Splunk to cut workforce by 7% after cisco deal
bloomberg.com
bloomberg.com
I was at Kenna Security when Cisco bought them (I was only there for a month too, so Kenna hired me knowing the purchase was going to happen). They lied through their teeth about the process. They promised every resume would be reviewed for leveling, but then gave out the worst offers I've ever seen. They were literally dropping people by multiple levels, and if anyone complained they told them they couldn't make personal exceptions. They wouldn't even listen to people's managers about it, it was just a bunch of anonymous resume reviews.
At the same time Kenna leadership said they'd pay for Cobra for me if I didn't want to stay. The VP of Eng, David La France, at Kenna promised me that to my face. Then once they sale went through he refused to talk to me and told me to cover it myself. Ultimately they did back down, and were "kind" enough to give me a whole two weeks severance. However it made me realize that Cisco views it's acquisitions in the worst way possible, and if I ever work at a company that Cisco purchases I will immediately start looking for a new job.
It's worth noting that I've kept in touch with a lot of the Kenna people who stayed (at least initially), and according to my old manager more than half of the people who stayed on are gone now.
The real lesson to learn here is twofold:
- People recruiting / hiring are incentivized to say whatever is needed to close the deal. With the exception of a bold faced lie (I don't think this was that).
- People at the company being acquired are more often than not going to lose most of their power. Including the C-suite. No one is safe and as an employee/victim you won't know the actual arrangements of the deal until the dust settles.
- People forget and circumstances change. Signed documents don't.
Sorry to hear that happened, that sucks.
M&A can be done without being ethically and morally bankrupt. It's totally possible. Cisco just doesn't think that's a priority.
You can have people running the company change what the company does to be more ethical or moral, but it's like training an elephant to do tricks: an unnatural edge case. Their natural incentives are more like swarms of locusts or jellyfish; the more you feed them, the larger they grow, the bigger impact they have on their environment. No real thoughts, just an urge to consume and expand.
at every level, the incentive is to maximize the profit margins. If acting ethically doesn't increase the profits, then any personal sacrifice on the part of the decision maker to act ethically is only going to get punished (may be not immediately, but certainly some time in the future).
This is wildly oversimplifying. For example, it theoretically rules out principle-agent problems.
No, you can’t. This is the problem of corporate management. Management will tend to act to maximise profit margins or even the stock price is a bad explanatory model.
Over what time frame?
However, if you want tech jobs to have a higher and guaranteed severance, national legislation might be more effective.
After all, many acquisitions and layoffs are at companies that are in dire financial straits, which limits discretionary spending.
There is no reason to over complicate things and require businesses to directly pay, figure out how much cash to always have to be able to pay, hire auditors to make sure they have enough cash, then take them to court when they don’t have enough cash to pay, yadda yadda.
Business sells product or service. Employee sells labor to business. Government takes care of the safety nets.
FWIW, I didn't read parent post as making an excuse, just describing the reality.
In the corporate world, approximately nobody is rewarded for acting ethically, and as such it's a reasonable assumption that corporations will always trend towards unethical behavior (read: any behavior that pushes costs onto some other entity, while bringing profits to the company), because that can be a competitive advantage.
Acknowledging this is a first step in fixing the problem. We need to incentivize companies to do do the "right thing" - where the "right thing" is something other than simply maximizing profits - because we can't rely on "good people making moral choices" when they are incentivized not to do so.
The only way to achieve a change in behavior in corporations is to change the regulatory framework in which they operate.
In the narrow context of the OP, this doesn't even need to be very heavy handed (unlike say environmental devastation, which is a much bigger challenge). One option would be to pass legislation that makes it harder for megacorps like Cisco to eat smaller companies. Another would be to make layoffs relatively more expensive (require better severance, etc) or to limit them during the M&A phase that Splunk is currently in.
What the USSC said was that voluntary associations of people don’t forfeit the rights of the individuals in the association.
Its not unusual for the force cuts to be done via interviews at the new company
Presumably if you trust the organisation enough to pay for the whole thing, you would have a measure of trust in their ability to hire?
I work for a very large corp. As part of a round of layoffs earlier this year, they cut an entire foreign office, to the man. The decision was made from very high up: VPs were informed after it occurred. For some departments, the losses were small. For others, they were crippling: It was a very important group, doing things nobody else did, and which we couldn't cut.
The end result? The VP realized that the cuts had been extremely unwise, and now almost everyone that worked on that group has US visas, and is working from a new office in the US, with American salaries instead of their far, far lower ones. Not a costs savings, not an improvement in capability... just more expensive, and with projects that got delayed for months, as everyone was out for about 6 months.
For US layoffs, the decisions were not made quite that high, but still high enough that people in the know of salaries and performance were extremely confused about who got cut. Some great, cheap people were cut. Some expensive people that are poor performers by any standard remained. But nobody that managed ICs was involved with the decision making.
A large organization either makes very slow decisions, or acts basically blind. Sometimes they really fail, and do both!
No one is looking at individual people or teams.
The message was that they were in control. That they could cut off their nose to prove a point. This layoff event will be their downfall.
I’m considering whether I should ask for my options to immediately vest in the event of a buy out or liquidity event. It’s not that much money or options that the overall company will care. Should I ask for 1 year, or all 4 years, I’m uncertain if it could poison the well. Is this even something they would do?
Acquirers of growing businesses generally want that growth to continue and can "optimize" by hiring less.
Worst case scenario would be employee stock options and RSU grants remaining or becoming worthless, like in the case of a private company that never gains enough traction to exit or exits at a low valuation.
Usually in a public acquisition, shares are purchased at a price premium.
E.g., many Twitter employees got to cash out at a stock price well above the value of the company.
Every employee should see their role as temporary. This isn’t the lifetime employment pension days anymore. I see many opportunities for employees to walk away as a positive.
Good advice in general, but not a hard rule. There are roles where you need to expend a lot of energy learning proprietary stuff (processes, languages, frameworks, business rules). If you're in one of these roles it can give you a ton of leverage, but tread carefully around egos (you could get fired out of spite if you flex too hard, and maybe that's fine, but generally it's lose / lose).
You're right, of course, with just a nit of misinformation here that always bugs me: there are still lots of places that have pensions, just not places the HN demographic considers worthy of working at. I have one from my time at IBM, one from my telco days, and my current employer (financial) has a pretty generous one.
I've also had a company get acquired by private equity. I got nothing for my shares and they shut the team (and the product) down within two years.
My equity got paid out quickly, I have since gotten raises and bonuses, and the only shittiness has been all the mega-corp nonsense (omg the trainings) and worse health insurance.
Cisco is not a nightmare acquirer, that would be Amazon. If AMZN had acquired us I'd have left immediately.
FWIW, I've never be bought by Cisco, but my best friend has been at 3 startups bought by Cisco. He never enjoyed working for Cisco, but always said Cisco was very clear about their process, and it basically worked the same way each time, except when execs at his startup threw monkey wretches into things. YMMV.
Regardless, a dream offer landed before my shares vested, so I made the hard choice to leave empty handed. There did appear to be a lot of turnover before and after the acquisition. Though during M&A that's to be expected IME, so experiences may vary.
The two weeks of severance was actually pretty generous too for your time invested.
Outside of huge FAANG infra, paid observability seems like a "nice to have" rather than a "must have".. the type of thing you cut before you cut engineering staff, and extend your runway.
You can cobble together something worse with FOSS.. And biggest question is - who cares about p99 latencies anyway when your 2 year runway has shrunk to 6 months, ZIRP is over and you are doubtful of your next funding round.
I can't imagine another whale like Coinbase writing a $65M/year check to a Datadog at this point... "Things you only see at the top"
I would not want to be someone attempting to GTM in this space right now unless you are very confident in your value prop and your ability to communicate that your customer absolutely cannot live without your product.
Top passed, winter is coming.
Can confirm; I'm on a team doing this analysis right now. And, frankly, it's a really good idea.
When I started asking questions like "why do we have 4 different proxy technologies solving the same use case", "why are we using an on-prem solution over here and a SaaS over there to do the same thing" and "why are you buying this tool when we have an MSA with one of their competitors that will save us 60% on the licensing", it was enlightening. Occasionally, there was a really good reason ("it has feature X which makes us Y percent more efficient"...ok, that makes sense) but almost always we got something like "I didn't know anyone was using Product D when we purchased Product E".
I dunno if it's going to be 100s of millions in savings, but we're definitely going to see 10s of millions.
Have also seen aggressively playing VARs/reseller off of each other to drive down cost.
Hey now...that's the fun part.
You could ideally work most things with FOSS. Use opentelemtry extensions to a time dries DB of your choice. Use elk or opensearch for logs, osquery for Linux, native cloud monitoring tools that come out of the box, etc.
Problem is it takes a lot of setup and maintenance. It can bite you back in the worst of times - when you’re trying to work an outage and find out alerting is dead because your fluentbit daemon is hung and no logs came through.
Modern APM is completely out of proportion, and most people that use it do absolutely not get enough benefit for paying for those systems. My impression is this is yet another of those Gartner-created hypes that survive as a meme on the high-management minds and don't survive touching the ground.
People want to chase the bright new thing that Gartner is pushing (its always these guys).
Bang on!
Its part of same buzzword bullshittery of Kubernetes/ Cloud native / Micro services / observability and so on. Create an out of proportion tech stack that no one would understand and then one needs these APMs to monitor "p99 latencies" because who the fuck knows now on how incoming http request will get processed.
Look, there's a bunch of bullshit hype, but I think you're being overly reactionary.
Plenty of devs will never touch a profiler (as complex as a cloud based APM simple as jfr), that doesn't mean they don't have use.
Plenty of buzzwords conflated hype and misunderstanding with useful technology
'nosql'-> yeah don't try to do olap on nosql but document databases or kvs are still super useful. It's basically a hashmap with some index what's not to like (also using 'nosql' as a term to differentiate between relational databases and ...non relational is already a misnomer)
'big data'-> stupid hype at the beginning and yeah you can have a functioning product without it but try leading a business without any data to make a decision
'cloud'-> colocated data centers and timesharing have been useful things for decades but man do I love having an API to formalize it rather than calling up the onsite data tech and having a phonecall to do anything (that or a multi day email chain)
'microservices'-> yeah it's intractible if you atomize your app, but splitting application boundaries and defining contracts makes it a lot easier to horizontally scale, and it's cheaper in the end of you do it right. Also functions as a service are great for glue code and infra IMHO.
The longer I get in my career the more I see that wading through the bullshit is needed to know wtf I'm talking about. It's similar to science communications, where the actual researchers will figure out something cool and useful but situational and contextual, and then the zeitgeist completely distorts the findings beyond any measure of recognition
You just don't need a fully featured APM package to do that. People have been doing that for decades, for example by running a script on their server logs.
Timestamp each hop. Do your percentiles on a trailing X day window each morning. Alert on worrying moves in the p99/95/whatever.
Make sure you don't run out of disk/memory/database by like.. alerting when they get to 80/90/whatever %. Amazing footgun to not monitor this simple thing.
Have a process that serves as a reasonable proxy for "busy-ness" / bottlenecks. ie - gateways, Monitor the % CPU over X minute windows. If the CPU stays saturated for N minutes, something is bottlenecking.
Here's another secret - you want to also monitor for the opposite. Have processes that are "workers" of some sort that should always have load during business hours as there is always data flowing through? Monitor that their CPU doesn't fall BELOW some threshold (it means something fell over and they aren't doing work).
None of this has to alert within milliseconds. Simply having it, and it alerting within a few minutes is better than not having it. Some of these things like latency trends can be run nightly, whatever.
That's an interns work for a week or a seniors afternoon.
This is easy on s5s (servers). I'm sure you can do this in k8s or whatever too.
Python and other tools - not so much.
I wouldn't say Gartner created hype. Glowroot has been invaluable to us. Of course we run a massive footprint of 0.5m - 0.75m JVMs.
Yep, those APM packages are for places like yours. Not for most of the uncountable other places they recommend it.
Are you talking to me?
Implementing observability/SIEM yourself has also become a lot more complicated because the domain of things that have to be observed is increasing. There are many organizations now that have things that need to be monitored in several clouds, infrastructures like k8s, and stuff on prem. So you need a vendor that has the tools to collect this data easily and aggregate it.
The startup world and startup whales might be dying now. But there is a giant iceberg of companies that are becoming more hybrid and their systems that used to do things like funnel syslogs and firewall flow logs to a collector are no longer adequate.
Yeah, I imagine insure companies still require this.
Like containers/serverless was supposed to mean "cattle not pets" and it autoscales and autoheals and blah blah blah. And then we break everything into micro services and we need to pay for some SaaS to orchestrate it, and another SaaS to observe/monitor it, and another SaaS to...
Splunk and other observability companies (Datadog has been hiring like crazy on the security side) have been pivoting into becoming a SIEM 2.0 for a couple years now.
Infra budgets now include Security spend, so an entire generation of Infra companies in segments such as Observability/Application Management (Datadog), Data Platform (Databricks, Snowflake), API Management (Imperva, Wallarm, Postman), and DevTooling (Hashicorp) have begun pivoting into the Security segment.
The same thing happened with networking in the 2010s.
It's a 2 birds-1 stone strategy because Splunk can be used by your Platform team as an APM and by your Infosec team as a SIEM. This way you can file 1 PO and use a smaller portion of your budget.
This is was a major reason why Cisco acquired Splunk as their SIEM offering is shit, and there is a massive overlap in customer base.
So you can maybe help a 200 person org save 0.5-1% of their lower paid staff? Is your bill + engineering integration costs going to be less than $200-400k/year?
At some point you're wasting a lot of time/bandwidth on RPC, and/or memory on all the data copies across process boundaries. So its bigger and slower, harder to orchestrate, harder to monitor, and.. I'm sure there's some positives somewhere.
That said, the costs are too high. And in a rising interest rate, declining revenues environment, a lot of services that were previously instrumented are getting de-instrumented or deprecated.
As an example, all the monolith->microservices drama that happened in the past few years is now becoming a questionable engineering direction. Fewer services automatically leads to lesser cloud usage and lesser observability usage.
I don't think it's cut entirely, but when you're looking at your cloud spend, it's got a target painted on it. It doesn't produce revenue on its own, so people will ask a lot of "do we really need X" or "can we lower retention."
The market still does seem big. Datadog is needlessly very expensive and the experience is just ok.
- Company wants to save money, tells team they're cancelling service that costs them $20k/month to observe their production env.
- Dev team starts building small parts they need anyways, chews up significant engineering resources.
- Company now pays more for highly custom solution no one can compete with.
If the company ends up being successful, they'll probably point to all their custom stuff as why. If they end up failing they'll talk about all the boondoggles they went on. This replays so much.
You build the parts that are most urgent as they come up..
Or is that the 10% of after 9-5 free time you're talking about?
They're all effectively surveillance systems with extra steps. The Network itself is always listening.
Sure you could argue that by 2011 Flip was on the way out as phones were taking over, but there was plenty of room to pivot and plenty of good will.
Had a relative whose company was to be bought by Cisco but thankfully Flip debacle destroyed that deal.
It is just that Cisco cut their losses extremely early. There were still 2-5 years left where Flip could have been profitable.
But I will say this:
1. cisco is not a consumer company. they tried with linksys, bailed. tried with scientific atlanta, bailed. no surprise that they bailed on PD.
2. having seen a lot of ASIC acquisitions in my lifetime, which is basically what Pure Digital was - apple knockoff packaging and branding plus an encoder - in my experience tons of startup teams get their first ASIC done, but then totally flub their second (and some of this is the layoff dynamics of how ASIC startups operate on the HW side - unless you immediately start the next chip before finding fit, you have dead weight that you cut). Also, once you show how it's done and have fit, the professionals show up, like Qualcomm, which makes that even harder.
It wouldn't surprise at all if (2) was the culprit.
"T-Mobile is laying off 7% of staff"
"Robinhood Lays Off About 7% of Its Full-Time Employees"
"Sonos lays off 7%"
"Vox Media to lay off 7% of workforce"
"Payments firm PayPal to lay off 7% of its workforce"
"Roomba maker iRobot to lay off about 7% of its workforce"
"GitLab to reduce workforce by 7%"
"Informatica to lay off 7% of its workforce"
It seems like these CEOs are just copying from the same playbook. I wish there was a CEO who was brave enough to ignore the herd mentality, take a look at what the actual needs of the company, and make a bold plan like "fuck it we're doing 8 and a half percent".
So the 7% cuts will continue until someone boldly breaks the mold and standardizes 8% and brands it “the rule of 8s” and preaches it at overpriced executive retreats.
7% equates to laying off one person per group of 14 people. It would be hard to argue that most companies couldn’t get by with 13 people doing the work of 14.
I think you would feel the loss of one person on a team of 10 a lot more.
Only if you fire the people at random. Any bias will change that number.
Us peon employees don't like to hear it, but it's true.
It's getting noticed that Twitter/X reduced it's staff by 80%, and also reduced it's cloud spend by 60% ... and there hasn't been any material change to their business.
Some might argue that Twitter/X has been able to innovate faster as a result.
Now I'm not suggesting that FANG is going to layoff 80% overnight. But I wouldn't be surprised if CFOs gradually over time continue reduce their headcount, or keep headcount flat over the years to come.
https://www.cnn.com/2023/04/12/tech/elon-musk-bbc-interview-...
https://finance.yahoo.com/news/elon-musk-x-worth-less-221637...
The business is worth less half of what Musk paid for it. And that's his estimate of the value.
That's the only reason why Twitter forced him to honor his offer.
So it's a mischaracterization to state the value of Twitter halved while on Elon's watch.
https://www.cnbc.com/2022/07/11/twitter-shares-sink-after-el...
Their revenue has halved. That's pretty material.
I think everyone who is honest accepts that Twitter was massively bloated. By the time Musk made his offer, it was 8x the size it was in 2011 and the product really hadn't changed much in a way that required that kind of increase. But Twitter is an awful experiment because of Musk's clownish handling of just about everything.
Non the less, IMO, the only winners here are the stockholders, Splunk as a business, and many others with the same model of “schema selling” are in a high risks stake in the new erra of AI/LLMs.
If you consider the accelerating world of AI we are living in, and the emergence/trend towards Domain Specific Large Language Models (DS-LLMs) and advancement like MEMgpt, they represent a transformative approach to data analytics. Instead of using a schema-specific model, as seen in tools like Splunk which extract and transform data into a predefined schema, DS-LLMs offer a flexible, continuously trained approach. They not only analyze data but also learn from it in real-time. The “actors”, or bots, leveraging tech like MEMgpt that not only collect but also learn from the vast streams of data are far more capable than those schema models. As these models self-train and trade knowledge, they are poised to provide insights more organically aligned with the data’s inherent structure, rather than a pre-defined schema. This means businesses could potentially gain deeper, more intuitive insights without the confines of structured data models. With the rapid pace of innovation in the AI sector, it’s worth questioning whether traditional, schema-based solutions will be able to keep up with the dynamic learning capabilities of DS-LLMs. I still wonder who got the better deal here.
Wishing the best to all the Splunk employees moving forward.
I am so bitter and jaded when it comes to this entire system.
Absolutely true.
I'm not saying you shouldn't complain about your employer. But the notion that companies are ethically obligated to hold onto workers who aren't necessary, I thought we were way passed that.
In the cold calculus of M&As, 7% sounds like an entirely normal number, IME.
I remember vividly when one of my companies got bought by IBM, and a couple of the younger back-office folks came by to ask me "what do you think?" because I'd been through M&As before. "I think you need to look for another job" was the best I could do, and it was a little disheartening.
Their graph and front end tools were just seamless to use. It was a very well done product.
They're also in the middle of being acquired by Fransisco Partners and TPG. I'm not sure what to expect there... cuts or restructuring would leave me pretty exposed if I moved there in the recent future but it seems like a good place with a bright future... Decisions decisions!
Create a subsidiary? Fine... Buy up all the tadpoles so you don't have to deal with frogs? Noncompetitive...
The chance of a successful IPO is faaaaar less than "bigcorp wants you to go away, so here's some $$"