3 ms·
I think it's a space that's largely overengineered when classic solutions tend to work very well and are FOSS. On the log side, rsyslog, systemd-journal-remote,
by arminiusreturns 2y ago
I think it's a space that's largely overengineered when classic solutions tend to work very well and are FOSS. On the log side, rsyslog, systemd-journal-remote, etc are being overlooked in favor of the behemoths like Splunk, and I think the real opportunity is in reducing the SIEM stack complexity by returning to simple tools that do their job well (unix philosophy).
The problem is then VC's and their companies are trying to monetize in their style, which almost always means using massive funds to dominate a market space and then hold on to that. Serving the customer need has almost become secondary to growth for these types.
What I see in this article is more stuff about the next Splunk, but what I want is an analysis of why people even need splunk (often they don't), and how that means the real opportunity is in returning to basics.
- bsder 2y agoIt's overengineered because if you just need "logging" and "insights" you have lots of open source options. If, however, you need "logging that an executive will put their signature to" suddenly you have very few options.
- deleted 2y ago[deleted]