Splunk dumped a ton of news at its user conference today including another acquisition — it’s third since late August — a security platform called Mission Control, and new capabilities in its Data-to-Everything Platform.
CTO Tim Tully kicked off .conf19 in Las Vegas announcing Splunk reached a deal to buy Streamlio, an open source distributed messaging startup, for an undisclosed amount. In a blog, Tully said the acquisition will “accelerate our efforts in real-time stream processing as well as containerized multi-tenant cloud platform applications. (Not to mention Open Source!)”
Stremalio built its platform on open source Apache Pulsar, which the startup helped to create, and its team continues to contribute code to the project and the open source community at large. “Those roots in OSS are incredibly important to us at Splunk as we’re voracious consumers of OSS as well as emerging contributors back to it,” Tully wrote.
This latest acquisition follows two other recent purchases. In late August Splunk paid $1.05 billion for SignalFX, which provides real-time monitoring and metrics for the cloud, microservices, and applications. Two weeks later it acquired Omnition, a startup that is developing a observability platform for microservices-based applications.
It’s almost enough acquisitions to draw envy from the likes of VMware and Google Cloud.
Splunk Mission ControlIn addition to highlighting its buying spree, Splunk rolled out new products and capabilities at .conf19. The vendor integrated its existing security tools — these include security information and event management (SIEM), user behavior analytics (UBA), and security orchestration, automation, and response (SOAR) — into a new unified platform called Splunk Mission Control, that’s available in beta.
“The idea is to provide a native, cloud-based application that acts as a single pane of glass for security analysts who can understand what’s happening, be able to investigate, be able to do case management around it, and even automate response to certain types of events so they can focus on the ones that require human intervention and allow automation to take over the ones that don’t,” said Jeff Schultz, Splunk’s VP of product marketing.
The company also added new features to its security software including asset and identity framework improvements to its SOAR product and mobile capabilities as well as 30 new open sourced apps to Phantom, its SOAR tool.
“We definitely see this as a strategy to provide a much more wholistic experience for our customers,” Schultz said. “If you want to be able to increase efficiency for security analysts and for the folks who are running the security operations center, you need to think about how all of these products come together so they are not having to switch between lots of products.”
Data-to-Everything UpdatesSplunk also added several new capabilities to its Data-to-Everything Platform, which enterprises use to search, investigate, monitor, analyze, and act on data at scale. This includes the general availability of its Data Fabric Search (DFS) and Data Stream Processor (DSP).
DFS streamlines data analytics by weaving together insights from massive datasets across diverse data stores, including those that aren’t Splunk-based, into a single view.
Meanwhile DSP is a real-time stream processing product that continuously collects high-velocity, high-volume data from diverse sources, uses this data to provide insights, and then distributes results to Splunk or other destinations typically within milliseconds. It can also mask sensitive data to protect critical information that could impact a business.
“[Data Stream Processor] is one of the first products that augments the platform but can sit outside the platform and execute on its own behalf,” Schultz said. “It allows us to ingest data from multiple sources and provides data processing in real time.”
The vendor also rolled out Splunk Connected Experiences, which extends its data processing and analytics capabilities to augmented reality (AR), mobile devices, and mobile applications.
And it announced integrations with SignalFX that target DevOps teams to allow them to process metrics, traces, and logs using AI-driven analytics. This includes building in SignalFX’s deep-linking capabilities to Splunk Cloud so that DevOps can go from problem detection to root cause without switching between products. It also integrated SignalFX technology with VictorOps, which routes alerts to the right people for faster problem resolution. This integration will further reduce time to detect and remediate, according to Splunk.
Splunk’s Big VisionAll of these product updates aim to make Splunk’s vision of “data to everything” a reality, Schultz said.
“Organizations are telling us they have more and more data than ever before though systems and sensors and applications are sitting in transactional databases,” he explained. “They know there’s a lot of information and data locked in those, and we want to give them a platform that allows them to bring data to every detection, every question, and every action they have, and work with data regardless of structure, from any source, regardless of where it lives. And handle it in any scale.”
Comments