CISCO ACQUIRES SPLUNK, BUT HOW DO YOU CONVINCE SPLUNK CUSTOMERS THAT CISCO HAS ADVANTAGES News
02.11.2023
Cisco acquires Splunk, but how do you convince Splunk customers that Cisco has advantages
01.11.2023
CrowdStrike provides 100% coverage according to the MITRE Engenuity ATT&CK® Evaluations: round 5
31.10.2023
Top 20 Shocking Data Breach Statistics for 2023
06.09.2023
Adversaries Can “Log In with Microsoft” through the nOAuth Azure Active Directory Vulnerability
06.09.2023
iIT Distribution is the official distributor of LogRhythm!
31.08.2023
Instant replication with NAKIVO Backup & Replication v10.10 Beta
03.08.2023
Effective communication: Email vs. Instant Messaging?
25.07.2023
Infinidat Expands Support for Hybrid Cloud Storage Deployments with InfuzeOS Cloud Edition
14.07.2023
Falcon Insight for ChromeOS: The Industry’s First Native XDR Offering for ChromeOS
03.06.2023
Opening new horizons: iIT Distribution is the official distributor of Gatewatcher
13.05.2023
Another revolution in cybersecurity from CrowdStrike: top 5 important things to know about Managed XDR (MXDR)
09.05.2023
GTB Technologies is the best solution in the DLP industry
04.04.2023
CrowdStrike Falcon Platform Detects and Prevents Active Intrusion Campaign Targeting 3CXDesktopApp Customers
24.03.2023
Labyrinth Deception Platform v2.0.51: Release notes
23.03.2023
SIEM vs Log Management Systems: What you need to know before choosing
15.03.2023
CrowdStrike Falcon Named the Winner of the 2022 AV-TEST Award for Best MacOS Security Product
10.03.2023
CrowdStrike 2023 Global Threat Report: Resilient Businesses Fight Relentless Adversaries
10.03.2023
Threema Work App Update: Encrypted Group Calls Are Now Available on Android Devices
28.02.2023
CrowdStrike Ranked #1 in the IDC Worldwide Endpoint Security Market Shares Report for Third Time in a Row
21.02.2023
Picus Red Report 2023: The Top 10 Most Prevalent MITRE ATT&CK Techniques Used by Attackers
14.02.2023
On leadership in the sphere of high-end unified storage: An exclusive interview with Phil Bullinger, CEO of Infinidat
11.02.2023
Securing PostgreSQL from Cryptojacking Campaigns in Kubernetes
30.01.2023
What's New in NAKIVO Backup & Replication v10.8: Release Overview
16.01.2023
Success Story: Georgian Bank Achieves 100% Backup Success Rate with NAKIVO
12.01.2023
CrowdStrike Named a Leader in Frost & Sullivan’s 2022 Frost Radar for Cyber Threat Intelligence
12.12.2022
DDoS Attack Prevention and DDoS Protection Best Practices
21.11.2022
How Hackers Can Bypass Multi-Factor Authentication
08.11.2022
CrowdStrike Achieves Red Hat OpenShift Certification: Streamlining Visibility and Automating Protection for OpenShift
03.11.2022
Infinidat Recognized as a Leader in Gartner Magic Quadrant for Primary Storage – 5th Year in a Row
19.10.2022
New version of NetBrain Release 11: the key to reducing the cost of NetOps
13.10.2022
With security revenue surging, CrowdStrike wants to be a broader enterprise IT player
05.10.2022
CrowdStrike Announced the Acquisition of Reposify to Bolster Visibility and Reduce Risk Exposure of External Assets
22.09.2022
Kubernetes против Docker: в чем между ними разница?
16.09.2022
Infinidat расширяет функции NVMe/TCP для сред VMware
15.09.2022
Новые возможности InfiniBox от Infinidat: vVols репликация для VMware сред
02.09.2022
Индикаторы атак на основе искусственного интеллекта позволяют максимально быстро прогнозировать и останавливать угрозы
03.08.2022
Истории с Dark Web: Отслеживание подпольной экономики eCrime улучшает эффективность киберзащиты
22.07.2022
Развитие ботнетов и DDoS-атак
15.07.2022
Lookout обнаружила шпионское ПО для Android, развернутое в Казахстане
11.07.2022
Выявление и смягчение атак NTLM-ретрансляции, нацеленных на контроллеры домена Microsoft
20.06.2022
Что такое демократизация данных?
07.06.2022
Неизменные резервные копии: что вам нужно знать, чтобы защитить свои данные
22.05.2022
Украинские Киберактивисты Использовали Скомпрометированные Docker Honeypots Для Антироссийских Dos-Атак
06.05.2022
ЧТО НОВОГО В LABYRINTH DECEPTION PLATFORM: РЕЛИЗ 2.0.32
22.04.2022
PALO ALTO NETWORKS проинформировала об уязвимостях, которые могут разрешить злоумышленникам отключить платформу CORTEX XDR
15.04.2022
INSPUR ВТОРОЙ ГОД ПОДРЯД СТАНОВИТСЯ ОБРАЗЦОВЫМ ПОСТАВЩИКОМ CLOUD-OPTIMIZED ОБОРУДОВАНИЯ ПО ВЕРСИИ GARTNER HYPE CYCLE
08.10.2020
Intelligent IT Distribution взяла участь у Третьому щорічному Міжнародному Форумі «Кібербезпека - Захистимо Бізнес, Захистимо Держава»
29.09.2020
iITD - партнер форуму “Кібербезпека - захистимо бізнес, захистимо державу” 2020
24.09.2020
Компанія IIT Distribution отримала статус дистриб’ютора рішень NetBrain Technologies на території України
28.08.2020
Fal.Con 2020 від CrowdStrike
25.08.2020
Дотримання норм страхування кіберризиків
25.08.2020
Автоматично блокуйте скомпрометовані облікові записи з Lepide Active Directory Self Service 20.1
25.08.2020
Компанія Cossack Labs запрошує відвідати NoNameCon
22.07.2020
Підписання дистриб’юторської угоди з компанією Safe-T
21.07.2020
Міжнародна конференція: "Online Banking - Час інновацій!"
18.06.2020
Глобальний звіт про кіберзагрози 2020
11.06.2020
Четвер, 25 червня 2020 року. Не пропустіть!
05.05.2020
Анонс: нова версія Acra Enterprise забезпечує підвищену гнучкість для високонавантажених систем
13.04.2020
Lepide Remote Worker Monitoring Pack - легка платформа безпеки, яка гарантує негайний захист даних бізнесу протягом непередбаченого періоду віддаленої роботи.
12.04.2020
Забезпечення кібербезпеки для віддалених користувачів
08.04.2020
Labyrinth Technologies пропонує скористатися спеціальною пропозицією - ліцензія на 12 місяців за ціною 6 місяців.
07.04.2020
«CrowdStrike: дистанційна робота та ІТ-безпеку за часів кризи - скорочена ліцензійна програма на 3-6 місяців».
23.03.2020
Компанія iIT Distribution отримала статус дистриб’ютора рішень RedSeal Networks на території України.
23.03.2020
Компанія iIT Distribution отримала статус дистриб’ютора рішень Lepide на території України.
16.03.2020
Компанія iIT Distribution починає дистрибуцію рішень CrowdStrike на території України.
19.02.2020
20 лютого у Києві відбудеться щорічна конференція CISO DX DAY 2020
18.02.2020
Компанія iIT Distribution отримала статус дистриб’ютора рішень Instana на території України.
17.02.2020
Exabeam Security Intelligence Platform допомагає
On September 21, Cisco announced its intention to buy Splunk for $28 billion in cash, its largest acquisition ever and fourth this year. This is a massive investment and win for Cisco from two perspectives: observability and security. Cisco’s full-stack observability platform could catapult into relevance against established competitors overnight. Similarly, on the security side, Cisco gains the leading security analytics platform on the market today with an incredibly loyal customer base.
Cisco also gets an added benefit from the Splunk acquisition by way of a recent addition to Splunk’s leadership team that may highlight its plans for generative AI. The acquisition brings with it talent, including Min Wang, Splunk’s chief technology officer. Appointed CTO of Splunk in June of this year, Min has been in technology R&D for 20 years and spent more than five years at Google leading a team responsible for the AI-driven Google Assistant. She is establishing the generative AI capabilities at Splunk to go beyond domain use cases and be open and extensible.
Read about the dynamics for security and observability with the Splunk acquisition below.
Splunk Is Good For Cisco, But Splunk Security Customers Are Wary
Splunk is one of the most ubiquitous and most frequently used security tools in enterprises today. The platform has consistently been named a Leader in the Forrester Wave™ for its flexibility and vast capabilities for alerting and compliance. Splunk also has an incredibly loyal set of users, which, more than anything else, serves as a fanbase for the brand. Security leaders struggle, however, with Splunk’s lack of innovation over the past several years and how costly the offering can become. Even the addition of alternative pricing models has done little to change that.
These factors add up to this acquisition being a massive win for Cisco’s security business. Most XDR vendors have shifted to having a SIEM or SIEM alternative offering in their portfolio. This acquisition positions Cisco to have both sides of the coin — detection and response focus in XDR with Cisco XDR, and flexibility and adaptability in a security analytics platform with Splunk. This solidifies Cisco as a key player in two massive markets: XDR and SIEM. The acquisition also helps position Cisco to better compete against the Cortex platform for security operations from rival Palo Alto Networks.
Security Practitioners Will Need To Be Won Over
As with most acquisitions, it’s not all sunshine and rainbows. What Cisco does with the Splunk product will determine if it’s a win for security practitioners.Cisco has long been a case study for acquisitions that don’t live up to their initial promise and suffer from underinvestment and a lack of focus. Security leaders know this. In fact, since this was announced, many have demonstrated concern that this pairing will degrade the quality of the SIEM that they’ve come to rely on more than any other SecOps tool.
That said, there are exceptions to this, such as how, in recent years, Cisco has maintained the Duo, Meraki and ThousandEyes acquisitions as standalones. To keep Splunk’s massive, loyal user base, Cisco needs to follow a similar model and let Splunk deliver what Splunk does best: a flexible, powerful SIEM offering (and the cool t-shirts and hoodies their loyal users love).
There will also be an opportunity to evolve the Cisco story for identity threat detection and response(ITDR).Earlier this year, Cisco acquired a startup Oort, which deals with ITDR. The combination of Splunk, Oort, and Duo will allow Cisco to tell a differentiated ITDR story. This will give the company a new direction of development that was not previously inherent in Cisco, namely, identity security.
The Security Industry — And SIEM Market — Is Experiencing Massive Disruption
This acquisition signals a massive inflection point for the SIEM market.This is a concern for Splunk users who have a negative view of Cisco's role in security and how it will affect Splunk's innovation.
This uncertainty will cause Splunk customers to explore alternatives, and we expect to see experimental deployments of other smaller security analytics players as backup. This will also be a boon for Microsoft Sentinel.
Microsoft is the biggest SIEM competitor to Splunk right now. Splunk customers will flock to or expand their Sentinel deployments as they hedge their bets between where Cisco takes Splunk and where Microsoft takes Sentinel.
Lastly, this shift in the market opens up an opportunity for XDR vendors with a SIEM replacement strategy like CrowdStrike and Palo Alto Networks to swoop in and push customers away from a traditional SIEM deployment. This is still early days for vendors and customers and requires a change in mindset to get right, which will hold certain teams back from making the transition in the short term.
Cisco Acquires Splunk To Increase Its Relevancy In An AIOps, Hybrid, Multicloud World
Splunk is a stalwart in the operational arena, used by enterprises across the globe in every industry. Its superior log management capabilities are entrenched in enterprises, but its observability features within its AIOps offering are what made it a Strong Performer in The Forrester Wave™: Artificial Intelligence For IT Operations, Q4 2022. The Splunk platform is trusted by practitioners to provide a complete service view, from back-end monitoring through end-user interactions.
Its loyal customer base openly praises its access to Splunk product teams, describing them as “always willing to listen to their suggestions.” Will this access to product leaders continue under the Cisco banner, or will it get cut off and initiate a Splunk customer revolt?
For Cisco, it gets a Splunk platform that currently surpasses Cisco’s recent announcement of its Full-Stack Observability (FSO) offering. FSO integrates Cisco products such as AppDynamics and ThousandEyes as well as third-party offerings to deliver business risk observability.
FSO will be bolstered by Splunk’s vast and highly regarded observability features, which are sure to fill many of the likely roadmap objectives that Cisco had for FSO. Additionally, Splunk’s strong cloud-based revenue stream adds to Cisco’s top line and helps its transition from hardware producer to operational software provider. With the acquisition, Cisco is also positioned to deliver offerings that support the convergence of operational observability with security, which is already underway.
AIOps And Observability Acquisitions Naturally Cause Hesitation
Splunk’s acquisition marks the fifth AIOps and observability vendor to change ownership in 2023 (the others include Sumo Logic, OpsRamp, Moogsoft, and New Relic). Practitioners are in for an interesting ride as they wait to see what exactly Cisco will decide to do with Splunk. Cisco observability offerings could migrate to the Splunk platform, or FSO could become the underpinning platform upon which the Splunk capabilities land.
Cisco could also choose to simply leave Splunk as a standalone offering in the same manner it did with Duo, ThousandEyes, and others. Each direction poses different challenges to practitioners who may need to learn new environments or change vast amounts of integrations.
Not surprisingly, purchases and strategic long-term project plans will be put on hold and more attention will be paid to finding alternatives until the direction of Splunk's future development becomes clear.
Cloud Migrations Are Transforming AIOps And Observability
The AIOps and observability vendor marketplace is shifting fast to meet the demands of enterprises that are moving workloads to the cloud. AIOps platforms such as Splunk with strong observability capabilities are needed to process the data and deliver AI-enriched actionable information.
Competitors such as Dynatrace, Datadog, and ScienceLogic will certainly look to capitalize on this transition period. Data-driven actions require high-quality data that has been correlated and analyzed for causality, something Splunk excels at and Cisco will soon possess. The addition of Splunk gives Cisco an expansive portfolio, and a strategic direction set by FSO makes Cisco a formidable opponent for established market leaders.
Technology leaders as well as AIOps and observability competitors will be watching this closely for any signs of delays or conflicts. Millions of dollars worth of decisions will be held up or redirected while the portfolios, leadership teams, and customer bases of these two organizations learn how to best work together.
Approach With Caution
Since Splunk will span two product groups in Cisco — security and observability — it runs the risk of being torn apart by internal forces. Operating it as a standalone will allow Splunk to serve both constituencies equally and continue growing and innovating. Splunk President and CEO Gary Steele reporting directly to Cisco Chair and CEO Chuck Robbins is a positive sign.
These markets and the vendors in them need the disruption that this acquisition will bring forth, but this all comes with a lot of uncertainty for practitioners.
LogRhythm is a convincing alternative
In the ever-changing cybersecurity landscape, we understand the importance of making informed decisions when selecting a security information and event management (SIEM) vendor.
In a time of uncertainty, more clarity is needed. As the article states, "this uncertainty will leave Splunk customers looking for alternatives," and LogRhythm offers a compelling alternative.
In light of these possible changes, LogRhythm may be a better choice for some organizations. Here are a few reasons why:
- LogRhythm is an independent product that is not influenced by the development strategy of another company. This means that LogRhythm will continue to evolve in accordance with the needs of its users.
- LogRhythm has a simpler architecture and user interface than Splunk. This can make it easier to use for organizations with limited resources.
- LogRhythm пропонує широкий спектр готових до використання правил виявлення загроз. Це може допомогти організаціям швидше виявляти та реагувати на інциденти безпеки.
- LogRhythm offers more affordable prices than Splunk. This can make it a better choice for companies on a budget.
- LogRhythm delivers consistent, effective innovation every quarter, meeting changing security needs with precision and dedication.
LogRhythm believes that SIEM is not just a tool, but a critical foundation for reliable cybersecurity. A SIEM is not a one-time project, but a journey to maturity that requires a lot of effort, critical thinking, and continuous improvement. The SIEM product and vendor are of particular importance in the ongoing fight against the ever-evolving digital threat landscape.
Learn more about LogRhythm
Take care of a reliable SIEM solution for your business today! Company iIT Distribution is the official distributor of LogRhythm solutions in Ukraine, Kazakhstan, Uzbekistan, Georgia, Azerbaijan, Estonia, Kyrgyzstan, Moldova, Tajikistan, and Armenia. You can schedule a technical demonstration of LogRhythm and order a demo version of the solution using a special form on our website.
Back