Splunk (big data) IPO Raises $229.5 million ($1.6 billion valuation)
businessweek.com
businessweek.com
Do they have a viable business or is this just another "inflate and escape" company?
Given that they expect "operating expenses to increase over the next several years as we hire additional personnel, particularly in sales and marketing," I don't know if that is sustainable and thus indicative of any strategic brilliance.
It's enterprise software and they are the market leaders for the whole "unstructured data analysis" segment (which is a real segment, and has real demand)
That makes the business essentially a sales organization with a R&D wing. The CEO "is well known for taking Hyperion from $500M in 2001 to revenues of almost $1B in 2007"[1], so he seems to understand that process well.
Who designs these things? I gave up after two minutes.
In a nutshell, Splunk is valuable because it turns your unstructured untyped data into something much easier to analyze and Business Intelligence (BI) ready. IMHO, the strength of Splunk is two folds. First, it provides a central place to view and mine your logs across hundreds or thousands of machines. This is very useful in many organizations with large scale distributed computing because you don't need to ssh into your database server in one terminal and compare the results in another terminal connecting to your web server, if you could ever figure out which of the 100 database servers you should look at. Second, instead of just greping, it treats each log entry as a list of key-value pairs and provides a simple yet powerful query language for it. On top of that, it gives you a library of visualization components. I was able to build a fully-customized Google Analytics style dashboard for my application in 20 minutes. And I would say that is empowerment, and empowerment is the most valuable value.
And if you are very into technologies, they are a Python house, which is always a plus :)
- No up-front pricing, you need to get a quote
- No screen-shots, you need to see a prepared demo
- Any contact what the company results in assignment of an "account manager", the used-car salesman of the software industry.
- Lots of testimonials from people you've never heard of talking about software you've never heard of using the very same buzzwords found on the website.
The one useful thing it can do is give (say) devs access to logfiles from prod servers that they aren't allowed for whatever reason to log into themselves. But you could do this yourself with a periodic rsync to an internal webserver...
Honestly, your competing with inhouse scripts people spend a few weeks / year maintaining. Which is not to say you can't make a lot of money doing so. Ideally, your saving people significant time writing these scripts, but tossing out buzzwords just alienates your users.
I am not a Splunk developer or serious user of it, but you greatly underestimate the problem space to suggest this class of products address the same problems solved by even a very skilled scripter's scripts.
Competing business idea...?
I have since left working with Splunk directly but I would still advocate its use because it's one of the better commercial (albeit expensive) log management/SIEM products around.
* the largest data source in any enterprise
* increasingly must be stored for long-term analysis ...
* by corporate policy or ...
* by government regulation/demand
Regular open-source tool stacks can't do this without astronomical cost in storage hardware. Various log analysis players have managed to make this data storable and some have done well on the analysis side.Splunk will do well. I hope this boosts acquisition interest in my old company, http://www.sensage.com, another log analysis company.
It's pretty good software, and isn't as trivial as some on this thread seem to think (I've built large Solr implementations too, so I know search reasonably well).
The strong points: good interface, excellent data import, decent search language, decent docs & community, good APIs, a good set of mostly decent drop in applications that run on top of it.
The weaknesses: While indexeing is Map/Reduced based and scales fairly well, querying is single threaded. That limits it to the performance of a single CPU core + IO limitations. This also applies to things like sub-queries: in a database they could be run separatly, but in Splunk they aren't.
It is also fairly expensive at large scale, although the licening model is fair (it is licensed by data volume, so you can install it on as many machines as you like and share the license between them).
Nevertheless, I believe that there are opportunities for query multithreading that aren't being taken.
For example, a query like this appends the second query results to the first, and the graphs both:
sourcetype="blah" | search blahblah | eval series="label1" | append maxtime=600 [search anotherlongsearch | eval series="label2" ] | timechart count(somefield) by series
There is no reason why that second search couldn't be executed simultaneously, and that would approximately half the time for the whole query to run (assuming sufficient CPU power etc).
We at Pattern Insight are currently working on the next generation of logging software, called Log Insight. If you are a Splunk customer or thinking of buying them, take a look at at our product page [http://patterninsight.com/products/log-insight/] for information on a more sophisticated and complete solution.
Don't hesitate to contact me if you are on the job market and want to work on interesting data-mining problems (full-time only please).
I'm not sure in this case (I know lots of people at Splunk, Adammark/sensage, and other SIEM companies, and IMO they're all useful in some cases, and too expensive for a lot of cases).
[1] http://www.sec.gov/Archives/edgar/data/1353283/0001047469120...
" Upon at least ten (10) days prior written notice, Splunk may audit your use” …. ” Any such audit will be conducted during regular business hours at your facilities“ … “You will provide Splunk with access to the relevant records and facilities“ "
More or less they screw their customers.
The only clause I see worth objecting to is the bit that forbids publishing benchmarks or reviews. That part's BS, but I imagine that it's BS that they would drop rather than lose a sale.
There are Splunk customers who do not allow outbound connections to the Internet and so Splunk can't use automated means of auditing license compliance. So they reserve the right to audit you on site. So if you're the CIA and you are paying for 1 petabyte and you are using 2, they want to know and charge you appropriately.
As a matter of good corporate governance, they are actually doing you a favor and preventing you from being a thief. :-)
Fortunately, customers of Splunk don't view them as a random supplier.
I can't be the only one that finds it very disquieting that you have to give a company access to your internal network so they can perform antipiracy checks.