the homelab down, so I couldn't tell you if they still have hobbyist licensing, but they certainly had it in the past.
I know they have a free license for super small deployments but haven’t heard of anyone actually using it.
I think modern solutions would be any of the recent Clickhouse based solutions.
Loki exists but it seems to have a tragically small market share.
For some organizations what Splunk does well is important but for most of them they really only need much more basic log aggregation and analysis tools.
What splunk has going for it now is that they have lot invested in compliance and security but its only matter of time before other providers start offering the same. Only use case i would consider them for is a SIEM. Datadog logging is so cheap and works and gives me more money to spend on other things.
But as you lose the smaller and middle-range customers, you're also missing on the trends of the market, while getting shaken up by the big players you can't afford to say no to. If one of your whales needs feature Y, no matter how exotic you think it could be, you'll have to implement Y, bloating your product for the rest of your clients.
And while you're doing that, smaller competitors slowly creep up, eating up the bottom of you market, until you're stuck in a niche.
So what, milking mega enterprise for ossified products is a decently profitable niche. IBM, SAP, that huge American company powering a lot of hospital IT, Cisco itself...
Epic
There's a few contenders for sure.
Basically every ERP technology every invented.
It was super expensive and what I dubbed a "choice bot"
Where you are basically navigating a decision tree and the text box is extraneous
It is not better at all, by almost any metric other than overhead. Losing 1 of 1000 customers @ $1000 is very different than 1 of 1 customer @ $1M. One is easy to manage, the other leaves you dead in the water. In addition, you'd start to make concessions/unnatural decisions because you're so lopsided in diversity. And you're going to get completely fucked at renewal time. and, and and..
Good M&A teams know this. They build a risk profile when revenue is a component of the acquisition. The acquiring party gets to learn a lot about the fundamentals when putting deals together and it's all factored in.
To put it simply: having a healthy balance of revenue from multiple sources is a premium. Those are opportunities to advance your relationship and grow. Too many eggs in too few baskets are major red flags that will have your revenue working against you.
They'll pick up another 10-20% capex/open/cogs on private pricing that Cisco gets.
Great M&A if Cisco manages to maintain Splunk's customer base. I look at Splunk as the Oracle DB of the world now, does anything a giant enterprise can imagine, but is old and costs a leg & arm.
PagerDuty is significantly better for about the same price and demonstrates ways in which the product could have kept improving.
They care about its capabilities and its on a different level than Datadog, Elastic etc
That’s… a compliment? There have been very few positive interface developments in the last 2 decades for power users. If you want to rip out 95% of the functionality and 99% of the usefulness so morons with iPads can navigate it, then it probably needs adjustments.
OMB Memorandum M-21-31[0], “Improving the Federal Government's Investigative and Remediation Capabilities Related to Cybersecurity Incidents” which includes directives to ensure event logging goes well beyond the current norms.
By all accounts I've heard it's going to enrich the fortunes of every single SIEM/Log aggregation company out there, pretty much every govt contractor is going to need larger licenses in the next few years as contracts get rewritten with this EO in mind.
[0] https://www.fedramp.gov/2023-07-14-fedramp-guidance-for-m-21...
The logs into metrics abilities along with the ability to unlock finding relationships in data is amazing. Mouse over the fields found in logs matching your search and see the top N values for other these keys.
Imagine getting an alert and being able to search your logs for that error message and immediately being able to see it affects these N users disproportionally, that it is split 50/50 in two of your seven regions, only affects version X of your service. A couple more searches to dig in and you can see it is only feature Y with setting Z that is the problem. You switch to a timechart view and can see the moment the error started and the affected user counts. A few more minutes and your support team has a list of known affected users. You decide to monitor this new feature so you quickly create a new dashboard (or panel on an existing dashboard) and a new alert. At no time did you have to declare a field of your structured logs as an index or as searchable or aggregatable.
We used Splunk to associate a change request ticket number all the way through the change control process to the Puppet log output tagging each change to the original business purpose.
It was like magic for auditors back then and I rarely see that depth of tracing automated changes to business purpose in the field today, though we get close with gitops.
With Vector you can even source from Splunk and move elsewhere.
However, AppDynamics and Duo seem to be doing well at Cisco from what I can tell. I think observability and security tools are a good match for Cisco and bundle well with hardware. For this reason, I’ll bet Splunk does reasonably well under Cisco too.