Cisco to buy Splunk – 5 Things to Watch
Cisco announced its intended acquisition of Splunk for $28B. Security industry analyst Jo Peterson shares her thoughts on the impact of the acquisition and the five things to watch.
Transcript
All right, so it's not too often that the industry gives us a topic to talk about from a news perspective, but I have Joe Peterson returning to the podcast. Joe, Cisco gave us some $28 billion worth of reasons to talk about them this week. Yeah. What was the news? Cha-ching, cha-ching. So, Cisco bought Splunk. At least they're buying Splunk. $28 billion in an all-cash deal is by far Cisco's largest acquisition ever. And I have a bunch of thoughts, but you're the security expert, and I wanted to have you on specifically to kind of get your reaction.
Other than the size of the deal, the cash value of the deal, how important is this deal? Man, it's important in so many ways. So, first of all, it really solidifies Cisco's position in cybersecurity and AI observability software. Boy, I need another cup of coffee. It's Monday. But, yeah, so that would be the first thing. And, you know, they're putting a stake in the ground, and they're saying, man, we are here for security. Don't be thinking about us as just a routing and switching company.
We're a security player. So, I want to note that, why this is important, because I went back and forth with Dave Vellante and a bunch of other really smart analysts. Cisco called themselves a networking security company or a security company. Like, I don't know if, yeah, Cisco has some security products, yes, and they're decent products. But I don't know if I would actually, as an enterprise architect, I don't know if I would have, before this deal, have called Cisco a security company.
Yes, they have security products, but are they a security company? Not in the lights of like a Palo Alto or companies that I think are focused on just security. I have to admit, this Splunk deal, for me, kind of solidifies. There's no question to it about me, Cisco, security company. Cisco plus Splunk, security company, a $28 billion company. I think I saw the stack that is basically 6X revenue of Splunk, which is, you know, like $4 billion a year in security product.
That's a sizable security company. Yeah, for sure. And, I mean, Cisco, for years, has been building out their security strategy, right? And they're doing it for a couple reasons, I think. So, first of all, they were doing network-adjacent security. So the products that you saw them come into the market with were products that could be bought by the network manager, maybe bought by the CIO, too, since it was network-adjacent security, and maybe bought by the CISO. So they've been working their way in front of the CISO, right, for a number of years.
The other reason that I think this is such an interesting deal is how revenue is recognized. So Cisco has long been known as a hardware company, and we know that the world is run and driven by software. And so they've been trying for the last several years to get themselves additional what's known as ARR revenue. The acquisition of Splunk is going to have a huge influence on annual recurring revenue as it relates to Cisco's go-to-market strategy. It represents a $4 billion ARR bump.
And this is going to go far in helping to transition Cisco from a hardware-based CapEx revenue model to a software-focused recurring revenue model. Yeah, and as you stated, Cisco's been trying to make this transition for several years now. a. the way most tech vendors get that is via subscription. So they've been selling their hardware, essentially, for the past couple of years as a subscription. The customers are pretty resistant to buying hardware under a subscription model. At the end of the day, you own hardware, and a lot of these software vertical stack companies have been, you know, kind of separating you buy the hardware and you license or you subscribe to the software to mix reviews.
So for my audience who may not be as familiar with Splunk, what is Cisco buying in Splunk? What is Splunk exactly? Well, so Splunk started out as a SIP, right? Security Incident Event Management Tool. So all of my security events will go to this platform, and I have a single pane of glass to see all of my security events, basically? Yeah. And so it is more than a repository, right? So the second thing that it does, it's great to correlate the data.
So let's just say your endpoint data is flowing in, right, and it all flows into your SIEM. Well, it's great to correlate everything there, but the other side of it is threat detection and response. So it doesn't just end up there and do nothing. It's not sitting in a data lake, right, and doing nothing. It is actually the intelligence that's being acted upon or the data is being acted upon by intelligence. So Splunk's gone a long way in helping customers do things like navigate around false positive.
If you think about the plethora of alerts that come in, particularly in a large organization, it's estimated that maybe up to 40% of those could be false positive. So how do you separate the noise from the truth, right? And how do you concentrate your people on separating the noise from the truth? And so that's where the whole idea of observability comes in. So this is a tool that, in a pane of glass, can help you not only identify but then remediate, right?
So is this where the AI story comes in, the ability to look at all of this massive amounts of data? This is something I've heard over and over again, too many incidents for humans to look at. That's right. And to your point, up to 40% of them can be false positive. So I'm essentially getting 40% the, it's bad math, but bear with me. I'm basically getting 40% more staff in the ability to have these AI tools like Splunk be able to eliminate the false positives and act upon kind of simple ones.
Like should this be escalated or should a event, should I trigger some type of isolation, some other third-party tool until we can, you know, enable traffic or some human looks at this and says, oh, this is good or bad traffic. That's right. And then Splunk up-leveled. So they helped bring to life the whole concept of contextualization. So the idea that there's patterns in data. We all know that there's patterns in data, right? So some of the technology that they've built in with the help of AI and observability has recognized patterns like, hey, we know that, you know, this bad guy always tries to get in through this door.
So we're going to try to lock down this door more effectively on a continual basis. It's the idea of visualization of patterns across the data. So you're using the word data. And specifically, we talked about Cisco being adjacent with their network security products. This isn't just limited to network. This is like application level. This is application level security monitoring. It could be. I mean, it's a number of things, right? It's a repository, as you mentioned earlier, for all kinds of endpoints.
It could be endpoint data coming in. It could be network data coming in, right? It could be all kinds of data that's kind of getting put into this engine. And then the engine is helping parse through the data. And not only is it looking for bad guys, it's looking for false positive. It's looking for patterns. It's looking for a number of things in the data. So it's a smart approach to handling that volume of data that's coming in.
So thanks for helping me bring me back up to speed where Splunk is now versus where it started. Actually, I think my last update of Splunk might have been, you know, kind of where they were at the entry point. So you've helped me kind of understand where they're at. So let's go back to kind of. I know you have maybe about four or five different key points about the acquisition. We've probably hit two now. What's, you know, kind of number three?
I think that Splunk's done a great job. Don't get me wrong. But Cisco is one of the granddaddies in the tech space, right? They just are. And they've been around, you know, I mean, I've got my CCNA back in. I don't even want to tell you what year it was. But I was younger and fresher looking. It was 2001 for me. I remember. It was a tough test. Oh, okay. So you took the frame relay test too?
Yes, I did. It was frame relay on my test. All right. What's it tell us? Come on, Keith. Oh, no. Please don't make me do frame relay addressing anymore. No, no, no, no. The memories. So we got it the same year. Actually, Cisco's been around forever. And the point is that they've done a wonderful job in terms of global market penetration and channel strategy. And I think that that wealth of tenure and experience is only going to help Splunk get into markets that they have been into, stratifying their market strategy and channel strategy to be deeper and richer.
That's going to open doors for Splunk. So, okay. And I think I've made this point online as well. Symbiotic relationship. You mentioned it in your point number two that, you know, Cisco is basically buying their way into the CISO's office. They have a much stronger relationship. And the inverse is true too. Cisco's sales organization is probably their number one asset. They are very, very good at generating leads, curating deals and being exceptionally aggressive in closing deals. So this ability to just open doors for the Splunk value prop makes a lot of sense to me.
I'm very bullish on, you know, kind of Cisco's sales and marketing force getting hold of the Splunk assets. All right. Point number four. I think point number four is going to be interesting as it plays out. I think we're going to start to see this integration between products that is going to be like an amplification effect for Cisco. What I mean is they've been taking products into their portfolio that are going to all sort of click together like a set of Legos.
So we've got Thousand Eyes. Now we've got Splunk. We've got AppDynamics. Think about the things that they've bought and that are going to work in concert. And so the story that they're going to be able to walk into a customer and tell is big. And then the fact that, you know, all these tools are going to play nicely together is also big. And that's some of the pushback that I've been getting about the deal is simply Cisco's never made a deal this big.
When you look at most of their acquisitions, those acquisitions have taken on the Cisco personality, Meraki, the other, even Thousand Eyes and AppDynamic. These have been much smaller acquisitions. They've come on. Cisco has done some integration, probably the most famous of which has been their SDN play in which they bought the SDN product or code set to their router platform versus, you know, kind of adopting the models of these companies. Splunk is a $28 billion acquisition. You're going to get some splunk DNA inserted into Cisco just by the sheer size of it.
Do you see kind of Cisco's traditional approach to acquisitions as a risk to the success of this deal? I think you're really asking me a different question. I am. At least I'm hearing a different question. And it was crafty. That was very crafty, Keith. So what I'm hearing is culture. I'm hearing a question about culture. Yes. And I think that there's a pivot occurring. Cisco has been wildly successful doing what they've done for years, but it's a newer generation of buyers, and I think they're recognizing that.
I think they're recognizing that, you know, the way people used to procure products is different today, and they're making that shift, right? So I think I'm always hopeful. I'm a glass half full girl. So I'm always hopeful that something this large and meaningful to the whole industry is going to work. Yeah, to put some technical meat behind the hope, you know, I could always go out and buy Thousand Eyes, AppDynamics, Splunk, all these services separately. As a matter of fact, I just wrote a tweet about how in the security space, multi-vendor is actually a good thing from a tax service perspective.
A lot of security professionals prefer to have multiple vendors. However, the challenge of that, that that introduces is real. Because all of these multiple vendors are, you know, kind of focused on their slice of the problem. When I think about the problem that enterprises have from a practical security perspective, I give the Lambda to Oracle example that I love to give, which is if I have a Lambda running in AWS, and that Lambda has access to Oracle database, how do I ensure that my security policy is in effect?
If I went to Cisco before, Cisco really didn't have an answer to that, not from a network centric perspective, because there's no IP addresses to, you know, this is serverless. There's no IP addresses. I don't have the traditional controls. You ask Splunk and you add Thousand Eyes, you add AppDynamics, you add Cisco's traditional monitoring solutions, and now you might actually have an end-to-end solution if those three or four different product teams can get together and focus on that unique challenge. I think that's the possibility.
So let's end with your fifth point. What do you think the fifth consideration for this acquisition is? I think that, you know, having had a chance to work with the Splunk team, I was really impressed about all the work they were doing around AI early. So this deal has been in the making for a long time. This didn't just happen yesterday, right? And Cisco is going to benefit from all the AI work that all the folks at Splunk have done with their product just instantly.
Yeah, this is the problem space that Splunk has been focused on. I joked that this is going to be, no, it wasn't a joke. I was actually pretty serious about this. This is going to have a halo effect on all of Cisco. I've never thought of this possible combination, but Splunk on-premises is a infrastructure heavy solution. So one of the things that we haven't talked about is the server group, the new partnership with Nutanix and what used to be HyperFlex, the ability to sell the infrastructure that Splunk runs on will be a halo.
The same team that sells you the software licenses can also sell you the physical infrastructure to land that in. Cisco can wrap kind of Splunk up in a subscription model. You can buy a Splunk pod that gives you the software licensing, the capabilities, et cetera, all in one package without you really thinking about, do I run out of infrastructure? Cisco, if done right, can do all of that for you. And then there's the simple fact that this is AI around this space is a hard problem.
So the barrier of entry to be able to take all of these security data sets, put some intelligence behind them is really, I think both of us would agree Splunk is probably the leader in this segment. And you couple Splunk with one of the leaders and where this data is coming from and you get their AI scientists behind it, I can't see nothing but good things, maybe expensive things, but good things down the road for Splunk plus Cisco. I'm completely bullish on this solution and this combination.
Yeah, I think it's a great combo. So, Joe, for those who have not watched our cloud everyday series, our AWS everyday series, who just haven't gotten enough of you on the CTO advisor platform, what can folks find you? They can find me on LinkedIn at Joe Peterson, or they can find me on Twitter or X at Clear Tech Today and on threads at Clear Tech Today. So little known fact, Joe Peterson's cat videos are the only ones I ever see on LinkedIn.
LinkedIn does not allow cat videos for the most part. They punish the algorithm. Cat videos get punished in the algorithm. But Joe has for years, she's just worth following for this, for years has trained like general basic security knowledge with cute cat videos. She is well known in the industry, not just for her chops around doing analysis around these types of deals, but for this as well. If you want to learn more about the CTO advisor, you can follow us on the web.
The CTO advisor dot com is where you can find just about everything. CTO is related in at CTO advisor on most social platforms, including X dot com, blue sky, master Don, et cetera. And of course, LinkedIn talk to you next. CTO advisor podcast.