During Cisco’s earnings call this week, an investor posed the $20 billion question to Cisco CEO Chuck Robbins: Are you buying Splunk?
Robbins opened with the usual “we don’t comment on rumors and speculations or stories.” But, he added, Cisco constantly evaluates potential acquisition opportunities, and “for every deal we do, we probably look at 10 to 15 companies.”
The networking giant bases its decisions on strategic fit, cultural fit, and financial fit, he added. “And we are always disciplined, and we continue to focus on both inorganic and organic opportunities,” Robbins said. “But I will tell you that you should expect us to continue to be very, very disciplined as we go forward as well.”
In other words: tell me the rumored $20 billion Splunk takeover is dead without telling me the deal is dead.
Observability, Security High on M&A ListStill, Cisco under Robbins’ leadership hasn’t been one to shy away from M&A. Last month Cisco announced its intent to acquire Opsani to boost its AppDynamics observability platform. This followed two other deals that closed in 2021: Epsagon and replex, both of which further built out Cisco’s full-stack observability strategy.
There’s also Cisco’s original move into observability with its $3.7 billion AppDynamics purchase in 2017, and its $1 billion ThousandEyes buy in 2020. These two acquisitions formed the basis for Cisco’s observability platform, which it’s been steadily building out largely via M&A ever since.
And at a technology conference in December, Cisco Chief Strategy Officer Liz Centoni said she expects security and observability to converge.
So while the Splunk deal may be dead, it’s still highly likely that Cisco’s still in the market for another observability and security analytics vendor. Now the question is: which company in this space will Cisco buy instead of Splunk?
Will Cisco Buy Exabeam or Devo?“The two that come to mind are Exabeam and Devo, but there are probably others as well,” ESG senior principal analyst Jon Oltsik wrote in response to questions. “Exabeam provides an installed base, but certainly not at the scale of Splunk. Devo provides a scalable cloud analytics backend.”
Exabeam started in user entity and behavior analytics (UEBA) before moving into security information and event management (SIEM), and, more recently, extended detection and response (XDR). It correlates and analyzes data from third-party vendors’ agents and connectors across endpoints, cloud, workloads, and the network.
Over the summer, the vendor announced that it closed a $200 million late-stage funding round on a $2.4 billion valuation and hired a new CEO: Michael DeCesare, who previously was president of McAfee, and most recently served as CEO and president of ForeScout Technologies.
In an earlier interview with SDxCentral, DeCesare, who took ForeScout public in 2017, said an initial public offering “is still on the table,” while he believes Exabeam “will be quite successful in the public market,” an IPO is not a top priority. “I ultimately believe that our destiny is to be a major player in the larger category called security operations,” he said.
Still, it’s worth noting that Cisco snatched AppDynamics on the eve of its IPO.
Devo Technology, meanwhile, is another security analytics unicorn. Last fall it announced a $250 million Series E funding round that pushed its valuation to $1.5 billion.
And while Devo CEO Marc van Zadelhoff names Splunk as one of his company’s top competitors, “we would differentiate by the fact that we are a cloud-native, contemporary solution,” he said in an earlier interview. “We have really strong machine learning algorithms in the platform, and then we have a very strong security application on top of it.”
Or a Smaller Observability Vendor?Zeus Kerravala, principal analyst with ZK Research, says he expects Cisco to target a company that’s more of a straight observability play — and has a much smaller price tag.
“I do think it makes sense for Cisco to bolster its observability story,” he wrote in response to questions. “It already has ThousandEyes and AppD, and something like Splunk would complement it. With that being said, I don’t see Cisco buying Splunk.”
The $20 billion price doesn’t fit in with Cisco’s normal acquisition strategy, Kerravala said. “It’s more likely they buy a smaller vendor and drop it into their channel and product roadmap and grow it that way.”
Cribl, an observability pipeline vendor, “would be an excellent acquisition,” Kerravala said. “They’re still small and a very typical Cisco move. It has a great product that works very fast and can ingest lots of different types of data, including Splunk, which supports Cisco’s mission of being open.”
Observe is another observability company that Kerravala says would make a good target. “Its dashboard is very slick and customizable, and given the diversity of Cisco’s business could be used by many different buying centers,” he explained.
Gigamon may be on the shortlist, Kerravala said, noting the vendor’s work integrating network telemetry with the traditional observability data sources of metrics, events, logs, and traces. “The issue with Gigamon is it would need to decouple the software from the network packet broker business,” he added.
And then Kerravala listed a couple other vendors, Dynatrace and DataDog — but both are public companies that will come with a much higher price tag compared to some of the others. “If [Cisco] was going to go this route,” Kerravala said, “then go with Splunk and pick up the security portion, too.”
Comments